From 4ebf7bbe274a8615ab00a685e34301c700a67922 Mon Sep 17 00:00:00 2001 From: Ikey Doherty Date: Wed, 3 Jun 2015 05:21:15 +0100 Subject: [PATCH] tests: Incorporate dummy data Signed-off-by: Ikey Doherty --- tests/dummy_data/nvdcve-2.0-2002.xml | 313631 ++++++++++++++++++++++++ 1 file changed, 313631 insertions(+) create mode 100644 tests/dummy_data/nvdcve-2.0-2002.xml diff --git a/tests/dummy_data/nvdcve-2.0-2002.xml b/tests/dummy_data/nvdcve-2.0-2002.xml new file mode 100644 index 0000000..50308a5 --- /dev/null +++ b/tests/dummy_data/nvdcve-2.0-2002.xml @@ -0,0 +1,313631 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:freebsd:freebsd:2.1.6.1 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:freebsd:freebsd:1.2 + cpe:/o:freebsd:freebsd:1.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.1.7 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:1.0 + cpe:/o:freebsd:freebsd:2.0.1 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:bsdi:bsd_os:3.1 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0001 + 1999-12-30T00:00:00.000-05:00 + 2010-12-16T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + OSVDB + 5707 + + + CONFIRM + http://www.openbsd.org/errata23.html#tcpfix + + ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:2.1 + cpe:/o:redhat:linux:2.0 + cpe:/o:caldera:openlinux:1.2 + cpe:/o:bsdi:bsd_os:1.1 + cpe:/o:redhat:linux:3.0.3 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0002 + 1998-10-12T00:00:00.000-04:00 + 2009-01-26T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 121 + + + CIAC + J-006 + + + SGI + 19981006-01-I + + Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.02 + cpe:/o:ibm:aix:4.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.0 + cpe:/o:sun:solaris:1.2 + cpe:/a:tritreal:ted_cde:4.3 + cpe:/o:sun:solaris:1.1 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:hp:hp-ux:10.03 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0003 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:33:30.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 122 + + + SGI + 19981101-01-PX + + + SGI + 19981101-01-A + + Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). + + + + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.02 + cpe:/o:sco:unixware:7.0 + cpe:/a:hp:dtmail + + CVE-1999-0004 + 1997-12-16T00:00:00.000-05:00 + 2008-09-09T08:33:31.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-008 + + MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook. + + + + + + + + + + cpe:/a:university_of_washington:imap:10.234 + cpe:/a:netscape:messaging_server:3.55 + + CVE-1999-0005 + 1998-07-20T00:00:00.000-04:00 + 2008-09-09T08:33:31.117-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 130 + + + SUN + 00177 + + Arbitrary command execution via IMAP buffer overflow in authenticate command. + + + + + + + + + cpe:/a:qualcomm:qpopper:2.4 + + CVE-1999-0006 + 1998-07-14T00:00:00.000-04:00 + 2008-09-09T08:33:31.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 133 + + + SGI + 19980801-01-I + + Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:c2net:stonghold_web_server:2.3 + cpe:/a:ssleay:ssleay:0.6.6 + cpe:/a:netscape:enterprise_server:3.5.1 + cpe:/a:netscape:proxy_server:3.5.1 + cpe:/a:netscape:certificate_server:1.0:patch1 + cpe:/a:c2net:stonghold_web_server:2.0.1 + cpe:/a:c2net:stonghold_web_server:2.2 + cpe:/a:open_market:secure_webserver:2.1 + cpe:/a:netscape:collabra_server:3.5.2 + cpe:/a:netscape:messaging_server:3.54 + cpe:/a:netscape:enterprise_server:3.0.1b + cpe:/a:ssleay:ssleay:0.9 + cpe:/a:netscape:directory_server:3.12 + cpe:/a:netscape:fasttrack_server:3.01b + cpe:/a:netscape:directory_server:3.1:patch1 + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:netscape:directory_server:1.3:patch5 + cpe:/a:ssleay:ssleay:0.8.1 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:netscape:enterprise_server:2.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-0007 + 1998-06-26T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-002 + + Information from SSL-encrypted sessions via PKCS #1. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0008 + 1998-06-08T00:00:00.000-04:00 + 2008-09-09T08:33:31.320-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00170 + + Buffer overflow in NIS+, in Sun's rpc.nisd program. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/a:data_general:dg_ux:5.4_4.11 + cpe:/o:sgi:irix:4.0.5 + cpe:/o:sgi:irix:4.0 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:4.0.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:4.0.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:4.0.4 + cpe:/o:sgi:irix:4.0.3 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:3.2 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:3.3 + cpe:/o:sgi:irix:6.1 + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:sgi:irix:4.0.4b + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/a:isc:bind:4.9.6 + cpe:/o:nec:asl_ux_4800:64 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:bsdi:bsd_os:2.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:bsdi:bsd_os:2.0.1 + cpe:/o:sun:solaris:2.6::x86 + cpe:/a:data_general:dg_ux:5.4_3.0 + cpe:/a:isc:bind:8.1.1 + cpe:/o:sgi:irix:4.0.5e + cpe:/o:sgi:irix:4.0.5d + cpe:/o:sgi:irix:4.0.5g + cpe:/o:sgi:irix:4.0.5f + cpe:/a:data_general:dg_ux:5.4_3.1 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sgi:irix:4.0.5h + cpe:/o:sgi:irix:4.0.5_ipr + cpe:/a:data_general:dg_ux:5.4_4.1 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:sgi:irix:4.0.5a + cpe:/o:sgi:irix:5.1.1 + cpe:/o:sgi:irix:4.0.4t + cpe:/o:caldera:openlinux:1.0 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/a:isc:bind:8.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sco:open_desktop:5.0 + cpe:/o:sgi:irix:3.3.3 + cpe:/o:sco:unixware:2.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sgi:irix:4.0.5_iop + cpe:/o:ibm:aix:4.1.5 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:3.3.2 + cpe:/o:sgi:irix:3.3.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:sgi:irix:4.0.1t + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0009 + 1998-04-08T00:00:00.000-04:00 + 2008-09-09T08:33:31.727-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9808-083 + + + BID + 134 + + + SUN + 00180 + + + SGI + 19980603-01-PX + + + + + Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:nec:asl_ux_4800:13 + cpe:/o:ibm:aix:4.3 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02 + cpe:/o:nec:asl_ux_4800:11 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:5.5.1 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03 + cpe:/o:sco:unixware:2.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/a:isc:bind:8 + cpe:/o:sun:solaris:5.5 + cpe:/o:sun:solaris:5.4 + cpe:/o:sun:solaris:5.6 + cpe:/o:netbsd:netbsd:1.3 + cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03 + cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2v4 + cpe:/o:sco:openserver:5.0 + cpe:/a:isc:bind:4.9 + cpe:/o:redhat:linux:4.2 + cpe:/o:sun:solaris:5.3 + + CVE-1999-0010 + 1998-04-08T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9808-083 + + + SGI + 19980603-01-PX + + + + + Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:nec:asl_ux_4800:13 + cpe:/o:ibm:aix:4.3 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02 + cpe:/o:nec:asl_ux_4800:11 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:5.5.1 + cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03 + cpe:/o:sco:unixware:2.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/a:isc:bind:8 + cpe:/o:sun:solaris:5.5 + cpe:/o:sun:solaris:5.4 + cpe:/o:sun:solaris:5.6 + cpe:/o:netbsd:netbsd:1.3 + cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03 + cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2v4 + cpe:/o:sco:openserver:5.0 + cpe:/a:isc:bind:4.9 + cpe:/o:redhat:linux:4.2 + cpe:/o:sun:solaris:5.3 + + CVE-1999-0011 + 1998-04-08T00:00:00.000-04:00 + 2008-09-09T08:33:31.867-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9808-083 + + + SUN + 00180 + + + SGI + 19980603-01-PX + + + + + Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. + + + + + + + + + + + + + + cpe:/a:netscape:fasttrack_server:2.01 + cpe:/a:netscape:enterprise_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:netscape:fasttrack_server:3.01 + cpe:/a:microsoft:personal_web_server:4.0 + cpe:/a:microsoft:frontpage + + CVE-1999-0012 + 1998-02-06T00:00:00.000-05:00 + 2008-09-09T08:33:31.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.3 + cpe:/a:ssh:ssh:1.2.4 + cpe:/a:ssh:ssh:1.2.1 + cpe:/a:ssh:ssh:1.2.2 + cpe:/a:ssh:ssh:1.2.7 + cpe:/a:ssh:ssh:1.2.8 + cpe:/a:ssh:ssh:1.2.5 + cpe:/a:ssh:ssh:1.2.6 + cpe:/a:ssh:ssh:1.2.14 + cpe:/a:ssh:ssh:1.2.9 + cpe:/a:ssh:ssh:1.2.12 + cpe:/a:ssh:ssh:1.2.13 + cpe:/a:ssh:ssh:1.2.0 + cpe:/a:ssh:ssh:1.2.10 + cpe:/a:ssh:ssh:1.2.11 + + CVE-1999-0013 + 1998-01-22T00:00:00.000-05:00 + 2008-09-09T08:33:32.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/a:cde:cde:1.01_x86 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:ibm:aix:4.1 + cpe:/a:cde:cde:1.2 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:11.00 + cpe:/a:cde:cde:1.02_x86 + cpe:/a:cde:cde:1.02 + cpe:/a:cde:cde:1.01 + cpe:/a:cde:cde:1.2_x86 + cpe:/o:hp:vvos:10.24 + + CVE-1999-0014 + 1998-01-21T00:00:00.000-05:00 + 2008-09-09T08:33:32.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9801-075 + + + SUN + 00185 + + Unauthorized privileged access or denial of service via dtappgather program in CDE. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:microsoft:windows_95:0.0a + cpe:/o:hp:hp-ux:10.30 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:9.03 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:microsoft:windows_nt:3.5.1:sp2 + cpe:/o:microsoft:windows_nt:3.5.1:sp1 + + CVE-1999-0015 + 1997-12-16T00:00:00.000-05:00 + 2009-03-04T00:00:06.593-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + Teardrop IP denial of service. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/a:gnu:inet:5.01 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:microsoft:windows_95 + cpe:/o:hp:hp-ux:9.03 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:cisco:ios:7000 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:10.16 + cpe:/a:microsoft:winsock:2.0 + + CVE-1999-0016 + 1997-12-01T00:00:00.000-05:00 + 2008-09-09T08:33:32.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9801-076 + + + + + + + + Land IP denial of service. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:freebsd:freebsd:1.2 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:freebsd:freebsd:1.1 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:ibm:aix:3.2 + cpe:/o:caldera:openlinux:1.2 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sun:sunos:5.3 + cpe:/o:sun:sunos:5.4 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sun:sunos:5.5 + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/a:washington_university:wu-ftpd:2.4 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/a:gnu:inet:5.01 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sco:unixware:2.1 + cpe:/o:siemens:reliant_unix + cpe:/o:freebsd:freebsd:2.1.7 + cpe:/a:gnu:inet:6.01 + cpe:/o:freebsd:freebsd:1.0 + cpe:/a:gnu:inet:6.02 + cpe:/o:freebsd:freebsd:2.1.0 + + CVE-1999-0017 + 1997-12-10T00:00:00.000-05:00 + 2008-09-09T08:33:32.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sun:solaris:2.5 + cpe:/o:sgi:irix:5.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:ibm:aix:3.2 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-0018 + 1997-12-05T00:00:00.000-05:00 + 2008-09-09T08:33:32.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 127 + + Buffer overflow in statd allows root privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.1 + cpe:/o:nighthawk:cx_ux + cpe:/a:ncr:mp-ras:3.0 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/a:data_general:dg_ux:4.11 + cpe:/o:sco:unixware:2 + cpe:/o:sco:open_desktop:2 + cpe:/o:sco:open_desktop:3 + cpe:/o:ibm:aix:3.2 + cpe:/a:ncr:mp-ras:2.03 + cpe:/o:nighthawk:powerux + cpe:/o:sco:openserver:5.0 + cpe:/o:sun:sunos:5.3 + cpe:/o:sun:sunos:5.4 + cpe:/o:sco:openserver:3.0 + cpe:/o:sun:sunos:5.5 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0019 + 1996-04-24T00:00:00.000-04:00 + 2008-09-09T08:33:32.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00135 + + Delete or create a file via rpc.statd, due to invalid information. + + + CVE-1999-0020 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:34.853-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/a:muhammad_a._muquit:wwwcount:2.3 + + CVE-1999-0021 + 1997-11-05T00:00:00.000-05:00 + 2008-09-09T08:33:34.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 128 + + Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:4.1.1 + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:4.1.3:u1 + cpe:/o:sun:solaris:4.1.3 + cpe:/o:ibm:aix:3.1 + cpe:/o:sun:solaris:4.1.2 + cpe:/o:sgi:irix:5.1.1 + cpe:/o:ibm:aix:3.2 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:ibm:aix:3.2.5 + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.2 + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:ibm:aix:4.1.5 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:bsdi:bsd_os:1.1 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0022 + 1996-07-03T00:00:00.000-04:00 + 2008-09-09T08:33:34.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00179 + + Local user gains root privileges via buffer overflow in rdist, via expstr() function. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:sco:openserver:2.0 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/a:inet:inet:5.01 + cpe:/o:sco:tcp_ip:1.2.1 + cpe:/o:sco:tcp_ip:1.2.0 + cpe:/o:ibm:aix:3.2 + cpe:/o:sco:open_desktop:2.0 + cpe:/a:inet:inet:6.01 + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sun:solaris:1.1 + cpe:/o:sun:sunos:5.3 + cpe:/o:sun:sunos:5.4 + cpe:/o:sco:internet_faststart:1.0 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sun:sunos:5.5 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:bsdi:bsd_os + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sco:unixware:2.0 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:unixware:2.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:sco:openserver:5.0 + + CVE-1999-0023 + 1996-07-24T00:00:00.000-04:00 + 2008-09-09T08:33:35.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Local user gains root privileges via buffer overflow in rdist, via lookup() function. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:ibm:aix:4.2 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sco:unixware:2.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/a:isc:bind:4.9.5 + cpe:/o:nec:asl_ux_4800:64 + cpe:/o:nec:up-ux_v:4.2mp + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:nec:ews-ux_v:4.2 + cpe:/o:sco:unix:3.2v4 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:sco:openserver:5.0 + cpe:/a:isc:bind:8.1 + cpe:/o:nec:ews-ux_v:4.2mp + + CVE-1999-0024 + 1997-08-13T00:00:00.000-04:00 + 2008-09-09T08:33:35.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + DNS cache poisoning via BIND, by predictable query IDs. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0025 + 1997-07-16T00:00:00.000-04:00 + 2008-09-09T08:33:35.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#20851 + + + CERT + CA-1997-21 + + + XF + df-bo(440) + + + BID + 346 + + root privileges via buffer overflow in df command on SGI IRIX systems. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0026 + 1997-07-16T00:00:00.000-04:00 + 2008-09-09T08:33:35.307-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + root privileges via buffer overflow in pset command on SGI IRIX systems. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0027 + 1997-07-16T00:00:00.000-04:00 + 2009-02-25T00:00:00.000-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + root privileges via buffer overflow in eject command on SGI IRIX systems. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0028 + 1997-07-16T00:00:00.000-04:00 + 2008-09-09T08:33:35.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + root privileges via buffer overflow in login/scheme command on SGI IRIX systems. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0029 + 1997-07-16T00:00:00.000-04:00 + 2008-09-09T08:33:35.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + root privileges via buffer overflow in ordist command on SGI IRIX systems. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0030 + 1997-07-16T00:00:00.000-04:00 + 2008-09-09T08:33:35.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + root privileges via buffer overflow in xlock command on SGI IRIX systems. + + + + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:netscape:communicator:3.0 + cpe:/a:netscape:communicator:2.0 + cpe:/a:netscape:communicator:4.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0031 + 1997-07-08T00:00:00.000-04:00 + 2008-09-09T08:33:35.790-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9707-065 + + JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1.4 + cpe:/o:next:nextstep:4.1 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:next:nextstep:4.0 + cpe:/o:sgi:irix:5.1.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:sgi:irix:6.4 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0032 + 1996-10-25T00:00:00.000-04:00 + 2008-09-09T08:33:35.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 707 + + + CIAC + I-042 + + + SGI + 19980402-01-PX + + Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sco:unixware:3.2v4 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/o:sun:sunos:5.5.1 + cpe:/a:ncr:mp-ras:3.0 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sgi:irix + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sco:unixware:2.1 + cpe:/o:ibm:aix + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:openserver:5.0 + cpe:/o:sun:sunos:5.3 + cpe:/o:sco:openserver:3.0 + cpe:/o:sun:sunos:5.4 + cpe:/o:sun:sunos:5.5 + + CVE-1999-0033 + 1997-06-12T00:00:00.000-04:00 + 2008-09-09T08:33:35.930-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Command execution in Sun systems via buffer overflow in the at program. + + + + + + + + + + + + + + + + + + + + cpe:/a:larry_wall:perl:5.3 + cpe:/a:sgi:freeware:1.0 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:4.1 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:redhat:linux:4.2 + cpe:/a:sgi:freeware:2.0 + + CVE-1999-0034 + 1997-05-29T00:00:00.000-04:00 + 2008-09-09T08:33:36.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in suidperl (sperl), Perl 4.x and 5.x. + + + + + + + + + + cpe:/a:gnu:inet:5.01 + cpe:/o:sgi:irix + + CVE-1999-0035 + 1997-05-29T00:00:00.000-04:00 + 2008-09-09T08:33:36.087-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Race condition in signal handling routine in ftpd, allowing read/write arbitrary files. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0036 + 1997-05-26T00:00:00.000-04:00 + 2008-09-09T08:33:36.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-lockout(557) + + + OSVDB + 990 + + + CIAC + H-106 + + + SGI + 19970508-02-PX + + IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files. + + + + + + + + + + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:redhat:linux + + CVE-1999-0037 + 1997-05-21T00:00:00.000-04:00 + 2008-09-09T08:33:36.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:ibm:aix:4.1 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:hp:hp-ux:10.24 + cpe:/a:data_general:dg_ux:6.0 + cpe:/a:data_general:dg_ux:7.0 + cpe:/o:ibm:aix:3.2 + cpe:/o:sgi:irix:5.1.1 + cpe:/o:debian:debian_linux:0.93 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:hp:hp-ux:10.16 + cpe:/a:data_general:dg_ux:1.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/a:data_general:dg_ux:4.0 + cpe:/o:sun:solaris:2.5 + cpe:/a:data_general:dg_ux:3.0 + cpe:/o:hp:hp-ux:10.10 + cpe:/a:data_general:dg_ux:2.0 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:5.0.1 + cpe:/o:debian:debian_linux:1.1 + cpe:/o:debian:debian_linux:1.2 + cpe:/o:debian:debian_linux:1.3 + cpe:/a:data_general:dg_ux:5.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:hp:hp-ux:10.08 + + CVE-1999-0038 + 1997-04-26T00:00:00.000-04:00 + 2008-09-09T08:33:36.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in xlock program allows local users to execute commands as root. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0039 + 1997-05-06T00:00:00.000-04:00 + 2008-09-09T08:33:36.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-1997-12 + + + XF + http-sgi-webdist(333) + + + BID + 374 + + + OSVDB + 235 + + + SGI + 19970501-02-PX + + webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:ibm:aix:4.1 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:hp:hp-ux:9.10 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:ibm:aix:3.2 + cpe:/o:sgi:irix:4.0 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.0 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:sgi:irix:6.0 + cpe:/o:nec:ews-ux_v:4.2 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:nec:asl_ux_4800:64 + cpe:/o:nec:up-ux_v:4.2mp + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:bsdi:bsd_os:2.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:bsdi:bsd_os:2.0.1 + cpe:/o:hp:hp-ux:10.09 + cpe:/o:nec:ews-ux_v:4.2mp + cpe:/o:hp:hp-ux:10.08 + + CVE-1999-0040 + 1997-05-01T00:00:00.000-04:00 + 2008-09-09T08:33:36.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:cray:unicos:9.0 + cpe:/o:cray:unicos:1.5::mk + cpe:/o:ibm:aix:4.1 + cpe:/a:gnu:libc:5.2.18 + cpe:/o:cray:unicos_max:1.3 + cpe:/o:redhat:linux:4.0 + cpe:/a:gnu:libc:5.3.12 + cpe:/o:slackware:slackware_linux:3.1 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:cray:unicos:9.2 + cpe:/a:gnu:libc:5.0.9 + + CVE-1999-0041 + 1997-02-13T00:00:00.000-05:00 + 2008-09-09T08:33:36.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in NLS (Natural Language Service). + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:2.0 + cpe:/o:caldera:openlinux:1.0 + cpe:/a:university_of_washington:imap:4 + cpe:/a:university_of_washington:pop:3 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:redhat:linux:4.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0042 + 1997-04-07T00:00:00.000-04:00 + 2008-09-09T08:33:36.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in University of Washington's implementation of IMAP and POP servers. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:isc:inn:1.4sec2 + cpe:/h:nec:goah_networksv:1.2 + cpe:/a:isc:inn:1.5 + cpe:/h:nec:goah_networksv:3.1 + cpe:/h:nec:goah_intrasv:1.1 + cpe:/a:netscape:news_server:1.1 + cpe:/o:caldera:openlinux:1.0 + cpe:/h:nec:goah_networksv:2.2 + cpe:/o:redhat:linux:4.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:redhat:linux:4.1 + cpe:/a:isc:inn:1.4sec + cpe:/a:isc:inn:1.4unoff3 + cpe:/a:isc:inn:1.4unoff4 + + CVE-1999-0043 + 1996-12-04T00:00:00.000-05:00 + 2008-09-09T08:33:36.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-0044 + 1996-12-03T00:00:00.000-05:00 + 2008-09-09T08:33:36.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19970301-01-P + + fsdump command in IRIX allows local users to obtain root access by modifying sensitive files. + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communications_server:1.12 + cpe:/a:apache:http_server:0.8.14 + cpe:/a:netscape:commerce_server:1.12 + cpe:/a:apache:http_server:1.0 + cpe:/a:apache:http_server:0.8.11 + cpe:/a:netscape:communications_server:1.1 + cpe:/a:apache:http_server:1.1 + cpe:/a:apache:http_server:1.0.2 + cpe:/a:apache:http_server:1.0.5 + cpe:/a:apache:http_server:1.0.3 + cpe:/a:netscape:enterprise_server:2.0a + + CVE-1999-0045 + 1996-12-10T00:00:00.000-05:00 + 2008-09-09T08:33:36.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + List of arbitrary files on Web host via nph-test-cgi script. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:digital:ultrix:4.3a + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:sunos:4.1.4 + cpe:/o:digital:ultrix:4.5 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:digital:ultrix:4.4 + cpe:/o:digital:ultrix:4.3 + cpe:/o:digital:ultrix:4.2 + cpe:/o:digital:ultrix:4.1 + cpe:/o:debian:debian_linux:0.93 + cpe:/o:digital:ultrix:4.0 + cpe:/o:ibm:aix:3.2 + cpe:/o:digital:ultrix:2.2 + cpe:/o:digital:ultrix:3.0 + cpe:/o:digital:unix:4.0 + cpe:/o:next:nextstep:1.0a + cpe:/o:next:nextstep:3.3 + cpe:/a:data_general:dg_ux:4.0 + cpe:/a:data_general:dg_ux:3.0 + cpe:/a:data_general:dg_ux:2.0 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:next:nextstep:4.0 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:next:nextstep:2.0 + cpe:/o:next:nextstep:2.1 + cpe:/o:digital:unix:3.2g + cpe:/o:bsdi:bsd_os:1.1 + cpe:/o:digital:unix:4.0b + cpe:/o:digital:unix:4.0a + cpe:/o:bsdi:bsd_os:2.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:next:nextstep:3.0 + cpe:/o:bsdi:bsd_os:2.0.1 + cpe:/o:next:nextstep:3.1 + cpe:/o:next:nextstep:3.2 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:netbsd:netbsd:1.0 + cpe:/a:data_general:dg_ux:1.0 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:next:nextstep:1.0 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:hp:hp-ux:10.09 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:hp:hp-ux:10.08 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0046 + 1997-02-06T00:00:00.000-05:00 + 2008-09-09T08:33:36.867-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow of rlogin program using TERM environmental variable. + + + + + + + + + + + + + + + + cpe:/a:eric_allman:sendmail:8.8.4 + cpe:/a:eric_allman:sendmail:8.8.3 + cpe:/o:caldera:openlinux:1.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0047 + 1997-01-28T00:00:00.000-05:00 + 2008-09-09T08:33:36.947-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 685 + + MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/a:debian:netkit:0.07 + cpe:/o:ibm:aix:4.1 + cpe:/o:nec:up-ux_v + cpe:/o:nec:ews-ux_v + cpe:/o:nec:asl_ux_4800 + cpe:/o:ibm:aix:3.1 + + CVE-1999-0048 + 1997-01-27T00:00:00.000-05:00 + 2008-09-09T08:33:37.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00147 + + Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0049 + 1997-01-08T00:00:00.000-05:00 + 2008-09-09T08:33:37.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Csetup under IRIX allows arbitrary file creation or overwriting. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:9.10 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:9.03 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:hp:hp-ux:9.08 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:9.06 + cpe:/o:hp:hp-ux:9.09 + + CVE-1999-0050 + 1996-12-01T00:00:00.000-05:00 + 2008-09-09T08:33:37.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in HP-UX newgrp program. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:globetrotter:flexlm:5.0 + cpe:/o:sgi:irix:4.0.5 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/a:globetrotter:flexlm:4.0 + cpe:/o:sgi:irix:4.0 + cpe:/a:sgi:license_oeo:3.1.1 + cpe:/o:sgi:irix:5.3 + cpe:/a:globetrotter:flexlm:4.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:4.0.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:4.0.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:4.0.4 + cpe:/o:sgi:irix:4.0.3 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:4.0.4b + cpe:/a:sgi:license_oeo:3.1 + cpe:/a:sgi:license_oeo:3.0 + cpe:/o:sgi:irix:4.0.5e + cpe:/o:sgi:irix:4.0.5d + cpe:/o:sgi:irix:4.0.5g + cpe:/o:sgi:irix:4.0.5f + cpe:/o:sun:sunos:4.1.4jl + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sgi:irix:4.0.5h + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sgi:irix:4.0.5_ipr + cpe:/o:sgi:irix:4.0.5a + cpe:/o:sgi:irix:5.1.1 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:4.0.4t + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sgi:irix:3.3.3 + cpe:/o:sgi:irix:4.0.5_iop + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:3.3.2 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sgi:irix:4.0.1t + + CVE-1999-0051 + 1997-01-06T00:00:00.000-05:00 + 2008-09-09T08:33:38.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX. + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:bsdi:bsd_os:4.0 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:2.1.7.1 + + CVE-1999-0052 + 1998-11-04T00:00:00.000-05:00 + 2008-09-09T08:33:38.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + freebsd-ip-frag-dos(1389) + + + OSVDB + 908 + + IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash. + + + + + + + + + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0053 + 1998-10-13T00:00:00.000-04:00 + 2008-09-05T16:16:20.580-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6094 + + TCP RST denial of service in FreeBSD. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0054 + 1998-06-10T00:00:00.000-04:00 + 2008-09-09T08:33:38.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00171 + + Sun's ftpd daemon can be subjected to a denial of service. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:ibm:aix:4.2 + cpe:/o:sun:solaris:2.3 + cpe:/o:ibm:aix:4.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-1999-0055 + 1998-05-14T00:00:00.000-04:00 + 2008-09-09T08:33:38.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + AIXAPAR + IX80543 + + + SUN + 00172 + + Buffer overflows in Sun libnsl allow root access. + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:sunos + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0056 + 1998-09-09T00:00:00.000-04:00 + 2008-09-09T08:33:39.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00174 + + Buffer overflow in Sun's ping program can give root access to local users. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix + cpe:/o:hp:hp-ux:10.00 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos + cpe:/o:sun:solaris + cpe:/o:hp:hp-ux:9 + cpe:/o:hp:hp-ux:10.09 + cpe:/o:hp:vvos + cpe:/a:eric_allman:vacation + + CVE-1999-0057 + 1998-11-16T00:00:00.000-05:00 + 2008-09-09T08:33:39.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9811-087 + + + + + Vacation program allows command execution by remote users through a sendmail command. + + + + + + + + + + cpe:/a:php:php:2.0b10 + cpe:/a:php:php:1.0 + + CVE-1999-0058 + 1997-04-17T00:00:00.000-04:00 + 2008-09-09T08:33:39.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 712 + + Buffer overflow in PHP cgi program, php.cgi allows shell access. + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0059 + 1997-07-14T00:00:00.000-04:00 + 2008-09-09T08:33:39.243-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + irix-fam(325) + + + BID + 353 + + + OSVDB + 164 + + IRIX fam service allows an attacker to obtain a list of all files on the server. + + + + + + + + + + + + + + + + + + + + + cpe:/h:lucent:ascend_tnt_router:1.0 + cpe:/h:lucent:ascend_max_router:4.0 + cpe:/h:lucent:ascend_pipeline_router:5.0 + cpe:/h:lucent:ascend_pipeline_router:2.0 + cpe:/h:lucent:ascend_pipeline_router:3.0 + cpe:/h:lucent:ascend_max_router:1.0 + cpe:/h:lucent:ascend_max_router:2.0 + cpe:/h:lucent:ascend_tnt_router:2.0 + cpe:/h:lucent:ascend_pipeline_router:4.0 + cpe:/h:lucent:ascend_pipeline_router:1.0 + cpe:/h:lucent:ascend_max_router:3.0 + cpe:/h:lucent:ascend_max_router:5.0 + cpe:/h:lucent:ascend_pipeline_router:6.0 + + CVE-1999-0060 + 1998-03-16T00:00:00.000-05:00 + 2008-09-09T08:33:39.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool. + + + + + + + + + + + + cpe:/o:bsdi:bsd_os + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:openbsd:openbsd:2.1 + + CVE-1999-0061 + 1997-10-02T00:00:00.000-04:00 + 2008-09-09T08:33:39.383-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). + + + + + + + + + cpe:/o:openbsd:openbsd:2.3 + + CVE-1999-0062 + 1998-08-03T00:00:00.000-04:00 + 2008-09-09T08:33:39.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 7559 + + The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage. + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%281%29xb + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:12.0%281%29xa3 + cpe:/o:cisco:ios:12.0%281%29w + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.3aa + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0%281%29xe + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.0%282%29xc + cpe:/o:cisco:ios:11.3db + + CVE-1999-0063 + 1999-01-11T00:00:00.000-05:00 + 2008-09-09T08:33:39.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:4.1.3 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0064 + 1997-05-26T00:00:00.000-04:00 + 2008-09-09T08:33:39.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX lquerylv program gives root access to local users. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0065 + 1998-08-31T00:00:00.000-04:00 + 2008-09-09T08:33:39.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00181 + + Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands. + + + + + + + + + + cpe:/a:john_s._roberts:anyform:2.0 + cpe:/a:john_s._roberts:anyform:1.0 + + CVE-1999-0066 + 1995-07-31T00:00:00.000-04:00 + 2008-09-09T08:33:39.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 719 + + AnyForm CGI remote execution. + + + + + + + + + + cpe:/a:ncsa:ncsa_httpd:1.5a::export + cpe:/a:apache:http_server:1.0.3 + + CVE-1999-0067 + 1996-03-20T00:00:00.000-05:00 + 2008-09-09T08:33:39.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1996-06 + + + BID + 629 + + + OSVDB + 136 + + phf CGI program allows remote command execution through shell metacharacters. + + + + + + + + + + + cpe:/a:php:php:2.0b10 + cpe:/a:php:php:2.0 + cpe:/a:php:php:1.0 + + CVE-1999-0068 + 1997-10-19T00:00:00.000-04:00 + 2008-09-09T08:33:39.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 713 + + + OSVDB + 3396 + + CGI PHP mylog script allows an attacker to read any file on the target server. + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0069 + 1998-04-29T00:00:00.000-04:00 + 2008-09-09T08:33:39.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 8158 + + + SUN + 00169 + + Solaris ufsrestore buffer overflow. + + + + + + + + + + cpe:/a:apache:http_server + cpe:/a:ncsa:ncsa_web_server + + CVE-1999-0070 + 1996-04-01T00:00:00.000-05:00 + 2008-09-09T08:33:40.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + test-cgi program allows an attacker to list files on the server. + + + + + + + + + cpe:/a:apache:http_server:1.1.1 + + CVE-1999-0071 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:40.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0072 + 1997-10-22T00:00:00.000-04:00 + 2008-09-09T08:33:40.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX xdat gives root access to local users. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.1.1 + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:digital:unix:3.2g + cpe:/o:digital:osf_1:1.2 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:digital:osf_1:3.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:digital:osf_1:2.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:digital:osf_1:3.0 + cpe:/o:sgi:irix:6.3 + cpe:/o:digital:unix:4.0 + cpe:/o:digital:osf_1:1.3 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0073 + 1995-10-13T00:00:00.000-04:00 + 2008-09-09T08:33:40.210-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:microsoft:windows_nt + + CVE-1999-0074 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:40.273-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Listening TCP ports are sequentially allocated, allowing spoofing attacks. + + + + + + + + + cpe:/a:washington_university:wu-ftpd + + CVE-1999-0075 + 1996-10-16T00:00:00.000-04:00 + 2008-09-09T08:33:40.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 5742 + + PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password. + + + + + + + + + cpe:/a:washington_university:wu-ftpd + + CVE-1999-0076 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:40.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in wu-ftp from PASV command causes a core dump. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0077 + 1995-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:40.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tcp-seq-predict(139) + + Predictable TCP sequence numbers allow spoofing. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os + cpe:/o:ibm:aix:4.2 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:ibm:aix:4.1 + cpe:/a:ncr:mp-ras:3.0 + cpe:/o:nec:up-ux_v + cpe:/o:sco:unixware:2.1 + cpe:/o:sun:sunos:4.1 + cpe:/o:hp:hp-ux + cpe:/o:ibm:aix:3.2 + cpe:/o:sco:openserver:5 + cpe:/a:ncr:mp-ras:2.03 + cpe:/o:sgi:irix:5.3 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:next:nextstep + cpe:/a:ncr:mp-ras:3.01 + + CVE-1999-0078 + 1996-04-18T00:00:00.000-04:00 + 2008-09-09T08:33:40.557-04:00 + + + 1.9 + LOCAL + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. + + + + + + + + + cpe:/a:bisonware:bisonware_ftp_server:3.5 + + CVE-1999-0079 + 1997-09-12T00:00:00.000-04:00 + 2008-09-09T08:33:40.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports. + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.4 + + CVE-1999-0080 + 1995-11-30T00:00:00.000-05:00 + 2008-09-09T08:33:40.697-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command. + + + + + + + + + cpe:/a:washington_university:wu-ftpd + + CVE-1999-0081 + 1997-01-11T00:00:00.000-05:00 + 2008-09-09T08:33:40.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + wu-ftp allows files to be overwritten via the rnfr command. + + + + + + + + + + cpe:/a:ftp:ftp + cpe:/a:ftpcd:ftpcd + + CVE-1999-0082 + 1988-11-11T00:00:00.000-05:00 + 2008-09-09T08:33:40.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FarmerVenema + Improving the Security of Your Site by Breaking Into it + + CWD ~root command in ftpd allows root access. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0083 + 1997-06-11T00:00:00.000-04:00 + 2008-09-09T08:33:40.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + getcwd() file descriptor leak in FTP. + + + + + + + + + cpe:/a:sun:nfs + + CVE-1999-0084 + 1990-05-01T00:00:00.000-04:00 + 2008-09-05T16:16:25.283-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + nfs-mknod(78) + + Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0. + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0085 + 1996-08-21T00:00:00.000-04:00 + 2008-09-09T08:33:41.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + rwhod(119) + + + XF + rwhod-vuln(118) + + Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname. + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0086 + 1998-01-08T00:00:00.000-05:00 + 2008-09-09T08:33:41.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + AIX routed allows remote users to modify sensitive files. + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + + CVE-1999-0087 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:33:41.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7992 + + Denial of service in AIX telnet can freeze a system and prevent users from accessing the server. + + + + + + + + + cpe:/o:ibm:aix:4.3 + + CVE-1999-0088 + 1998-10-26T00:00:00.000-05:00 + 2008-09-05T16:16:25.877-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. + + + + + + + + + cpe:/o:ibm:aix:4.3 + + CVE-1999-0089 + 1997-10-28T00:00:00.000-05:00 + 2008-09-05T16:16:26.003-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX libDtSvc library can allow local users to gain root access. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0090 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:33:41.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX rcp command allows local users to obtain root access. + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0091 + 1997-10-28T00:00:00.000-05:00 + 2008-09-09T08:33:41.507-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX writesrv command allows local users to obtain root access. + + + + + + + + + cpe:/o:ibm:aix:4.2.1 + + CVE-1999-0092 + 1997-10-29T00:00:00.000-05:00 + 2008-09-09T08:33:41.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Various vulnerabilities in the AIX portmir command allows local users to obtain root access. + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0093 + 1997-10-29T00:00:00.000-05:00 + 2008-09-09T08:33:41.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0094 + 1997-10-29T00:00:00.000-05:00 + 2008-09-09T08:33:41.710-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + AIX piodmgrsu command allows local users to gain additional group privileges. + + + + + + + + + cpe:/a:eric_allman:sendmail:5.58 + + CVE-1999-0095 + 1988-10-01T00:00:00.000-04:00 + 2008-09-09T08:33:41.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1 + + + OSVDB + 195 + + The debug command in Sendmail is enabled, allowing attackers to execute commands as root. + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:bsdi:bsd_os + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.1.6.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:internet_faststart:1.1 + cpe:/o:sco:internet_faststart:1.0 + + CVE-1999-0096 + 1996-12-10T00:00:00.000-05:00 + 2008-09-09T08:33:41.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00122 + + Sendmail decode alias can be used to overwrite sensitive files. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:hp:hp-ux:9.10 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:ibm:aix:3.2 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:hp:hp-ux:9.03 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:hp:hp-ux:9.08 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:9.06 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:hp:hp-ux:9.09 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:sun:sunos:4.1.3c + cpe:/o:ibm:aix:4.2.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0097 + 1997-10-29T00:00:00.000-05:00 + 2008-09-09T08:33:41.960-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). + + + + + + + + + + + cpe:/a:pmail:mercury_mail_server + cpe:/a:apple:appleshare::::jp + cpe:/a:slmail:slmail:2.6 + + CVE-1999-0098 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:33:42.023-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:cray:unicos:8.3 + cpe:/o:convex:convexos:10.1 + cpe:/o:convex:convexos:10.2 + cpe:/o:ibm:aix:4.1 + cpe:/o:convex:spp-ux:3 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:convex:convexos:11.1 + cpe:/o:convex:convexos:11.0 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:cray:unicos:8.0 + cpe:/o:ibm:aix:3.2 + cpe:/o:cray:unicos:9.0 + cpe:/o:bsdi:bsd_os:2.0 + cpe:/o:bsdi:bsd_os:2.0.1 + + CVE-1999-0099 + 1995-10-19T00:00:00.000-04:00 + 2008-09-09T08:33:42.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in syslog utility allows local or remote attackers to gain root privileges. + + + + + + + + + cpe:/a:isc:inn:1.5.1 + + CVE-1999-0100 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:42.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Remote access in AIX innd 1.5.1, using control messages. + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0101 + 1996-12-10T00:00:00.000-05:00 + 2008-09-09T08:33:45.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + H-13 + + Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names. + + + + + + + + + cpe:/a:seattle_lab_software:slmail:3.0.2421 + + CVE-1999-0102 + 1998-07-09T00:00:00.000-04:00 + 2008-09-09T08:33:45.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line. + + + CVE-1999-0103 + 1996-02-08T00:00:00.000-05:00 + 2008-09-09T08:33:45.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm. + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux:2.0 + cpe:/o:microsoft:windows_95:0a + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:hp:hp-ux + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0104 + 1997-12-16T00:00:00.000-05:00 + 2009-03-04T00:00:14.640-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. + + + CVE-1999-0105 + 1997-03-01T00:00:00.000-05:00 + 2008-09-09T08:33:45.743-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + finger allows recursive searches by using a long string of @ symbols. + + + CVE-1999-0106 + 1997-03-01T00:00:00.000-05:00 + 2008-09-09T08:33:45.807-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Finger redirection allows finger bombs. + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:0.8.14 + cpe:/a:apache:http_server:1.0 + cpe:/a:apache:http_server:0.8.11 + cpe:/a:apache:http_server:1.1 + cpe:/a:apache:http_server:1.0.2 + cpe:/a:apache:http_server:1.2.5 + cpe:/a:apache:http_server:1.0.5 + cpe:/a:apache:http_server:1.1.1 + cpe:/a:apache:http_server:1.0.3 + + CVE-1999-0107 + 1997-12-30T00:00:00.000-05:00 + 2008-09-09T08:33:45.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. + + + + + + + + + cpe:/o:sgi:irix + + CVE-1999-0108 + 1998-05-01T00:00:00.000-04:00 + 2008-09-09T08:33:45.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The printers program in IRIX has a buffer overflow that gives root access to local users. + + + + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0109 + 1997-02-10T00:00:00.000-05:00 + 2008-09-09T08:33:46.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00140 + + Buffer overflow in ffbconfig in Solaris 2.5.1. + + + CVE-1999-0110 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:46.557-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0315. Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315. Notes: All CVE users should reference CVE-1999-0315 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0111 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:46.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + RIP v1 is susceptible to spoofing. + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/a:cde:cde + + CVE-1999-0112 + 1997-05-01T00:00:00.000-04:00 + 2008-09-09T08:33:46.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + dtterm-bo(878) + + Buffer overflow in AIX dtterm program for the CDE. + + + + + + + + + + + + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0113 + 1994-05-23T00:00:00.000-04:00 + 2008-09-09T08:33:46.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 458 + + Some implementations of rlogin allow root access if given a -froot parameter. + + + + + + + + + cpe:/a:elm_development_group:elm:2.4 + + CVE-1999-0114 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:46.837-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack. + + + + + + + + + + + + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0115 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:46.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1800 + + AIX bugfiler program allows local users to gain root access. + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/h:ibm:sng:2.1 + cpe:/h:ibm:sng:2.2 + cpe:/o:ibm:aix:3.2.5 + + CVE-1999-0116 + 1996-09-19T00:00:00.000-04:00 + 2008-09-09T08:33:46.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00136 + + + SGI + 19961202-01-PX + + Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood. + + + + + + + + + + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0117 + 1992-03-31T00:00:00.000-05:00 + 2008-09-09T08:33:47.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + AIX passwd allows local users to gain root access. + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0118 + 1998-11-01T00:00:00.000-05:00 + 2008-09-09T08:33:48.180-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981119 RSI.0011.11-09-98.AIX.INFOD + + AIX infod allows local users to gain root access through an X display. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0::beta + + CVE-1999-0119 + 1999-01-19T00:00:00.000-05:00 + 2008-09-05T16:16:30.393-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows NT 4.0 beta allows users to read and delete shares. + + + + + + + + + + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:sunos:4.1 + + CVE-1999-0120 + 1994-03-21T00:00:00.000-05:00 + 2008-09-09T08:33:48.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00126 + + Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root. + + + CVE-1999-0121 + 1999-01-21T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in dtaction command gives root access. + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0122 + 1997-07-21T00:00:00.000-04:00 + 2008-09-09T08:33:48.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in AIX lchangelv gives root access. + + + + + + + + + cpe:/o:slackware:slackware_linux:3.0 + + CVE-1999-0123 + 1995-12-01T00:00:00.000-05:00 + 2008-09-05T16:16:30.923-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Race condition in Linux mailx command allows local users to read user files. + + + + + + + + + cpe:/a:university_of_minnesota:gopherd + + CVE-1999-0124 + 1993-08-09T00:00:00.000-04:00 + 2008-09-09T08:33:48.587-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sgi:irix:5.3 + cpe:/o:sun:solaris:2.6 + cpe:/o:sgi:irix:5.2 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:redhat:linux:4.2 + cpe:/o:sgi:irix:6.3 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0125 + 1998-01-25T00:00:00.000-05:00 + 2008-09-09T08:33:48.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SGI + 19980605-01-PX + + Buffer overflow in SGI IRIX mailx program. + + + + + + + + + cpe:/a:xfree86_project:xfree86 + + CVE-1999-0126 + 1998-05-03T00:00:00.000-04:00 + 2008-09-09T08:33:48.727-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + J-010 + + SGI IRIX buffer overflow in xterm and Xaw allows root access. + + + + + + + + + cpe:/o:hp:hp-ux + + CVE-1999-0127 + 1996-12-19T00:00:00.000-05:00 + 2008-09-09T08:33:48.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/h:ibm:sng:2.1 + cpe:/h:ibm:sng:2.2 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:linux:linux_kernel:1.3.0 + cpe:/o:sco:tcp_ip:1.2.1 + cpe:/o:ibm:aix:3.2 + cpe:/o:digital:osf_1:1.3.3 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:linux:linux_kernel:2.0 + cpe:/o:sco:openserver:5.0 + cpe:/h:ibm:sng + cpe:/o:sco:internet_faststart:1.1 + cpe:/o:sun:sunos:5.4 + cpe:/o:sco:internet_faststart:1.0 + cpe:/o:sun:sunos:5.5 + + CVE-1999-0128 + 1996-12-18T00:00:00.000-05:00 + 2008-09-09T08:33:48.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:ibm:aix:4.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:ibm:aix:3.2 + cpe:/a:eric_allman:sendmail:8.8.2 + cpe:/a:eric_allman:sendmail:8.8.3 + cpe:/a:eric_allman:sendmail:8.8.1 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:sco:internet_faststart:1.1 + cpe:/o:sco:internet_faststart:1.0 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:freebsd:freebsd:2.1.6.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/a:eric_allman:sendmail:8.8 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:sco:openserver:5.0 + + CVE-1999-0129 + 1996-12-03T00:00:00.000-05:00 + 2008-09-09T08:33:48.930-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/a:caldera:network_desktop:1.0 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/a:eric_allman:sendmail:8.8.2 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/a:eric_allman:sendmail:8.8.1 + cpe:/a:eric_allman:sendmail:8.7 + cpe:/a:eric_allman:sendmail:8.8 + cpe:/o:redhat:linux:4.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0130 + 1996-11-16T00:00:00.000-05:00 + 2008-09-09T08:33:49.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 716 + + Local users can start Sendmail in daemon mode and gain root privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:ibm:aix:4.1 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:redhat:linux:3.0.3 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sco:openserver:5.0.2 + cpe:/a:eric_allman:sendmail:8.7.5 + cpe:/o:ibm:aix:3.2 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/a:eric_allman:sendmail:8.6 + cpe:/a:eric_allman:sendmail:8.7.4 + cpe:/a:eric_allman:sendmail:8.7.3 + cpe:/o:digital:osf_1:1.3.2 + cpe:/a:eric_allman:sendmail:8.7.2 + cpe:/a:eric_allman:sendmail:8.7.1 + cpe:/o:sco:openserver:5.0 + cpe:/o:bsdi:bsd_os:2.1 + cpe:/o:sco:internet_faststart:1.0 + + CVE-1999-0131 + 1996-09-11T00:00:00.000-04:00 + 2008-09-09T08:33:49.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 717 + + Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:hp:hp-ux:10 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:hp:hp-ux:9 + cpe:/o:sun:sunos:4.1.3c + + CVE-1999-0132 + 1996-08-15T00:00:00.000-04:00 + 2008-09-09T08:33:49.133-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1996-19 + + + XF + expreserve(401) + + + OSVDB + 11723 + + Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. + + + + + + + + + cpe:/a:adobe:framemaker + + CVE-1999-0133 + 1996-08-14T00:00:00.000-04:00 + 2008-09-09T08:33:49.210-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access. + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sun:sunos:5.4 + cpe:/o:sun:sunos:5.5 + + CVE-1999-0134 + 1996-08-06T00:00:00.000-04:00 + 2008-09-09T08:33:49.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 8159 + + vold in Solaris 2.x allows local users to gain root access. + + + + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0135 + 1996-07-25T00:00:00.000-04:00 + 2008-09-09T08:33:49.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + admintool in Solaris allows a local user to write to arbitrary files and gain root access. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.5 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0136 + 1996-07-31T00:00:00.000-04:00 + 2008-09-09T08:33:49.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access. + + + + + + + + + cpe:/a:fred_n._van_kempen:dip:3.3.7o + + CVE-1999-0137 + 1996-07-09T00:00:00.000-04:00 + 2008-09-09T08:33:49.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The dip program on many Linux systems allows local users to gain root access via a buffer overflow. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:nec:asl_ux_4800 + cpe:/o:hp:hp-ux:8 + cpe:/o:hp:hp-ux:9 + cpe:/o:apple:a_ux:3.1.1 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:nec:up-ux_v:4.2mp + cpe:/o:ibm:aix:4 + cpe:/o:nec:ews-ux_v:4.2 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:linux:linux_kernel:1.2.0 + cpe:/o:linux:linux_kernel:2.0 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:nec:ews-ux_v:4.2mp + cpe:/o:digital:osf_1:1.3 + cpe:/o:ibm:aix:3.2.5 + + CVE-1999-0138 + 1996-06-26T00:00:00.000-04:00 + 2008-09-09T08:33:49.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-1999-0139 + 1998-12-12T00:00:00.000-05:00 + 2008-09-09T08:33:49.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 8205 + + Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0140 + 1999-06-30T00:00:00.000-04:00 + 2008-09-05T16:16:33.893-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in RAS/PPTP on NT systems. + + + + + + + + + cpe:/a:netscape:navigator:2.02 + + CVE-1999-0141 + 1996-03-29T00:00:00.000-05:00 + 2008-09-09T08:33:49.757-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00134 + + Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. + + + + + + + + + + cpe:/a:sun:java + cpe:/a:netscape:navigator + + CVE-1999-0142 + 1996-03-01T00:00:00.000-05:00 + 2008-09-09T08:33:49.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/a:mit:kerberos:5 + cpe:/a:mit:kerberos:4.0 + cpe:/a:process_software:multinet:3.4 + cpe:/a:process_software:multinet:3.5 + + CVE-1999-0143 + 1996-02-21T00:00:00.000-05:00 + 2008-09-09T08:33:49.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. + + + CVE-1999-0144 + 1997-06-01T00:00:00.000-04:00 + 2005-10-20T00:00:00.000-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qmail-rcpt + + + BID + 2237 + + + MISC + http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html + + + MISC + http://cr.yp.to/qmail/venema.html + + + BUGTRAQ + 19970612 Re: Denial of service (qmail-smtpd) + + + BUGTRAQ + 19970612 qmail-dos-2.c, another denial of service attack + + Denial of service in Qmail by specifying a large number of recipients with the RCPT command. + + + + + + + + + cpe:/a:eric_allman:sendmail + + CVE-1999-0145 + 1993-09-30T00:00:00.000-04:00 + 2008-09-09T08:33:50.680-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1993-14 + + + CERT + CA-1990-11 + + + BUGTRAQ + 19950206 sendmail wizard thing... + + + FarmerVenema + Improving the Security of Your Site by Breaking Into it + + Sendmail WIZ command enabled, allowing root access. + + + + + + + + + + cpe:/a:ncsa:campas + cpe:/a:ncsa:servers + + CVE-1999-0146 + 1997-07-15T00:00:00.000-04:00 + 2008-09-09T08:33:50.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + http-cgi-campas(298) + + + BID + 1975 + + The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. + + + + + + + + + + cpe:/a:university_of_arizona:webglimpse:1.5 + cpe:/a:university_of_arizona:glimpse_http:2.0 + + CVE-1999-0147 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:50.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0148 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:50.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 380 + + + SGI + 19970501-02-PX + + The handler CGI program in IRIX allows arbitrary command execution. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-1999-0149 + 1997-04-19T00:00:00.000-04:00 + 2008-09-09T08:33:50.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + http-sgi-wrap(290) + + + BID + 373 + + + OSVDB + 247 + + + SGI + 19970501-02-PX + + The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack. + + + + + + + + + cpe:/a:gnu:fingerd + + CVE-1999-0150 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:51.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The Perl fingerd program allows arbitrary command execution from remote users. + + + + + + + + + + cpe:/a:satan:satan:1.0 + cpe:/a:satan:satan:1.1 + + CVE-1999-0151 + 1995-04-03T00:00:00.000-04:00 + 2008-09-09T08:33:52.570-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access. + + + + + + + + + cpe:/a:data_general:dg_ux + + CVE-1999-0152 + 1997-08-11T00:00:00.000-04:00 + 2008-09-09T08:33:52.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The DG/UX finger daemon allows remote command execution through shell metacharacters. + + + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/o:sco:openserver:5.0 + cpe:/o:microsoft:windows_nt + + CVE-1999-0153 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:52.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1666 + + Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:2.0 + + CVE-1999-0154 + 1999-12-31T00:00:00.000-05:00 + 2008-09-09T08:33:52.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. + + + + + + + + + + cpe:/a:aladdin_enterprises:ghostscript:2.6 + cpe:/a:aladdin_enterprises:ghostscript:3.22 + + CVE-1999-0155 + 1995-08-31T00:00:00.000-04:00 + 2008-09-09T08:33:52.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The ghostscript command with the -dSAFER option allows remote attackers to execute commands. + + + + + + + + + cpe:/a:washington_university:wu-ftpd + + CVE-1999-0156 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:52.947-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + wu-ftpd FTP daemon allows any user and password combination. + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.3t + cpe:/o:cisco:pix_firewall:4.2%281%29 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:11.2p + + CVE-1999-0157 + 1998-08-18T00:00:00.000-04:00 + 2008-09-09T08:33:53.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1097 + + + + + Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. + + + + + + + + + + cpe:/o:cisco:pix_firewall:4.2%281%29 + cpe:/o:cisco:pix_firewall:4.1%286%29 + + CVE-1999-0158 + 1998-08-31T00:00:00.000-04:00 + 2008-09-09T08:33:53.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010913 Cisco PIX Firewall Manager File Exposure + + + OSVDB + 685 + + Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:9.1 + cpe:/o:cisco:ios:11.2%2810%29 + cpe:/o:cisco:ios:11.1%2816%29 + cpe:/o:cisco:ios:11.2%288%29sa3 + cpe:/o:cisco:ios:11.1%2816%29ia + cpe:/o:cisco:ios:11.3%281%29ed + cpe:/o:cisco:ios:11.1%2817%29ct + cpe:/o:cisco:ios:11.2%2810%29bc + cpe:/o:cisco:ios:11.3%281%29 + cpe:/o:cisco:ios:11.1%2815%29ca + cpe:/o:cisco:ios:11.1%2816%29aa + cpe:/o:cisco:ios:11.0%2820.3%29 + cpe:/o:cisco:ios:11.1%2817%29cc + cpe:/o:cisco:ios:11.3%281%29t + cpe:/o:cisco:ios:11.2%289%29xa + cpe:/o:cisco:ios:11.2%289%29p + + CVE-1999-0159 + 1998-08-12T00:00:00.000-04:00 + 2008-09-09T08:33:53.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases. + + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.0 + cpe:/o:cisco:ios:9.1 + cpe:/o:cisco:ios:4.1 + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:10.3 + cpe:/o:cisco:ios:11.2 + cpe:/o:cisco:ios:11.2p + + CVE-1999-0160 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:33:53.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 1099 + + + + + Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. + + + + + + + + + + cpe:/o:cisco:ios:10.3%284.2%29 + cpe:/o:cisco:ios:10.3%283.4%29 + + CVE-1999-0161 + 1995-07-31T00:00:00.000-04:00 + 2008-09-09T08:33:53.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 797 + + + + + In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. + + + + + + + + + cpe:/o:cisco:ios:11.2 + + CVE-1999-0162 + 1998-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:53.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. + + + + + + + + + cpe:/a:eric_allman:sendmail + + CVE-1999-0163 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:53.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + In older versions of Sendmail, an attacker could use a pipe character to execute root commands. + + + + + + + + + + + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sun:sunos:5.3 + cpe:/o:sun:sunos:5.4 + + CVE-1999-0164 + 1995-08-29T00:00:00.000-04:00 + 2008-09-09T08:33:53.493-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 8346 + + A race condition in the Solaris ps command allows an attacker to overwrite critical files. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os + cpe:/o:sun:solaris:2.3 + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:sunos:3.5 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + cpe:/o:sun:sunos:4.0 + cpe:/o:sun:sunos:4.0.1 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:sunos:4.0.2 + cpe:/o:sun:sunos:4.0.3 + cpe:/a:sun:nfs + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sun:solaris:1.2 + cpe:/o:sun:solaris:1.1 + + CVE-1999-0165 + 1997-03-01T00:00:00.000-05:00 + 2008-09-09T08:33:53.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + NFS cache poisoning. + + + + + + + + + cpe:/a:sun:nfs + + CVE-1999-0166 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:53.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + NFS allows users to use a "cd .." command to access other directories besides the exported file system. + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + + CVE-1999-0167 + 1991-12-06T00:00:00.000-05:00 + 2008-09-09T08:33:53.697-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. + + + + + + + + + + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.3 + + CVE-1999-0168 + 1992-06-04T00:00:00.000-04:00 + 2008-09-09T08:33:53.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. + + + + + + + + + cpe:/a:sun:nfs + + CVE-1999-0169 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:53.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + NFS allows attackers to read and write any file on the system by specifying a false UID. + + + + + + + + + cpe:/o:digital:ultrix + + CVE-1999-0170 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:53.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0171 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:53.977-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in syslog by sending it a large number of superfluous messages. + + + + + + + + + cpe:/a:matt_wright:formmail + + CVE-1999-0172 + 1995-08-02T00:00:00.000-04:00 + 2008-09-09T08:33:54.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + FormMail CGI program allows remote execution of commands. + + + + + + + + + cpe:/a:matt_wright:formmail + + CVE-1999-0173 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + FormMail CGI program can be used by web servers other than the host server that the program resides on. + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.05 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.07 + + CVE-1999-0174 + 1997-02-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.180-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:novell:web_server:1.0 + + CVE-1999-0175 + 1996-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:54.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server. + + + + + + + + + cpe:/a:webgais_development_team:webgais:1.0b2 + + CVE-1999-0176 + 1997-07-10T00:00:00.000-04:00 + 2008-09-09T08:33:54.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The Webgais program allows a remote user to execute arbitrary commands. + + + + + + + + + cpe:/a:oreilly:website:2.0 + + CVE-1999-0177 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:54.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. + + + + + + + + + cpe:/a:oreilly:oreilly_website:1.1e + + CVE-1999-0178 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + http-website-winsample(295) + + + BID + 2078 + + + OSVDB + 8 + + + BUGTRAQ + 19970106 Re: signal handling + + Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string. + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0179 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q140818 + + Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. + + + CVE-1999-0180 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + in.rshd allows users to login with a NULL username and execute commands. + + + + + + + + + cpe:/a:rpc.walld:rpc.walld + + CVE-1999-0181 + 1994-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:54.790-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands. + + + + + + + + + cpe:/a:samba:samba:1.9.17:p2 + + CVE-1999-0182 + 1997-09-30T00:00:00.000-04:00 + 2008-09-09T08:33:54.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + H-110 + + Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password. + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/a:tftp:tftp + + CVE-1999-0183 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:54.947-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Linux implementations of TFTP would allow access to files outside the restricted directory. + + + + + + + + + cpe:/a:isc:bind:9.4.0 + + CVE-1999-0184 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:55.007-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0185 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:33:55.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00156 + + In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. + + + + + + + + + cpe:/o:sun:solaris:2.6 + + CVE-1999-0186 + 1998-10-01T00:00:00.000-04:00 + 2008-09-09T08:33:55.227-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm + + In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. + + + CVE-1999-0187 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:33:59.307-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0188 + 1998-12-17T00:00:00.000-05:00 + 2008-09-09T08:33:59.367-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00182 + + The passwd command in Solaris can be subjected to a denial of service. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0189 + 1997-06-04T00:00:00.000-04:00 + 2008-09-09T08:33:59.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUN + 00142 + + Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0190 + 1998-04-08T00:00:00.000-04:00 + 2008-09-09T08:33:59.507-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00167 + + Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + + CVE-1999-0191 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:33:59.570-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 275 + + IIS newdsn.exe CGI script allows remote users to overwrite files. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:slackware:slackware_linux:3.5 + cpe:/o:slackware:slackware_linux:3.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:slackware:slackware_linux:3.3 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:slackware:slackware_linux:4.0 + cpe:/o:slackware:slackware_linux:3.6 + cpe:/o:redhat:linux:4.0 + cpe:/o:slackware:slackware_linux:3.9 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0192 + 1997-10-18T00:00:00.000-04:00 + 2008-09-09T08:33:59.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. + + + + + + + + + cpe:/a:ascend:cascadeview_ux:1.0 + + CVE-1999-0193 + 1997-12-01T00:00:00.000-05:00 + 2008-09-09T08:33:59.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. + + + CVE-1999-0194 + 1999-05-01T00:00:00.000-04:00 + 2008-09-09T08:33:59.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in in.comsat allows attackers to generate messages. + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:sgi:irix + + CVE-1999-0195 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:33:59.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. + + + + + + + + + cpe:/a:webgais_development_team:webgais:1.0 + + CVE-1999-0196 + 1997-07-08T00:00:00.000-04:00 + 2008-09-09T08:33:59.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2077 + + + OSVDB + 237 + + websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable). + + + CVE-1999-0197 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + finger 0@host on some systems may print information on some user accounts. + + + CVE-1999-0198 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + finger .@host on some systems may print information on some user accounts. + + + CVE-1999-0200 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. + + + + + + + + + cpe:/a:ftp:ftp + + CVE-1999-0201 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:00.197-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. + + + + + + + + + cpe:/a:university_of_washington:wu-ftpd:2.4.1 + + CVE-1999-0202 + 1997-01-01T00:00:00.000-05:00 + 2010-03-26T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. + + + + + + + + + cpe:/a:eric_allman:sendmail:8.6.10 + + CVE-1999-0203 + 1995-08-17T00:00:00.000-04:00 + 2008-09-09T08:34:00.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program. + + + + + + + + + cpe:/a:eric_allman:sendmail:8.6.9 + + CVE-1999-0204 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:00.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. + + + + + + + + + + cpe:/a:eric_allman:sendmail:8.6.11 + cpe:/a:eric_allman:sendmail:8.6.12 + + CVE-1999-0205 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:00.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Sendmail 8.6.11 and 8.6.12. + + + + + + + + + + cpe:/a:eric_allman:sendmail:8.8.1 + cpe:/a:eric_allman:sendmail:8.8 + + CVE-1999-0206 + 1996-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:00.913-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. + + + + + + + + + + cpe:/a:great_circle_associates:majordomo:1.90 + cpe:/a:great_circle_associates:majordomo:1.91 + + CVE-1999-0207 + 1994-06-09T00:00:00.000-04:00 + 2008-09-09T08:34:00.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:nec:up-ux_v + cpe:/o:nec:ews-ux_v + cpe:/o:nec:asl_ux_4800 + cpe:/o:sgi:irix:4 + cpe:/o:sgi:irix:3 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0208 + 1995-12-12T00:00:00.000-05:00 + 2008-09-09T08:34:01.057-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. + + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.0.1 + cpe:/o:sun:sunos:3.5 + cpe:/o:sun:sunos:4.0.2 + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1 + cpe:/o:sun:sunos:4.0 + + CVE-1999-0209 + 1990-08-14T00:00:00.000-04:00 + 2008-09-09T08:34:01.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 8 + + The SunView (SunTools) selection_svc facility allows remote users to read files. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0210 + 1997-11-26T00:00:00.000-05:00 + 2008-09-09T08:34:01.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-99-05 + + + HP + HPSBUX9910-104 + + + BID + 235 + + + BUGTRAQ + 19990103 SUN almost has a clue! (automountd) + + + BUGTRAQ + 19971126 Solaris 2.5.1 automountd exploit (fwd) + + + + + Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + + CVE-1999-0211 + 1994-02-14T00:00:00.000-05:00 + 2008-09-09T08:34:01.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 24 + + Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone. + + + + + + + + + + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:sunos + + CVE-1999-0212 + 1998-04-29T00:00:00.000-04:00 + 2008-09-09T08:34:01.337-04:00 + + + 7.8 + NETWORK + LOW + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + I-048 + + Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server. + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0213 + 1998-07-15T00:00:00.000-04:00 + 2008-09-09T08:34:01.397-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. + + + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + + CVE-1999-0214 + 1992-07-21T00:00:00.000-04:00 + 2008-09-09T08:34:01.507-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service by sending forged ICMP unreachable packets. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0215 + 1998-10-26T00:00:00.000-05:00 + 2008-09-09T08:34:01.633-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + J-012 + + + SGI + 19981004-01-PX + + Routed allows attackers to append data to files. + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/a:gnu:inet:5.01 + cpe:/o:hp:hp-ux:10 + + CVE-1999-0216 + 1997-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:01.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service of inetd on Linux through SYN and RST packets. + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1psr_a + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + cpe:/o:sun:sunos:4.0.3c + cpe:/o:sun:sunos:4.1.3a1 + + CVE-1999-0217 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:01.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems. + + + + + + + + + cpe:/h:livingston_portmaster:portmaster + + CVE-1999-0218 + 1995-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:01.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Livingston portmaster machines could be rebooted via a series of commands. + + + + + + + + + cpe:/a:cat_soft:serv-u:2.5 + + CVE-1999-0219 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:01.930-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ftp-servu(205) + + + BID + 269 + + + NTBUGTRAQ + 19990504 Re: Buffer overflows in FTP Serv-U 2.5 + + + NTBUGTRAQ + 19990503 Buffer overflows in FTP Serv-U 2.5 + + Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command. + + + CVE-1999-0220 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Attackers can do a denial of service of IRC by crashing the server. + + + + + + + + + cpe:/h:lucent:ascend_routers + + CVE-1999-0221 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:02.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service of Ascend routers through port 150 (remote administration). + + + + + + + + + cpe:/h:cisco:router + + CVE-1999-0222 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:02.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. + + + + + + + + + cpe:/o:sun:solaris:2.4 + + CVE-1999-0223 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:02.197-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1878 + + + CONFIRM + http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&collection=fpatches + + Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0224 + 1999-07-23T00:00:00.000-04:00 + 2008-09-09T08:34:02.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Windows NT messenger service through a long username. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0225 + 1998-02-14T00:00:00.000-05:00 + 2008-09-09T08:34:02.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NAI + 19980214 Windows NT Logon Denial of Service + + + MSKB + Q180963 + + Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. + + + CVE-1999-0226 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0227 + 1997-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:02.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q154087 + + Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0228 + 1997-02-07T00:00:00.000-05:00 + 2008-09-09T08:34:02.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q162567 + + Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. + + + + + + + + + cpe:/a:microsoft:internet_information_server + + CVE-1999-0229 + 1999-05-12T00:00:00.000-04:00 + 2008-09-09T08:34:02.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Windows NT IIS server using ..\.. + + + + + + + + + + + cpe:/o:cisco:ios:4.1 + cpe:/o:cisco:ios:4.1.2 + cpe:/o:cisco:ios:4.1.1 + + CVE-1999-0230 + 1997-12-15T00:00:00.000-05:00 + 2008-09-09T08:34:02.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1102 + + Buffer overflow in Cisco 7xx routers through the telnet service. + + + + + + + + + cpe:/a:seattle_lab_software:slmail:2.6 + + CVE-1999-0231 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:16:46.843-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. + + + CVE-1999-0232 + 1995-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in NCSA WebServer (version 1.5c) gives remote access. + + + + + + + + + cpe:/a:microsoft:internet_information_server:1.0 + + CVE-1999-0233 + 1996-02-25T00:00:00.000-05:00 + 2010-12-30T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MSKB + Q155056 + + + MSKB + Q148188 + + IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. + + + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux + cpe:/o:redhat:linux:3.0.3 + cpe:/o:yggdrasil:linux + cpe:/o:sgi:irix + cpe:/o:suse:suse_linux:4.2 + + CVE-1999-0234 + 1996-10-08T00:00:00.000-04:00 + 2008-09-09T08:34:03.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Bash treats any character with a value of 255 as a command separator. + + + + + + + + + + + cpe:/a:ncsa:ncsa_web_server:1.4.1 + cpe:/a:ncsa:ncsa_web_server:1.3 + cpe:/a:ncsa:ncsa_web_server:1.4 + + CVE-1999-0235 + 1995-02-17T00:00:00.000-05:00 + 2008-09-09T08:34:03.210-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. + + + + + + + + + + cpe:/a:apache:http_server + cpe:/a:ncsa:servers + + CVE-1999-0236 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.273-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. + + + + + + + + + cpe:/a:webcom:cgi_guestbook + + CVE-1999-0237 + 1997-09-01T00:00:00.000-04:00 + 2008-09-09T08:34:03.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Remote execution of arbitrary commands through Guestbook CGI program. + + + + + + + + + + + cpe:/a:php:php:2.0b10 + cpe:/a:php:php:2.0 + cpe:/a:php:php:1.0 + + CVE-1999-0238 + 1997-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:03.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + php.cgi allows attackers to read any file on the system. + + + + + + + + + cpe:/a:netscape:fasttrack_server:3.01 + + CVE-1999-0239 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 122 + + Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. + + + CVE-1999-0240 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy. + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sgi:irix + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/a:xfree86_project:x11r6 + + CVE-1999-0241 + 1995-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.617-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. + + + + + + + + + cpe:/o:slackware:slackware_linux + + CVE-1999-0242 + 1995-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. + + + CVE-1999-0243 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Linux cfingerd could be exploited to gain root access. + + + + + + + + + cpe:/a:livingston:radius:1.x + + CVE-1999-0244 + 1997-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:03.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0245 + 1995-09-07T00:00:00.000-04:00 + 2008-09-09T08:34:03.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Some configurations of NIS+ in Linux allowed attackers to log in as the user "+". + + + + + + + + + cpe:/o:hp:hp-ux + + CVE-1999-0246 + 1996-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:03.960-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + HP Remote Watch allows a remote user to gain root access. + + + + + + + + + + + + + + + cpe:/a:isc:inn:1.4sec2 + cpe:/a:isc:inn:1.5.1 + cpe:/a:isc:inn:1.4 + cpe:/a:isc:inn:1.4unoff3 + cpe:/a:isc:inn:1.4sec + cpe:/a:isc:inn:1.5 + cpe:/a:isc:inn:1.4unoff4 + + CVE-1999-0247 + 1997-07-21T00:00:00.000-04:00 + 2008-09-09T08:34:04.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1443 + + + NAI + 19970721 INN news server vulnerabilities + + Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands. + + + + + + + + + cpe:/a:ssh:ssh:1.2.27 + + CVE-1999-0248 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:16:49.157-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1 + + + MISC + http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html + + A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0249 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:04.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Windows NT RSHSVC program allows remote users to execute arbitrary commands. + + + + + + + + + cpe:/a:dan_bernstein:qmail:1.01 + + CVE-1999-0250 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:04.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html + + + MISC + http://cr.yp.to/qmail/venema.html + + + BUGTRAQ + 19970612 qmail-dos-2.c, another denial of service attack + + Denial of service in Qmail through long SMTP commands. + + + + + + + + + cpe:/a:talkd:talkd + + CVE-1999-0251 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:04.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in talk program allows remote attackers to disrupt a user's display. + + + + + + + + + cpe:/a:lsoft:listserv + + CVE-1999-0252 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:08.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in listserv allows arbitrary command execution. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:2.0 + cpe:/a:microsoft:internet_information_server:1.0 + + CVE-1999-0253 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:08.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. + + + + + + + + + cpe:/o:sun:solaris:2.6 + + CVE-1999-0254 + 1998-11-02T00:00:00.000-05:00 + 2008-09-09T08:34:08.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. + + + CVE-1999-0255 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in ircd allows arbitrary command execution. + + + + + + + + + + + + + + + cpe:/a:jgaa:warftpd:1.66 + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt + + CVE-1999-0256 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:08.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 875 + + Buffer overflow in War FTP allows remote execution of commands. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0257 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:08.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Nestea variation of teardrop IP fragmentation denial of service. + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt + + CVE-1999-0258 + 1998-02-13T00:00:00.000-05:00 + 2008-09-09T08:34:08.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Bonk variation of teardrop IP fragmentation denial of service. + + + + + + + + + cpe:/a:infodrom:cfingerd:1.2.2 + + CVE-1999-0259 + 1997-05-23T00:00:00.000-04:00 + 2008-09-09T08:34:08.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + cfingerd lists all users on a system via search.**@target. + + + + + + + + + cpe:/a:renaud_deraison:jj + + CVE-1999-0260 + 1996-12-24T00:00:00.000-05:00 + 2008-09-09T08:34:08.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The jj CGI program allows command execution via shell metacharacters. + + + CVE-1999-0261 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:08.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.insecure.org/sploits/netmanage.chameleon.overflows.html + + Netmanager Chameleon SMTPd has several buffer overflows that cause a crash. + + + + + + + + + cpe:/a:renaud_deraison:faxsurvey + + CVE-1999-0262 + 1998-08-04T00:00:00.000-04:00 + 2008-09-09T08:34:09.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + http-cgi-faxsurvey(1532) + + + BID + 2056 + + Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6:hw5 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.6:hw5:x86 + cpe:/o:sun:solaris:2.6:hw3:x86 + + CVE-1999-0263 + 1998-07-16T00:00:00.000-04:00 + 2008-09-09T08:34:09.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00173 + + Solaris SUNWadmap can be exploited to obtain root access. + + + + + + + + + cpe:/a:miva:htmlscript + + CVE-1999-0264 + 1998-01-27T00:00:00.000-05:00 + 2008-09-09T08:34:09.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + htmlscript CGI program allows remote read access to files. + + + + + + + + + + cpe:/o:novell:netware:3.12 + cpe:/o:microware:os-9 + + CVE-1999-0265 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q154174 + + ICMP redirect messages may crash or lock up a host. + + + + + + + + + cpe:/a:roar_smith:info2www + + CVE-1999-0266 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1995 + + The info2www CGI script allows remote file access or remote command execution. + + + + + + + + + cpe:/a:ncsa:ncsa_httpd:1.3 + + CVE-1999-0267 + 1997-09-23T00:00:00.000-04:00 + 2008-09-09T08:34:09.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. + + + + + + + + + cpe:/a:metainfo:metaweb + + CVE-1999-0268 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 3969 + + + OSVDB + 110 + + MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. + + + + + + + + + cpe:/a:netscape:enterprise_server + + CVE-1999-0269 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:09.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Netscape Enterprise servers may list files through the PageServices query. + + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0270 + 1998-04-03T00:00:00.000-05:00 + 2011-03-07T21:00:25.437-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sgi-pfdispaly(810) + + + BID + 64 + + + OSVDB + 134 + + + CIAC + I-041 + + + SGI + 19980401-01-P + + Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. + + + CVE-1999-0271 + 1998-01-15T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Progressive Networks Real Video server (pnserver) can be crashed remotely. + + + + + + + + + cpe:/a:slmail:slmail:3.0.2421 + + CVE-1999-0272 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:09.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Slmail v2.5 through the POP3 port. + + + + + + + + + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0273 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service through Solaris 2.5.1 telnet by sending ^D characters. + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0274 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0275 + 1997-06-10T00:00:00.000-04:00 + 2008-09-09T08:34:09.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. + + + + + + + + + + cpe:/a:hughes:msql:2.0. + cpe:/a:hughes:msql:2.0.1 + + CVE-1999-0276 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:09.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + mSQL v2.0.1 and below allows remote execution through a buffer overflow. + + + + + + + + + cpe:/o:sun:solaris:2.0 + + CVE-1999-0277 + 1996-10-28T00:00:00.000-05:00 + 2008-09-09T08:34:10.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The WorkMan program can be used to overwrite any file to get root access. + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0278 + 1998-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:10.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS98-003 + + + + + In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. + + + + + + + + + cpe:/a:excite:ews:1.1 + + CVE-1999-0279 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:10.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Excite for Web Servers (EWS) allows remote command execution via shell metacharacters. + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:microsoft:ie:3.0.1 + + CVE-1999-0280 + 1997-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:10.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Remote command execution in Microsoft Internet Explorer using .lnk and .url files. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:2.0 + + CVE-1999-0281 + 1997-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:10.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in IIS using long URLs. + + + CVE-1999-0282 + 1997-09-23T00:00:00.000-04:00 + 2008-09-09T08:34:13.757-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1584, CVE-1999-1586. Reason: This candidate combined references from one issue with the description from another issue. Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + CVE-1999-0283 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970716 Viewable .jhtml source with JavaWebServer + + The Java Web Server would allow remote users to obtain the source code for CGI programs. + + + + + + + + + + + cpe:/a:ibm:lotus_domino_mail_server + cpe:/a:microsoft:exchange_server:4.0 + cpe:/a:microsoft:exchange_server:5.0 + + CVE-1999-0284 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:13.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0285 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:16:54.203-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. + + + CVE-1999-0286 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. + + + + + + + + + cpe:/a:webcom:cgi_guestbook + + CVE-1999-0287 + 1999-04-09T00:00:00.000-04:00 + 2008-09-09T08:34:14.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Vulnerability in the Wguest CGI program. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0288 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:14.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-winsupd-fix(1233) + + + MISC + http://safenetworks.com/Windows/wins.html + + The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. + + + + + + + + + cpe:/a:apache:http_server + + CVE-1999-0289 + 1999-12-12T00:00:00.000-05:00 + 2008-09-05T16:16:54.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. + + + + + + + + + cpe:/a:qbik:wingate + + CVE-1999-0290 + 1998-02-21T00:00:00.000-05:00 + 2008-09-09T08:34:14.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost. + + + + + + + + + cpe:/a:qbik:wingate + + CVE-1999-0291 + 1999-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:14.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + + CVE-1999-0292 + 1997-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:14.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service through Winpopup using large user names. + + + + + + + + + cpe:/o:cisco:ios + + CVE-1999-0293 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:14.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + AAA authentication on Cisco systems allows attackers to execute commands without authorization. + + + + + + + + + cpe:/a:microsoft:wins + + CVE-1999-0294 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:14.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + All records in a WINS database can be deleted through SNMP for a denial of service. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0295 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:14.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00157 + + Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.6 + + CVE-1999-0296 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:14.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00162 + + Solaris volrmmount program allows attackers to read any file. + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:redhat:linux + cpe:/a:paul_vixie:vixie_cron:3.0 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0297 + 1996-12-12T00:00:00.000-05:00 + 2008-09-09T08:34:14.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable. + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1.3 + cpe:/o:slackware:slackware_linux:2.2 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:slackware:slackware_linux:2.1 + cpe:/o:slackware:slackware_linux:2.3 + + CVE-1999-0298 + 1997-02-05T00:00:00.000-05:00 + 2008-09-09T08:34:14.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + NAI + 19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme + + ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. + + + + + + + + + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0299 + 1997-03-05T00:00:00.000-05:00 + 2008-09-05T16:16:56.250-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 6093 + + Buffer overflow in FreeBSD lpd through long DNS hostnames. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0300 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:15.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00155 + + nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0301 + 1997-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:15.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00149 + + Buffer overflow in SunOS/Solaris ps command. + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0302 + 1998-09-01T00:00:00.000-04:00 + 2008-09-09T08:34:15.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUN + 00176 + + SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:1.1.4::jl + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:1.1.3:u1 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.2 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:digital:osf_1:1.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:solaris:1.2 + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sun:solaris:1.1.4 + cpe:/o:sun:solaris:1.1 + + CVE-1999-0303 + 1998-05-21T00:00:00.000-04:00 + 2008-09-09T08:34:15.807-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames. + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0304 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:15.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + mmap function in BSD allows local attackers in the kmem group to modify memory through devices. + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0305 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:15.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-sourceroute(736) + + + OSVDB + 11502 + + + MISC + http://www.openbsd.org/advisories/sourceroute.txt + + The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections. + + + + + + + + + cpe:/o:hp:vvos:10.24 + + CVE-1999-0306 + 1997-11-04T00:00:00.000-05:00 + 2008-09-09T08:34:16.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + buffer overflow in HP xlock program. + + + + + + + + + + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:10.00 + + CVE-1999-0307 + 2000-12-20T00:00:00.000-05:00 + 2008-09-09T08:34:16.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in HP-UX cstm program allows local users to gain root privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:8 + cpe:/o:hp:hp-ux:9 + + CVE-1999-0308 + 1996-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:16.197-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9410-018 + + HP-UX gwind program allows users to modify arbitrary files. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.24 + + CVE-1999-0309 + 1997-02-01T00:00:00.000-05:00 + 2013-07-21T00:11:26.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9702-056 + + HP-UX vgdisplay program gives root access to local users. + + + + + + + + + cpe:/a:ssh:ssh:1.2.25 + + CVE-1999-0310 + 1998-09-01T00:00:00.000-04:00 + 2008-09-09T08:34:16.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + SSH 1.2.25 on HP-UX allows access to new user accounts. + + + + + + + + + cpe:/o:hp:hp-ux:10 + + CVE-1999-0311 + 1996-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:16.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9612-042 + + fpkg2swpk in HP-UX allows local users to gain root access. + + + + + + + + + cpe:/o:hp:hp-ux + + CVE-1999-0312 + 1993-01-13T00:00:00.000-05:00 + 2008-09-09T08:34:16.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + HP ypbind allows attackers with root privileges to modify NIS data. + + + + + + + + + cpe:/o:sgi:irix:6.4::s2mp + + CVE-1999-0313 + 1998-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:16.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-disk-bandwidth(1441) + + + BID + 214 + + + MISC + http://www.securityfocus.com/bid/213/exploit + + + OSVDB + 936 + + + SGI + 19980701-01-P + + disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames. + + + + + + + + + cpe:/o:sgi:irix:6.4 + + CVE-1999-0314 + 1998-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:16.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-ioconfig(1199) + + + MISC + http://www.securityfocus.com/bid/213/exploit + + + BID + 213 + + + OSVDB + 6788 + + + SGI + 19980701-01-P + + ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0315 + 1997-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:16.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00138 + + Buffer overflow in Solaris fdformat command gives root access to local users. + + + + + + + + + cpe:/a:sam_lantinga:splitvt:1.6.3 + + CVE-1999-0316 + 1995-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:16.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Linux splitvt command gives root access to local users. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0317 + 1999-11-25T00:00:00.000-05:00 + 2008-09-09T08:34:16.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Linux su command gives root access to local users. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11 + cpe:/o:sun:solaris:7.0 + cpe:/o:ibm:aix:4 + cpe:/o:sun:solaris:8.0 + cpe:/o:redhat:linux:6.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0318 + 1997-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:16.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. + + + CVE-1999-0319 + 1996-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:16.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0320 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.040-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. + + + + + + + + + cpe:/o:sun:solaris + + CVE-1999-0321 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Solaris kcms_configure command allows local users to gain root access. + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0322 + 1997-10-29T00:00:00.000-05:00 + 2008-09-09T08:34:17.163-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6092 + + The open() function in FreeBSD allows local attackers to write to arbitrary files. + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0323 + 1998-02-20T00:00:00.000-05:00 + 2008-09-09T08:34:17.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NETBSD + 1998-003 + + FreeBSD mmap function allows users to modify append-only or immutable files. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-0324 + 1996-09-01T00:00:00.000-04:00 + 2008-09-09T08:34:17.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9702-053 + + ppl program in HP-UX allows local users to create root files through symlinks. + + + + + + + + + + cpe:/o:hp:hp-ux:8 + cpe:/o:hp:hp-ux:9 + + CVE-1999-0325 + 1995-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9406-013 + + vhe_u_mnt program in HP-UX allows local users to create root files through symlinks. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:9 + cpe:/o:hp:hp-ux:10.30 + + CVE-1999-0326 + 1997-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:17.557-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9710-071 + + Vulnerability in HP-UX mediainit program. + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0327 + 1997-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 19971103-01-PX + + SGI syserr program allows local users to corrupt files. + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-0328 + 1997-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19971103-01-PX + + SGI permissions program allows local users to gain root privileges. + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-0329 + 1998-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:17.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19980602-01-PX + + SGI mediad program allows local users to gain root access. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0330 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Linux bdash game has a buffer overflow that allows local users to gain root access. + + + + + + + + + + + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0331 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Buffer overflow in Internet Explorer 4.0(1). + + + + + + + + + cpe:/a:microsoft:netmeeting:2.1 + + CVE-1999-0332 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:17.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MSKB + Q184346 + + Buffer overflow in NetMeeting allows denial of service and remote command execution. + + + + + + + + + cpe:/o:hp:hp-ux + + CVE-1999-0333 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:18.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack. + + + + + + + + + + cpe:/o:sun:solaris:::x86 + cpe:/o:sun:solaris:2.0 + + CVE-1999-0334 + 1993-12-16T00:00:00.000-05:00 + 2008-09-09T08:34:18.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0335 + 1996-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:18.180-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-1999-0032. + + + + + + + + + cpe:/o:hp:hp-ux:10 + + CVE-1999-0336 + 1996-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:18.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in mstm in HP-UX allows local users to gain root access. + + + + + + + + + + + + + cpe:/o:ibm:aix:1.2.1 + cpe:/o:ibm:aix:2.2.1 + cpe:/o:ibm:aix:1.3 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0337 + 1994-06-03T00:00:00.000-04:00 + 2008-09-09T08:34:18.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled. + + + + + + + + + + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:3.2.5 + + CVE-1999-0338 + 1994-02-24T00:00:00.000-05:00 + 2008-09-09T08:34:18.383-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + AIX Licensed Program Product performance tools allow local users to gain root access. + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0339 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:18.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. + + + + + + + + + cpe:/o:slackware:slackware_linux:3.4 + + CVE-1999-0340 + 1997-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:18.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Linux Slackware crond program allows local users to gain root access. + + + + + + + + + + + + cpe:/o:debian:debian_linux:1.3.1 + cpe:/o:slackware:slackware_linux:2.2 + cpe:/o:slackware:slackware_linux:2.1 + cpe:/o:slackware:slackware_linux:2.3 + + CVE-1999-0341 + 1998-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:18.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in the Linux mail program "deliver" allows local users to gain root access. + + + + + + + + + cpe:/a:pam:pam:0.64 + + CVE-1999-0342 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:18.663-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Linux PAM modules allow local users to gain root access using temporary files. + + + + + + + + + cpe:/a:palace:palace_client + + CVE-1999-0343 + 1998-10-02T00:00:00.000-04:00 + 2008-09-09T08:34:18.727-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + A malicious Palace server can force a client to execute arbitrary programs. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0344 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:18.790-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MSKB + Q190288 + + + MS + MS98-009 + + NT users can gain debug-level access on a system process using the Sechole exploit. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/h:ibm:sng:2.1 + cpe:/h:ibm:sng:2.2 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:freebsd:freebsd:1.2 + cpe:/o:freebsd:freebsd:1.1 + cpe:/o:sco:open_desktop:3 + cpe:/o:ibm:aix:3.2 + cpe:/o:sco:openserver:5 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:1.0 + cpe:/o:sun:sunos + cpe:/o:sco:internet_faststart:1.1 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:sco:internet_faststart:1.0 + + CVE-1999-0345 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:18.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. + + + + + + + + + cpe:/a:php:php_fi + + CVE-1999-0346 + 1997-10-16T00:00:00.000-04:00 + 2008-09-09T08:34:18.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 713 + + + OSVDB + 3397 + + CGI PHP mlog script allows an attacker to read any file on the target server. + + + CVE-1999-0347 + 1999-01-26T00:00:00.000-05:00 + 2005-11-02T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19990126 Javascript ecurity bug in Internet Explorer + + + BUGTRAQ + 19990126 Javascript ecurity bug in Internet Explorer + + Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0348 + 1999-01-27T00:00:00.000-05:00 + 2008-09-09T08:34:19.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q197003 + + + OSVDB + 930 + + IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0349 + 1999-01-27T00:00:00.000-05:00 + 2008-09-09T08:34:19.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + EEYE + IIS Remote FTP Exploit/DoS Attack + + + MSKB + Q188348 + + + MS + MS99-003 + + A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. + + + + + + + + + cpe:/a:rational_software:clearcase:3.2 + + CVE-1999-0350 + 1999-02-08T00:00:00.000-05:00 + 2008-09-09T08:34:19.570-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. + + + + + + + + + cpe:/a:ftp:ftp_pasv + + CVE-1999-0351 + 1999-02-01T00:00:00.000-05:00 + 2008-09-05T16:17:03.967-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pasv-pizza-thief-dos(3389) + + + MISC + http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt + + FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client. + + + CVE-1999-0352 + 1999-01-25T00:00:00.000-05:00 + 2008-09-09T08:34:24.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-1999-0353 + 1999-02-10T00:00:00.000-05:00 + 2013-09-03T00:01:48.897-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9902-091 + + + CIAC + J-026 + + + + + rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:word:97 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0354 + 1999-11-01T00:00:00.000-05:00 + 2008-09-09T08:34:24.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS99-002 + + Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. + + + + + + + + + cpe:/a:ca:controlit:4.5 + + CVE-1999-0355 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:24.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service. + + + CVE-1999-0356 + 1999-01-25T00:00:00.000-05:00 + 2008-09-09T08:34:24.617-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book. + + + + + + + + + cpe:/o:microsoft:windows_98::gold + + CVE-1999-0357 + 1999-01-25T00:00:00.000-05:00 + 2008-09-09T08:34:24.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. + + + + + + + + + + + + + + cpe:/o:digital:unix:4.0e + cpe:/o:digital:unix:4.0d + cpe:/o:digital:unix:4.0c + cpe:/o:digital:unix:4.0b + cpe:/o:digital:unix:4.0a + cpe:/o:digital:unix:4.0 + + CVE-1999-0358 + 1999-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:24.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990125 Digital Unix 4.0 exploitable buffer overflows + + + CIAC + J-027 + + Digital Unix 4.0 has a buffer overflow in the inc program of the mh package. + + + + + + + + + cpe:/a:marc_schaefer:ptylogin + + CVE-1999-0359 + 2001-03-12T00:00:00.000-05:00 + 2008-09-09T08:34:24.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords. + + + + + + + + + cpe:/a:microsoft:site_server:2.0 + + CVE-1999-0360 + 1999-01-30T00:00:00.000-05:00 + 2008-09-05T16:17:05.140-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990130 Security Advisory for Internet Information Server 4 with Site + + MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. + + + CVE-1999-0361 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging. + + + + + + + + + + cpe:/a:ipswitch:ws_ftp_server:1.0.2eval + cpe:/a:ipswitch:ws_ftp_server:1.0.1eval + + CVE-1999-0362 + 1999-02-02T00:00:00.000-05:00 + 2008-09-09T08:34:25.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 217 + + + EEYE + AD02021999 + + WS_FTP server remote denial of service through cwd command. + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:5.2 + cpe:/a:plp:line_printer_control + + CVE-1999-0363 + 1999-02-02T00:00:00.000-05:00 + 2008-09-09T08:34:25.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 328 + + SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise. + + + + + + + + + + cpe:/a:fms_inc.:total_vb_sourcebook:6.0 + cpe:/a:microsoft:access:97 + + CVE-1999-0364 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:05.670-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990204 Microsoft Access 97 Stores Database Password as Plaintext + + Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. + + + + + + + + + + + cpe:/a:metainfo:sendmail:2.0 + cpe:/a:metainfo:metaip:3.1 + cpe:/a:metainfo:sendmail:2.5 + + CVE-1999-0365 + 1999-02-04T00:00:00.000-05:00 + 2008-09-09T08:34:25.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp4 + + CVE-1999-0366 + 1999-02-08T00:00:00.000-05:00 + 2008-09-09T08:34:25.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MSKB + Q214840 + + + MS + MS99-004 + + In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + + CVE-1999-0367 + 1999-02-09T00:00:00.000-05:00 + 2008-09-09T08:34:25.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7571 + + NetBSD netstat command allows local users to access kernel memory. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:sco:openserver:5.0.3 + cpe:/o:slackware:slackware_linux:3.5 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:redhat:linux:5.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:redhat:linux:5.0 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:caldera:openlinux:1.3 + cpe:/o:slackware:slackware_linux:3.6 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:openserver:5.0 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18 + cpe:/a:proftpd_project:proftpd:1.2_pre1 + + CVE-1999-0368 + 1999-02-09T00:00:00.000-05:00 + 2008-09-09T08:34:25.447-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:1.1.4::jl + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:1.1.3:u1 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sun:solaris:1.2 + cpe:/o:sun:solaris:1.1.4 + cpe:/o:sun:solaris:1.1 + + CVE-1999-0369 + 1997-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:25.507-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00183 + + The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0370 + 1999-02-10T00:00:00.000-05:00 + 2008-09-09T08:34:25.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 165 + + In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files. + + + + + + + + + cpe:/a:university_of_kansas:lynx:2.7.1 + + CVE-1999-0371 + 1999-02-11T00:00:00.000-05:00 + 2008-09-09T08:34:25.647-04:00 + + + 1.2 + LOCAL + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Lynx allows a local user to overwrite sensitive files through /tmp symlinks. + + + + + + + + + + + + + + + cpe:/a:microsoft:backoffice:4.0 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0372 + 1999-02-12T00:00:00.000-05:00 + 2008-09-09T08:34:25.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q217004 + + + MS + MS99-005 + + The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. + + + + + + + + + cpe:/o:debian:debian_linux:2.0 + + CVE-1999-0373 + 1999-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:25.773-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root. + + + + + + + + + cpe:/o:debian:debian_linux:2.0 + + CVE-1999-0374 + 1999-02-16T00:00:00.000-05:00 + 2008-09-09T08:34:25.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Debian GNU/Linux cfengine package is susceptible to a symlink attack. + + + + + + + + + cpe:/a:network_flight_recorder:network_flight_recorder:2.0.3 + + CVE-1999-0375 + 1999-02-16T00:00:00.000-05:00 + 2008-09-09T08:34:25.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0376 + 1999-02-20T00:00:00.000-05:00 + 2008-09-09T08:34:25.977-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS99-006 + + Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. + + + + + + + + + cpe:/o:unix:unix + + CVE-1999-0377 + 1999-02-22T00:00:00.000-05:00 + 2008-09-09T08:34:26.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall + + CVE-1999-0378 + 1999-02-22T00:00:00.000-05:00 + 2008-09-09T08:34:26.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6167 + + InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands. + + + + + + + + + cpe:/a:microsoft:backoffice_resource_kit:2.0 + + CVE-1999-0379 + 1999-02-22T00:00:00.000-05:00 + 2008-09-09T08:34:26.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 498 + + + OSVDB + 1019 + + + MS + MS99-007 + + Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. + + + + + + + + + cpe:/a:seattle_lab_software:slmail:3.0.2421 + + CVE-1999-0380 + 1999-02-25T00:00:00.000-05:00 + 2008-09-09T08:34:26.257-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + slmail-ras-ntfs-bypass(5392) + + + BID + 497 + + + NTBUGTRAQ + SLmail 3.2 Build 3113 (Web Administration Security Fix) + + + NTBUGTRAQ + 199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service + + + BUGTRAQ + 19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service + + SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:debian:debian_linux:2.0 + + CVE-1999-0381 + 1999-02-26T00:00:00.000-05:00 + 2008-09-09T08:34:26.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 342 + + + BUGTRAQ + 19990225 SUPER buffer overflow + + super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:3.5.1:sp3 + cpe:/o:microsoft:windows_nt:3.5.1:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:3.5.1:sp2 + cpe:/o:microsoft:windows_nt:3.5.1:sp4 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1:sp1 + + CVE-1999-0382 + 1999-03-12T00:00:00.000-05:00 + 2008-09-09T08:34:26.397-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS99-008 + + The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges. + + + + + + + + + cpe:/a:acc:tigris:10.5.8 + + CVE-1999-0383 + 1999-02-02T00:00:00.000-05:00 + 2008-09-09T08:34:26.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 183 + + + OSVDB + 267 + + ACC Tigris allows public access without a login. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:project:98 + cpe:/a:microsoft:visual_basic:5.0 + cpe:/a:microsoft:outlook:98 + cpe:/o:microsoft:windows_2000 + cpe:/a:microsoft:office:98::mac + cpe:/o:microsoft:windows_nt + + CVE-1999-0384 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:26.523-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS99-001 + + The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + + CVE-1999-0385 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:26.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS99-009 + + The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. + + + + + + + + + + cpe:/a:microsoft:personal_web_server:4.0 + cpe:/a:microsoft:frontpage + + CVE-1999-0386 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:26.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 111 + + + MS + MS99-010 + + Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-1999-0387 + 1999-11-29T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 829 + + + MS + MS99-052 + + + MSKB + Q168115 + + A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. + + + + + + + + + cpe:/a:datalynx:suguard:1.0 + + CVE-1999-0388 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:26.807-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 3186 + + DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root. + + + + + + + + + + + + + cpe:/o:debian:debian_linux:1.3.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:1.1 + cpe:/o:debian:debian_linux:1.2 + cpe:/o:debian:debian_linux:1.3 + + CVE-1999-0389 + 1999-01-03T00:00:00.000-05:00 + 2008-09-09T08:34:26.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 324 + + Buffer overflow in the bootp server in the Debian Linux netstd package. + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:suse:suse_linux:5.0 + cpe:/o:suse:suse_linux:5.1 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0390 + 1999-01-04T00:00:00.000-05:00 + 2008-09-09T08:34:27.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 187 + + + CALDERA + CSSA-1999-006.1 + + Buffer overflow in Dosemu Slang library in Linux. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:3.5.1:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:3.5.1:sp2 + cpe:/o:microsoft:windows_nt:3.5.1:sp4 + cpe:/o:microsoft:windows_nt:3.5.1:sp1 + + CVE-1999-0391 + 1999-01-05T00:00:00.000-05:00 + 2008-09-09T08:34:27.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. + + + + + + + + + cpe:/a:thomas_boutell:cgic_library:1.05 + + CVE-1999-0392 + 1999-01-10T00:00:00.000-05:00 + 2008-09-09T08:34:27.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in Thomas Boutell's cgic library version up to 1.05. + + + + + + + + + + cpe:/a:eric_allman:sendmail:8.8 + cpe:/a:eric_allman:sendmail:8.9.2 + + CVE-1999-0393 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:27.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990121 Sendmail 8.8.x/8.9.x bugware + + Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. + + + CVE-1999-0394 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + DPEC Online Courseware allows an attacker to change another user's password without knowing the original password. + + + + + + + + + cpe:/a:backweb_technologies:backweb_polite_agent_protocol + + CVE-1999-0395 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:27.430-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 19990118 Vulnerability in the BackWeb Polite Agent Protocol + + A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server. + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:openbsd:openbsd:2.4 + + CVE-1999-0396 + 1999-02-17T00:00:00.000-05:00 + 2008-09-09T08:34:27.523-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service. + + + CVE-1999-0397 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. + + + + + + + + + + cpe:/a:ssh:ssh2:2.0.11 + cpe:/a:ssh:ssh:1.2.27 + + CVE-1999-0398 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:27.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc:5.5 + + CVE-1999-0399 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:27.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.0 + + CVE-1999-0400 + 1999-01-26T00:00:00.000-05:00 + 2008-09-05T16:17:11.140-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 344 + + Denial of service in Linux 2.2.0 running the ldd command on a core file. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.1 + + CVE-1999-0401 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:27.867-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. + + + + + + + + + cpe:/a:gnu:wget:1.5.3 + + CVE-1999-0402 + 1999-01-02T00:00:00.000-05:00 + 2008-09-09T08:34:29.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. + + + + + + + + + cpe:/h:cyrix:linux + + CVE-1999-0403 + 1999-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:29.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990204 Cyrix bug: freeze in hell, badboy + + A bug in Cyrix CPUs on Linux allows local users to perform a denial of service. + + + + + + + + + cpe:/a:smartmax_software:mailmax + + CVE-1999-0404 + 1999-02-14T00:00:00.000-05:00 + 2008-09-09T08:34:29.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:5.2 + cpe:/o:suse:suse_linux:5.3 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:suse:suse_linux:5.0 + cpe:/o:suse:suse_linux:5.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:suse:suse_linux:6.0 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:suse:suse_linux:4.4.1 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:debian:debian_linux:2.0.5 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:suse:suse_linux:4.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:suse:suse_linux:4.3 + cpe:/o:suse:suse_linux:4.4 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + + CVE-1999-0405 + 1999-02-18T00:00:00.000-05:00 + 2008-09-09T08:34:29.930-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 3163 + + A buffer overflow in lsof allows local users to obtain root privilege. + + + + + + + + + cpe:/o:digital:unix + + CVE-1999-0406 + 1999-02-19T00:00:00.000-05:00 + 2008-09-09T08:34:30.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0407 + 1999-02-09T00:00:00.000-05:00 + 2008-09-05T16:17:12.187-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990209 Re: IIS4 allows proxied password attacks over NetBIOS + + + BUGTRAQ + 19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS + + By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. + + + + + + + + + cpe:/a:sun:cobalt_raq + + CVE-1999-0408 + 1999-02-25T00:00:00.000-05:00 + 2008-09-09T08:34:30.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 337 + + Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server. + + + + + + + + + + cpe:/o:suse:suse_linux:5.2 + cpe:/o:suse:suse_linux:3.5 + + CVE-1999-0409 + 1999-03-04T00:00:00.000-05:00 + 2008-09-09T08:34:30.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 319 + + Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access. + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + + CVE-1999-0410 + 1999-03-05T00:00:00.000-05:00 + 2008-09-09T08:34:30.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 293 + + The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access. + + + + + + + + + + cpe:/o:sco:openserver:5 + cpe:/o:sco:openserver:3.0 + + CVE-1999-0411 + 1999-03-07T00:00:00.000-05:00 + 2008-09-09T08:34:30.383-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:internet_information_server:2.0 + + CVE-1999-0412 + 1999-02-19T00:00:00.000-05:00 + 2008-09-09T08:34:30.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 501 + + In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0413 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:30.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19990301-01-PX + + A buffer overflow in the SGI X server allows local users to gain root access through the X server font path. + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.0.37 + cpe:/o:linux:linux_kernel:2.0.35 + cpe:/o:linux:linux_kernel:2.0.36 + cpe:/o:linux:linux_kernel:2.0.30 + + CVE-1999-0414 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:30.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection. + + + + + + + + + + cpe:/h:cisco:cisco_7xx_routers:3.2 + cpe:/h:cisco:cisco_7xx_routers:4.2 + + CVE-1999-0415 + 1999-03-11T00:00:00.000-05:00 + 2008-09-09T08:34:30.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 19990311 Cisco 7xx TCP and HTTP Vulnerabilities + + + CIAC + J-034 + + The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. + + + + + + + + + cpe:/h:cisco:cisco_7xx_routers + + CVE-1999-0416 + 1999-03-11T00:00:00.000-05:00 + 2008-09-09T08:34:30.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 19990311 Cisco 7xx TCP and HTTP Vulnerabilities + + + CIAC + J-034 + + Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port. + + + + + + + + + cpe:/o:sun:solaris:7.0 + + CVE-1999-0417 + 1999-03-09T00:00:00.000-05:00 + 2008-09-09T08:34:30.807-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 448 + + + OSVDB + 1001 + + 64 bit Solaris 7 procfs allows local users to perform a denial of service. + + + CVE-1999-0418 + 1999-03-08T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990308 SMTP server account probing + + Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection. + + + CVE-1999-0419 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:30.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. + + + + + + + + + cpe:/a:netbsd:umapfs + + CVE-1999-0420 + 1999-03-17T00:00:00.000-05:00 + 2008-09-09T08:34:31.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program. + + + + + + + + + cpe:/o:slackware:slackware_linux:3.6 + + CVE-1999-0421 + 1999-03-17T00:00:00.000-05:00 + 2008-09-09T08:34:31.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 338 + + + OSVDB + 981 + + During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password. + + + + + + + + + cpe:/o:netbsd:netbsd:1.3.3 + + CVE-1999-0422 + 1999-03-17T00:00:00.000-05:00 + 2008-09-09T08:34:31.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set. + + + + + + + + + cpe:/o:hp:hp-ux + + CVE-1999-0423 + 1994-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:31.210-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9903-093 + + Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges. + + + + + + + + + cpe:/a:netscape:communicator:4.5 + + CVE-1999-0424 + 1999-03-18T00:00:00.000-05:00 + 2008-09-09T08:34:31.273-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes. + + + + + + + + + cpe:/a:netscape:communicator:4.5 + + CVE-1999-0425 + 1999-03-18T00:00:00.000-05:00 + 2008-09-09T08:34:31.337-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes. + + + + + + + + + cpe:/o:suse:suse_linux:6.0 + + CVE-1999-0426 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:31.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. + + + + + + + + + + + + cpe:/a:qualcomm:eudora_light:3.0 + cpe:/a:qualcomm:eudora:4.3 + cpe:/a:qualcomm:eudora:4.2 + cpe:/a:qualcomm:eudora_pro:1.00 + + CVE-1999-0427 + 2000-05-01T00:00:00.000-04:00 + 2008-09-09T08:34:31.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names. + + + + + + + + + + cpe:/a:ssleay:ssleay + cpe:/a:openssl:openssl + + CVE-1999-0428 + 1999-03-22T00:00:00.000-05:00 + 2008-09-09T08:34:31.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 3936 + + OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls. + + + + + + + + + cpe:/a:ibm:lotus_notes:4.5 + + CVE-1999-0429 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:31.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990326 Re: Lotus Notes security advisory + + + BUGTRAQ + 19990326 Lotus Notes Encryption Bug + + + BUGTRAQ + 19990324 Re: LNotes encryption + + + BUGTRAQ + 19990323 + + The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference. + + + + + + + + + + + + + + + + + cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.502 + cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.5 + cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.501 + cpe:/a:cisco:catalyst_12xx_supervisor_software:4.29 + cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.5 + cpe:/a:cisco:catalyst_5xxx_supervisor_software:1.0 + cpe:/a:cisco:catalyst_29xx_supervisor_software:1.0 + cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.502 + cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.501 + + CVE-1999-0430 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:31.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1103 + + Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.1.89 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.15_pre20 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.2.16:pre6 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.15:pre16 + cpe:/o:linux:linux_kernel:2.2.13 + + CVE-1999-0431 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:31.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-1999-0432 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:31.820-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9903-094 + + + + + ftp on HP-UX 11.00 allows local users to gain privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/o:suse:suse_linux:5.2 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:suse:suse_linux:5.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:slackware:slackware_linux:3.5 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:slackware:slackware_linux:3.3 + cpe:/o:suse:suse_linux:6.0 + cpe:/o:slackware:slackware_linux:4.0 + cpe:/o:slackware:slackware_linux:3.6 + + CVE-1999-0433 + 1999-03-21T00:00:00.000-05:00 + 2008-09-09T08:34:31.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:5.3 + cpe:/o:debian:debian_linux:2.0:r5 + cpe:/o:caldera:openlinux:1.2 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:redhat:linux:5.1 + + CVE-1999-0434 + 1999-03-30T00:00:00.000-05:00 + 2008-09-09T08:34:31.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 359 + + XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-1999-0435 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM. + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/a:hp:desms + + CVE-1999-0436 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9903-095 + + + + + Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges. + + + + + + + + + cpe:/h:ramp_networks:webramp + + CVE-1999-0437 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port. + + + + + + + + + + cpe:/h:ramp_networks:webramp_m3:1.0 + cpe:/h:ramp_networks:webramp_200i:1.0 + + CVE-1999-0438 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address. + + + + + + + + + + + + + + cpe:/o:caldera:openlinux + cpe:/a:procmail:procmail:3.12 + + CVE-1999-0439 + 1999-04-05T00:00:00.000-04:00 + 2008-09-09T08:34:32.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file. + + + + + + + + + + + + + + + + + + + + + cpe:/a:sun:java + cpe:/a:netscape:navigator:4.0 + cpe:/a:netscape:navigator:4.08 + cpe:/a:netscape:navigator:4.06 + cpe:/a:netscape:navigator:4.07 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:navigator:4.01 + cpe:/a:netscape:navigator:4.61 + cpe:/a:netscape:navigator:4.5 + cpe:/a:netscape:navigator:4.04 + cpe:/a:netscape:navigator:4.05 + cpe:/a:netscape:navigator:4.02 + cpe:/a:netscape:navigator:4.03 + + CVE-1999-0440 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://java.sun.com/pr/1999/03/pr990329-01.html + + + BID + 1939 + + + BUGTRAQ + 19990405 Security Hole in Java 2 (and JDK 1.1.x) + + The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. + + + + + + + + + cpe:/a:qbik:wingate:3.0 + + CVE-1999-0441 + 1999-02-22T00:00:00.000-05:00 + 2008-09-09T08:34:32.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 509 + + + EEYE + AD02221999 + + Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0442 + 1999-01-07T00:00:00.000-05:00 + 2008-09-09T08:34:32.523-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 327 + + Solaris ff.core allows local users to modify files. + + + + + + + + + cpe:/a:bmc:patrol_agent:3.2.3 + + CVE-1999-0443 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990409 Patrol security bugs + + Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt + + CVE-1999-0444 + 1999-04-12T00:00:00.000-04:00 + 2008-09-09T08:34:32.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%281%29xb + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:12.0%282%29xg + cpe:/o:cisco:ios:12.0%281%29xa3 + cpe:/o:cisco:ios:12.0%282%29xf + cpe:/o:cisco:ios:12.0%281%29w + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0%281%29xe + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.0%282%29xc + + CVE-1999-0445 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1104 + + + + + In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + + CVE-1999-0446 + 1999-04-12T00:00:00.000-04:00 + 2008-09-09T08:34:32.837-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7051 + + Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS. + + + + + + + + + cpe:/o:hp:mpe_ix + + CVE-1999-0447 + 1999-04-01T00:00:00.000-05:00 + 2013-07-23T00:04:49.940-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBMP9904-006 + + Local users can gain privileges using the debug utility in the MPE/iX operating system. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0448 + 1999-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:32.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0449 + 1999-01-26T00:00:00.000-05:00 + 2008-09-09T08:34:33.040-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 193 + + + OSVDB + 4 + + + OSVDB + 3 + + + OSVDB + 2 + + The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:internet_information_server:2.0 + + CVE-1999-0450 + 1999-01-26T00:00:00.000-05:00 + 2009-06-24T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 194 + + In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.0 + + CVE-1999-0451 + 1999-01-19T00:00:00.000-05:00 + 2008-09-05T16:17:18.560-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 343 + + Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port. + + + CVE-1999-0452 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A service or application has a backdoor password that was placed there by the developer. + + + + + + + + + cpe:/h:cisco:router + + CVE-1999-0453 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:18.810-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). + + + CVE-1999-0454 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso. + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + + CVE-1999-0455 + 1999-12-25T00:00:00.000-05:00 + 2008-09-09T08:34:36.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 115 + + The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly. + + + + + + + + + + + cpe:/o:debian:debian_linux:1.3.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:1.3 + + CVE-1999-0457 + 1999-01-17T00:00:00.000-05:00 + 2008-09-09T08:34:36.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 317 + + Linux ftpwatch program allows local users to gain root privileges. + + + + + + + + + cpe:/a:l0pht:l0phtcrack:2.5 + + CVE-1999-0458 + 1999-01-06T00:00:00.000-05:00 + 2008-09-09T08:34:36.337-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 915 + + L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information. + + + CVE-1999-0459 + 1999-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:36.397-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.1 + cpe:/o:linux:linux_kernel:2.0 + cpe:/o:linux:linux_kernel:2.3.0 + + CVE-1999-0460 + 1999-02-19T00:00:00.000-05:00 + 2008-09-05T16:17:19.560-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 312 + + Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:sgi:irix + + CVE-1999-0461 + 1999-01-28T00:00:00.000-05:00 + 2008-09-09T08:34:36.540-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. + + + + + + + + + cpe:/o:suse:suse_linux:5.3 + + CVE-1999-0462 + 1999-03-17T00:00:00.000-05:00 + 2008-09-09T08:34:36.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 339 + + suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk. + + + + + + + + + cpe:/a:l0pht:l0phtcrack:2.5 + + CVE-1999-0463 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:36.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 19981201-01-PX + + Remote attackers can perform a denial of service using IRIX fcagent. + + + + + + + + + cpe:/a:tripwire:tripwire:1.2 + + CVE-1999-0464 + 1999-01-04T00:00:00.000-05:00 + 2008-09-05T16:17:20.123-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://marc.theaimsgroup.com/?l=bugtraq&m=91592136122066&w=2 + + + OSVDB + 6609 + + + BUGTRAQ + 19990104 Tripwire mess.. + + Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames. + + + CVE-1999-0465 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + + CVE-1999-0466 + 1999-04-21T00:00:00.000-04:00 + 2008-09-09T08:34:36.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 905 + + The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device. + + + + + + + + + cpe:/a:webcom:cgi_guestbook + + CVE-1999-0467 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:36.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-0468 + 1999-04-09T00:00:00.000-04:00 + 2008-09-09T08:34:37.023-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-012 + + Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-0469 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:37.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. + + + + + + + + + cpe:/o:novell:netware:4.0 + + CVE-1999-0470 + 1999-04-09T00:00:00.000-04:00 + 2008-09-09T08:34:37.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 482 + + A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted. + + + + + + + + + cpe:/a:winroute:winroute + + CVE-1999-0471 + 1999-04-09T00:00:00.000-04:00 + 2008-09-09T08:34:37.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button. + + + + + + + + + + + + + + cpe:/a:snmp:snmp + cpe:/h:network_appliance:netcache + + CVE-1999-0472 + 1999-04-07T00:00:00.000-04:00 + 2008-09-09T08:34:37.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it. + + + + + + + + + cpe:/a:andrew_tridgell:rsync:2.3.1 + + CVE-1999-0473 + 1999-04-07T00:00:00.000-04:00 + 2008-09-09T08:34:37.353-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 145 + + The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred. + + + + + + + + + cpe:/a:mirabilis:icq:99a_2.13build1700 + + CVE-1999-0474 + 1999-04-05T00:00:00.000-04:00 + 2008-09-09T08:34:37.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory. + + + + + + + + + cpe:/a:procmail:procmail + + CVE-1999-0475 + 1999-04-05T00:00:00.000-04:00 + 2008-09-09T08:34:37.493-04:00 + + + 1.2 + LOCAL + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. + + + + + + + + + cpe:/o:sco:openserver + + CVE-1999-0476 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:37.570-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user. + + + + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:3.12 + cpe:/a:allaire:coldfusion_server:2.0 + cpe:/a:allaire:coldfusion_server:3.0 + cpe:/a:allaire:coldfusion_server:3.11 + cpe:/a:allaire:coldfusion_server:3.01 + + CVE-1999-0477 + 1999-12-25T00:00:00.000-05:00 + 2008-09-05T16:17:21.920-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 115 + + The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly. + + + + + + + + + cpe:/a:sendmail:sendmail:8.9.2 + + CVE-1999-0478 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:34:37.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9904-097 + + + + + Denial of service in HP-UX sendmail 8.8.6 related to accepting connections. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.24 + cpe:/a:netscape:enterprise_server:3.6 + + CVE-1999-0479 + 1999-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:37.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9903-092 + + Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems. + + + + + + + + + cpe:/a:midnight_commander:midnight_commander:4 + + CVE-1999-0480 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:37.837-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. + + + + + + + + + cpe:/o:openbsd:openbsd:2.4 + + CVE-1999-0481 + 1999-03-22T00:00:00.000-05:00 + 2008-09-09T08:34:37.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7556 + + Denial of service in "poll" in OpenBSD. + + + + + + + + + cpe:/o:openbsd:openbsd + + CVE-1999-0482 + 1999-03-21T00:00:00.000-05:00 + 2008-09-09T08:34:37.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7557 + + OpenBSD kernel crash through TSS handling, as caused by the crashme program. + + + + + + + + + cpe:/o:openbsd:openbsd + + CVE-1999-0483 + 1999-02-25T00:00:00.000-05:00 + 2008-09-09T08:34:38.057-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6129 + + OpenBSD crash using nlink value in FFS and EXT2FS filesystems. + + + + + + + + + cpe:/o:openbsd:openbsd + + CVE-1999-0484 + 1999-02-23T00:00:00.000-05:00 + 2008-09-09T08:34:38.117-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6130 + + Buffer overflow in OpenBSD ping. + + + + + + + + + cpe:/o:openbsd:openbsd:2.4 + + CVE-1999-0485 + 1999-02-19T00:00:00.000-05:00 + 2008-09-09T08:34:38.197-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7558 + + Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. + + + + + + + + + cpe:/a:aol:instant_messenger:3.5 + + CVE-1999-0486 + 1998-02-01T00:00:00.000-05:00 + 2008-09-09T08:34:38.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0487 + 1999-05-01T00:00:00.000-04:00 + 2008-09-09T08:34:38.320-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-011 + + The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1:sp1 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0488 + 1999-04-21T00:00:00.000-04:00 + 2008-09-09T08:34:38.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS99-012 + + Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0489 + 1999-05-17T00:00:00.000-04:00 + 2008-09-05T16:17:23.640-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-015 + + MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0490 + 1999-04-21T00:00:00.000-04:00 + 2008-09-09T08:34:38.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS99-012 + + MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:gnu:bash:1.14.7 + cpe:/a:gnu:bash:1.14.6 + cpe:/a:gnu:bash:2.01 + cpe:/a:gnu:bash:1.14.5 + cpe:/a:gnu:bash:1.14.4 + cpe:/a:gnu:bash:2.02.1 + cpe:/a:gnu:bash:1.14.3 + cpe:/a:gnu:bash:2.05:a + cpe:/a:gnu:bash:1.14.2 + cpe:/a:gnu:bash:1.14.1 + cpe:/a:gnu:bash:1.14.0 + cpe:/a:gnu:bash:2.0 + cpe:/a:gnu:bash:2.01.1 + cpe:/a:gnu:bash:2.02 + cpe:/a:gnu:bash:2.03 + cpe:/a:gnu:bash:2.04 + cpe:/a:gnu:bash:2.05 + + CVE-1999-0491 + 1999-04-20T00:00:00.000-04:00 + 2014-12-31T10:18:18.390-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2014-12-31T10:09:30.480-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 119 + + The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute. + + + CVE-1999-0492 + 1999-04-23T00:00:00.000-04:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0493 + 1999-06-07T00:00:00.000-04:00 + 2008-09-09T08:34:38.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-99-05 + + + BID + 450 + + + CIAC + J-045 + + + SUN + 00186 + + + BUGTRAQ + 19990103 SUN almost has a clue! (automountd) + + rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd. + + + + + + + + + cpe:/a:wingate:wingate + + CVE-1999-0494 + 1998-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:38.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in WinGate proxy through a buffer overflow in POP3. + + + CVE-1999-0495 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0496 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:39.057-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MSKB + Q146965 + + A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin. + + + CVE-1999-0497 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Anonymous FTP is enabled. + + + CVE-1999-0498 + 1991-09-27T00:00:00.000-04:00 + 2008-09-09T08:34:39.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0499 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:39.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + NETBIOS share information may be published through SNMP registry keys in NT. + + + CVE-1999-0501 + 1998-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:39.337-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + A Unix account has a guessable password. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:redhat:linux:6.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0502 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:39.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Unix account has a default, null, blank, or missing password. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0503 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:39.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + A Windows NT local user or administrator account has a guessable password. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0504 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:56.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + A Windows NT local user or administrator account has a default, null, blank, or missing password. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0505 + 1998-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:56.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + A Windows NT domain user or administrator account has a guessable password. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0506 + 1998-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:56.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + A Windows NT domain user or administrator account has a default, null, blank, or missing password. + + + CVE-1999-0507 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An account on a router, firewall, or other network device has a guessable password. + + + CVE-1999-0508 + 1998-06-01T00:00:00.000-04:00 + 2008-09-09T08:34:57.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An account on a router, firewall, or other network device has a default, null, blank, or missing password. + + + CVE-1999-0509 + 1996-05-29T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands. + + + CVE-1999-0510 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A router or firewall allows source routed packets from arbitrary hosts. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0511 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + IP forwarding is enabled on a machine which is not a router or firewall. + + + CVE-1999-0512 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:linux:linux_kernel:2.1 + cpe:/o:linux:linux_kernel:2.0 + cpe:/o:digital:unix:4.0 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:digital:unix:3.2g + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:digital:unix:4.0d + cpe:/o:digital:unix:4.0c + cpe:/o:digital:unix:4.0b + cpe:/o:digital:unix:4.0a + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:freebsd:freebsd:2.1.0 + + CVE-1999-0513 + 1998-01-05T00:00:00.000-05:00 + 2008-09-09T08:34:57.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. + + + CVE-1999-0514 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target. + + + CVE-1999-0515 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv. + + + CVE-1999-0516 + 1998-08-01T00:00:00.000-04:00 + 2008-09-09T08:34:57.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An SNMP community name is guessable. + + + + + + + + + + + cpe:/o:sun:solaris:2.0 + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11.00 + + CVE-1999-0517 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An SNMP community name is the default (e.g. public), null, or missing. + + + + + + + + + cpe:/o:microsoft:windows_95 + + CVE-1999-0518 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A NETBIOS/SMB share password is guessable. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/a:microsoft:outlook:2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0519 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:57.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A NETBIOS/SMB share password is the default, null, or missing. + + + CVE-1999-0520 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical NETBIOS/SMB share has inappropriate access control. + + + CVE-1999-0521 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:58.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An NIS domain name is easily guessable. + + + CVE-1999-0522 + 1996-05-28T00:00:00.000-04:00 + 2008-09-09T08:34:58.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate. + + + CVE-1999-0523 + 1999-01-01T00:00:00.000-05:00 + 2010-12-01T00:00:00.000-05:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ICMP echo (ping) is allowed from arbitrary hosts. + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix + cpe:/o:microsoft:all_windows:abstract_cpe + cpe:/o:apple:mac_os + cpe:/o:santa_cruz_operation:sco_unix + cpe:/o:novell:netware + cpe:/o:ibm:os2 + cpe:/o:hp:tru64 + cpe:/o:cisco:ios + cpe:/o:windriver:bsdos + cpe:/o:apple:mac_os_x + cpe:/o:linux:linux_kernel + cpe:/o:hp:hp-ux + + CVE-1999-0524 + 1997-08-01T00:00:00.000-04:00 + 2014-11-04T21:02:24.447-05:00 + + + 0.0 + LOCAL + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CONFIRM + https://kc.mcafee.com/corporate/index?page=content&id=SB10053 + + + XF + icmp-timestamp(322) + + + XF + icmp-netmask(306) + + + OSVDB + 95 + + + MISC + http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434 + + + MISC + http://descriptions.securescout.com/tc/11011 + + + MISC + http://descriptions.securescout.com/tc/11010 + + ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. + + + CVE-1999-0525 + 1997-01-01T00:00:00.000-05:00 + 2014-11-24T14:41:36.463-05:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + IP traceroute is allowed from arbitrary hosts. + + + + + + + + + cpe:/a:x.org:x11:7.1_1.1.0 + + CVE-1999-0526 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:59.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#704969 + + An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. + + + CVE-1999-0527 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. + + + CVE-1999-0528 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. + + + CVE-1999-0529 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. + + + CVE-1999-0530 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system is operating in "promiscuous" mode which allows it to perform packet sniffing. + + + CVE-1999-0531 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO." + + + CVE-1999-0532 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:59.493-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A DNS server allows zone transfers. + + + CVE-1999-0533 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:59.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A DNS server allows inverse queries. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0534 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:59.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0535 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:34:59.697-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. + + + + + + + + + + cpe:/a:microsoft:ie:6.0.2900 + cpe:/a:netscape:communicator + + CVE-1999-0537 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:34:59.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. + + + CVE-1999-0539 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A trust relationship exists between two Unix hosts. + + + CVE-1999-0541 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:34:59.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A password for accessing a WWW URL is guessable. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0546 + 1998-10-01T00:00:00.000-04:00 + 2008-09-09T08:34:59.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The Windows NT guest account is enabled. + + + CVE-1999-0547 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An SSH server allows authentication through the .rhosts file. + + + CVE-1999-0548 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A superfluous NFS server is running, but it is not importing or exporting any file systems. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0549 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows NT automatically logs in an administrator upon rebooting. + + + CVE-1999-0550 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:00.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + A router's routing tables can be obtained from arbitrary hosts. + + + + + + + + + + + cpe:/a:hp:openmail:5.1 + cpe:/a:hp:openmail:5.10 + cpe:/a:hp:openmail:4.1 + + CVE-1999-0551 + 1998-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:00.397-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9804-078 + + HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. + + + CVE-1999-0554 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + NFS exports system-critical data to the world, e.g. / or a password file. + + + CVE-1999-0555 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Unix account with a name other than "root" has UID 0, i.e. root privileges. + + + CVE-1999-0556 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Two or more Unix accounts have the same UID. + + + CVE-1999-0559 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical Unix file or directory has inappropriate permissions. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0560 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:30.513-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical Windows NT file or directory has inappropriate permissions. + + + CVE-1999-0561 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IIS has the #exec function enabled for Server Side Include (SSI) files. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0562 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:01.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + The registry in Windows NT can be accessed remotely by users who are not administrators. + + + CVE-1999-0564 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. + + + CVE-1999-0565 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Sendmail alias allows input to be piped to a program. + + + + + + + + + cpe:/o:ibm:aix + + CVE-1999-0566 + 1997-08-01T00:00:00.000-04:00 + 2008-09-09T08:35:04.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities. + + + + + + + + + cpe:/o:sun:solaris + + CVE-1999-0568 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:31.217-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + rpc.admind in Solaris is not running in a secure mode. + + + CVE-1999-0569 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0570 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:31.450-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. + + + CVE-1999-0571 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0572 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0575 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:05.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0576 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:05.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0577 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:32.107-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0578 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:32.247-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0579 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:32.390-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. + + + CVE-1999-0580 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0581 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:32.623-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0582 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:05.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. + + + CVE-1999-0583 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + There is a one-way or two-way trust relationship between Windows NT domains. + + + CVE-1999-0584 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT file system is not NTFS. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:3.5.1:sp3 + cpe:/o:microsoft:windows_nt:3.5.1:sp5 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:3.5.1:sp2 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1:sp1 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0585 + 2000-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:05.697-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT administrator account has the default name of Administrator. + + + CVE-1999-0586 + 1999-01-01T00:00:00.000-05:00 + 2014-11-04T08:52:09.123-05:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network service is running on a nonstandard port. + + + CVE-1999-0587 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. + + + CVE-1999-0588 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A filter in a router or firewall allows unusual fragmented packets. + + + CVE-1999-0589 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical Windows NT registry key has inappropriate permissions. + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:3.5.1:sp3 + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:microsoft:windows_nt:3.5.1:sp5 + cpe:/o:apple:mac_os + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:3.5.1:sp2 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1:sp1 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0590 + 2000-06-01T00:00:00.000-04:00 + 2008-09-09T08:35:06.040-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system does not present an appropriate legal message or warning to a user who is accessing it. + + + CVE-1999-0591 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An event log in Windows NT has inappropriate access permissions. + + + CVE-1999-0592 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The Logon box of a Windows NT system displays the name of the last user who logged in. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0593 + 1999-01-01T00:00:00.000-05:00 + 2009-10-31T00:00:00.000-04:00 + + + 4.9 + LOCAL + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-shutdown-without-logon(1291) + + + MISC + http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true + + + CONFIRM + http://technet.microsoft.com/en-us/library/cc722469.aspx + + + OSVDB + 59333 + + The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. + + + CVE-1999-0594 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. + + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-0595 + 2000-01-20T00:00:00.000-05:00 + 2008-09-09T08:35:06.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. + + + CVE-1999-0596 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT log file has an inappropriate maximum size or retention period. + + + CVE-1999-0597 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. + + + CVE-1999-0598 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection. + + + CVE-1999-0599 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. + + + CVE-1999-0600 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network intrusion detection system (IDS) does not verify the checksum on a packet. + + + CVE-1999-0601 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets. + + + CVE-1999-0602 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A network intrusion detection system (IDS) does not properly reassemble fragmented packets. + + + CVE-1999-0603 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc. + + + + + + + + + cpe:/a:selena_sol:selena_sol_webstore:1.0 + + CVE-1999-0604 + 1999-04-20T00:00:00.000-04:00 + 2008-09-09T08:35:06.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information. + + + + + + + + + + cpe:/a:austin_contract_computing:merchant_order_form:1.2 + cpe:/a:austin_contract_computing:merchant_order_form:1.0 + + CVE-1999-0605 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information. + + + + + + + + + cpe:/a:seaside_enterprises:ezmall:2000 + + CVE-1999-0606 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information. + + + + + + + + + cpe:/a:i-soft:quikstore + + CVE-1999-0607 + 1999-04-20T00:00:00.000-04:00 + 2008-09-09T08:35:07.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. + + + + + + + + + cpe:/a:pdgsoft:pdg_shopping_cart:1.5 + + CVE-1999-0608 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.pdgsoft.com/Security/security.html. + + + XF + pdgsoftcart-misconfig(3857) + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information. + + + + + + + + + cpe:/a:mercantec:softcart + + CVE-1999-0609 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information. + + + + + + + + + cpe:/a:mountain_network_systems:webcart + + CVE-1999-0610 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990420 Shopping Carts exposing CC data + + An incorrect configuration of the Webcart CGI program could disclose private information. + + + CVE-1999-0611 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical Windows NT registry key has an inappropriate value. + + + + + + + + + + + + + + + + cpe:/a:gnu:fingerd + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/a:gnu:finger_service + + CVE-1999-0612 + 1997-03-01T00:00:00.000-05:00 + 2008-09-09T08:35:07.647-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A version of finger is running that exposes valid user information to any entity on the network. + + + CVE-1999-0613 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rpc.sprayd service is running. + + + CVE-1999-0614 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FTP service is running." + + + CVE-1999-0615 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SNMP service is running." + + + CVE-1999-0616 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The TFTP service is running." + + + CVE-1999-0617 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SMTP service is running." + + + CVE-1999-0618 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rexec service is running. + + + CVE-1999-0619 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The Telnet service is running." + + + CVE-1999-0620 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NIS is running." + + + CVE-1999-0621 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to NETBIOS is running." + + + CVE-1999-0622 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A component service related to DNS service is running." + + + CVE-1999-0623 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X Windows service is running." + + + CVE-1999-0624 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rstat/rstatd service is running. + + + CVE-1999-0625 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rpc.rquotad service is running. + + + + + + + + + cpe:/a:sun:rpc.ruserd + + CVE-1999-0626 + 1997-01-01T00:00:00.000-05:00 + 2008-09-09T08:35:08.680-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A version of rusers is running that exposes valid user information to any entity on the network. + + + + + + + + + + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0627 + 1992-03-01T00:00:00.000-05:00 + 2008-09-09T08:35:08.743-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0628 + 1997-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:08.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rwho/rwhod service is running, which exposes machine status and user information. + + + CVE-1999-0629 + 1999-01-01T00:00:00.000-05:00 + 2010-12-01T00:00:00.000-05:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The ident/identd service is running. + + + CVE-1999-0630 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The NT Alerter and Messenger services are running. + + + CVE-1999-0631 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NFS service is running." + + + CVE-1999-0632 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The RPC portmapper service is running. + + + CVE-1999-0633 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The HTTP/WWW service is running." + + + CVE-1999-0634 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SSH service is running." + + + CVE-1999-0635 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FULLDISC + 20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services + + The echo service is running. + + + CVE-1999-0636 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The discard service is running. + + + CVE-1999-0637 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The systat service is running. + + + CVE-1999-0638 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The daytime service is running. + + + CVE-1999-0639 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The chargen service is running. + + + CVE-1999-0640 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The Gopher service is running. + + + CVE-1999-0641 + 1999-01-01T00:00:00.000-05:00 + 2007-07-13T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The UUCP service is running. + + + CVE-1999-0642 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A POP service is running." + + + CVE-1999-0643 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IMAP service is running." + + + CVE-1999-0644 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The NNTP news service is running." + + + CVE-1999-0645 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The IRC service is running." + + + CVE-1999-0646 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The LDAP service is running." + + + CVE-1999-0647 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The bootparam (bootparamd) service is running." + + + CVE-1999-0648 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The X25 service is running." + + + CVE-1999-0649 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The FSP service is running." + + + CVE-1999-0650 + 1999-01-01T00:00:00.000-05:00 + 2006-06-15T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The netstat service is running, which provides sensitive information to remote attackers. + + + CVE-1999-0651 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The rsh/rlogin service is running. + + + CVE-1999-0652 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A database service is running, e.g. a SQL server, Oracle, or mySQL." + + + CVE-1999-0653 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A component service related to NIS+ is running. + + + CVE-1999-0654 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The OS/2 or POSIX subsystem in NT is enabled. + + + CVE-1999-0655 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE. Notes: the former description is: "A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities." + + + + + + + + + cpe:/o:linux:linux_kernel + + CVE-1999-0656 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:17:40.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + linux-ugidd(348) + + + MISC + http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638 + + The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. + + + CVE-1999-0657 + 1999-01-01T00:00:00.000-05:00 + 2007-07-21T00:00:00.000-04:00 + + + 0.0 + NETWORK + LOW + NONE + NONE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + WinGate is being used. + + + CVE-1999-0658 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "DCOM is running." + + + CVE-1999-0659 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present." + + + CVE-1999-0660 + 1999-01-01T00:00:00.000-05:00 + 2008-08-01T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE. It might be more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc." + + + CVE-1999-0661 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-28 + + + CERT + CA-1999-02 + + + CERT + CA-1999-01 + + + CERT + CA-1994-14 + + + CERT + CA-1994-07 + + + BID + 5921 + + + XF + sendmail-backdoor(10313) + + + BUGTRAQ + 20021009 Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail + + + BUGTRAQ + 20020801 OpenSSH Security Advisory: Trojaned Distribution Files + + + BUGTRAQ + 20020801 trojan horse in recent openssh (version 3.4 portable 1) + + A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6. + + + CVE-1999-0662 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete. + + + CVE-1999-0663 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified. + + + CVE-1999-0664 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An application-critical Windows NT registry key has inappropriate permissions. + + + CVE-1999-0665 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + An application-critical Windows NT registry key has an inappropriate value. + + + + + + + + + cpe:/h:arp_protocol:arp_protocol + + CVE-1999-0667 + 1997-09-19T00:00:00.000-04:00 + 2008-09-09T08:35:12.070-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0668 + 1999-08-21T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-032 + + + BID + 598 + + + MSKB + Q240308 + + + CIAC + J-064 + + The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0669 + 1999-09-01T00:00:00.000-04:00 + 2008-09-09T08:35:12.210-04:00 + + + 4.0 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + J-064 + + The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0670 + 1999-09-01T00:00:00.000-04:00 + 2008-09-09T08:35:12.557-04:00 + + + 4.0 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-032 + + + CIAC + J-064 + + Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. + + + + + + + + + cpe:/a:toxsoft:nextftp:1.82 + + CVE-1999-0671 + 1999-08-03T00:00:00.000-04:00 + 2008-09-09T08:35:12.617-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 572 + + Buffer overflow in ToxSoft NextFTP client through CWD command. + + + + + + + + + cpe:/a:fujitsu:chocoa:1.0beta7r + + CVE-1999-0672 + 1999-08-01T00:00:00.000-04:00 + 2008-09-09T08:35:12.680-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 573 + + Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics. + + + + + + + + + cpe:/a:crear:almail32:1.10 + + CVE-1999-0673 + 1999-08-08T00:00:00.000-04:00 + 2008-09-09T08:35:12.757-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 574 + + Buffer overflow in ALMail32 POP3 client via From: or To: headers. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.2 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.4 + + CVE-1999-0674 + 1999-08-09T00:00:00.000-04:00 + 2008-09-09T08:35:12.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 570 + + + CIAC + J-067 + + The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-1999-0675 + 1999-08-09T00:00:00.000-04:00 + 2008-09-09T08:35:12.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 576 + + + BUGTRAQ + 19990809 FW1 UDP Port 0 DoS + + + OSVDB + 1038 + + Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0676 + 1999-08-09T00:00:00.000-04:00 + 2008-09-09T08:35:12.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19990808 sdtcm_convert + + + BID + 575 + + sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. + + + + + + + + + + cpe:/h:ramp_networks:webramp_m3:1.0 + cpe:/h:ramp_networks:webramp_200i:1.0 + + CVE-1999-0677 + 1999-08-03T00:00:00.000-04:00 + 2008-09-09T08:35:13.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 577 + + The WebRamp web administration utility has a default password. + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + cpe:/a:apache:http_server + + CVE-1999-0678 + 1999-01-17T00:00:00.000-05:00 + 2008-09-09T08:35:13.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 318 + + A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server. + + + + + + + + + + cpe:/a:hybrid_network:hybrid_ircd:5.03p7 + cpe:/a:hybrid_network:hybrid_ircd:6.0beta58 + + CVE-1999-0679 + 1999-08-13T00:00:00.000-04:00 + 2008-09-09T08:35:13.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.efnet.org/archive/servers/hybrid/ChangeLog + + + BID + 581 + + Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. + + + + + + + + + cpe:/a:microsoft:terminal_server + + CVE-1999-0680 + 1999-08-09T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 571 + + + MS + MS99-028 + + + CIAC + J-057 + + + MSKB + Q238600 + + Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. + + + + + + + + + + + + cpe:/a:microsoft:frontpage:98 + cpe:/a:microsoft:frontpage:97 + cpe:/a:microsoft:personal_web_server:1.0 + cpe:/a:microsoft:personal_web_server:1.1 + + CVE-1999-0681 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:43.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + frontpage-pws-dos + + + BID + 568 + + + BUGTRAQ + 19990807 Crash FrontPage Remotely... + + Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5:sp1 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.5:sp2 + + CVE-1999-0682 + 1999-08-06T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 567 + + + MS + MS99-027 + + + CIAC + J-056 + + + MSKB + Q237927 + + Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. + + + + + + + + + cpe:/a:network_associates:gauntlet_firewall:5.0 + + CVE-1999-0683 + 1999-07-30T00:00:00.000-04:00 + 2008-09-09T08:35:13.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 556 + + + OSVDB + 1029 + + Denial of service in Gauntlet Firewall via a malformed ICMP packet. + + + + + + + + + cpe:/a:hp:sendmail:8.8.6 + + CVE-1999-0684 + 1999-04-19T00:00:00.000-04:00 + 2008-09-09T08:35:13.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Sendmail 8.8.6 in HPUX. + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.06 + + CVE-1999-0685 + 1999-09-02T00:00:00.000-04:00 + 2008-09-09T08:35:13.710-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 618 + + Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.24 + cpe:/a:netscape:enterprise_server + + CVE-1999-0686 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:13.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9906-098 + + + CIAC + J-046 + + Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/a:cde:cde:1.2 + cpe:/a:cde:cde:1.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/a:cde:cde:2.0 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/a:cde:cde:2.1 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:ibm:aix:4.3.2 + cpe:/a:cde:cde:2.120 + cpe:/a:cde:cde:1.0.1 + cpe:/a:cde:cde:1.0.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:digital:unix:4.0f + cpe:/o:ibm:aix:4.1.5 + cpe:/o:digital:unix:4.0d + cpe:/o:ibm:aix:4.2.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0687 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:13.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9909-103 + + + BID + 637 + + + CIAC + K-001 + + + SUN + 00192 + + + + + The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. + + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + + CVE-1999-0688 + 1999-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:13.913-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + HP + HPSBUX9907-101 + + + BID + 545 + + + + + Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/a:cde:cde:2.0 + cpe:/o:sun:solaris:2.5 + cpe:/a:cde:cde:2.1 + cpe:/o:sun:solaris:2.6 + cpe:/a:cde:cde:1.2 + cpe:/a:cde:cde:1.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/a:cde:cde:2.120 + cpe:/a:cde:cde:1.0.1 + cpe:/a:cde:cde:1.0.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-1999-0689 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:13.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + HP + HPSBUX9909-103 + + + BID + 636 + + + SUN + 00192 + + + + + The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/a:cde:cde + + CVE-1999-0690 + 1999-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:14.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + J-053 + + + HP + HPSBUX9907-100 + + HP CDE program includes the current directory in root's PATH variable. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1 + cpe:/a:cde:cde:1.2 + cpe:/a:cde:cde:1.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/a:cde:cde:2.0 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/a:cde:cde:2.1 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:ibm:aix:4.3.2 + cpe:/a:cde:cde:1.0.1 + cpe:/a:cde:cde:1.0.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:digital:unix:4.0f + cpe:/o:ibm:aix:4.1.5 + cpe:/o:digital:unix:4.0e + cpe:/o:digital:unix:4.0d + cpe:/o:ibm:aix:4.2.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-0691 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:14.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + HP + HPSBUX9909-103 + + + BID + 635 + + + SUN + 00192 + + + + + Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. + + + + + + + + + + + + + + + + + + + + + cpe:/o:cray:unicos + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0692 + 1999-07-19T00:00:00.000-04:00 + 2008-09-09T08:35:14.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + J-052 + + + SGI + 19990701-01-P + + The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges. + + + + + + + + + + + + cpe:/o:sco:unixware:7 + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + cpe:/o:ibm:aix:4 + + CVE-1999-0693 + 2000-03-02T00:00:00.000-05:00 + 2008-09-09T08:35:14.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + HP + HPSBUX9909-103 + + + BID + 641 + + + SUN + 00192 + + + + + Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges. + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + + CVE-1999-0694 + 1999-08-11T00:00:00.000-04:00 + 2008-09-09T08:35:14.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + J-055 + + Denial of service in AIX ptrace system call allows local users to crash the system. + + + + + + + + + cpe:/a:sybase:powerdynamo:3.0.652 + + CVE-1999-0695 + 2000-04-11T00:00:00.000-04:00 + 2008-09-09T08:35:14.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 620 + + + OSVDB + 1064 + + The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0696 + 1999-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:14.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9908-102 + + + CIAC + J-051 + + + SUN + 00188 + + + + + Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd). + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.4 + + CVE-1999-0697 + 1999-09-09T00:00:00.000-04:00 + 2008-09-09T08:35:14.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 621 + + SCO Doctor allows local users to gain root privileges through a Tools option. + + + CVE-1999-0698 + 1999-01-01T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. + + + + + + + + + cpe:/a:bluestone:sapphire_web:5.0 + + CVE-1999-0699 + 2000-04-11T00:00:00.000-04:00 + 2008-09-09T08:35:14.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 623 + + The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0700 + 1999-07-29T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-026 + + + MSKB + Q237185 + + Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0701 + 2000-04-11T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 626 + + + MS + MS99-036 + + + MSKB + Q173039 + + After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0702 + 1999-09-10T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 627 + + + MS + MS99-037 + + + MSKB + Q241361 + + Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:bsdi:bsd_os:3.2 + + CVE-1999-0703 + 1999-08-03T00:00:00.000-04:00 + 2008-09-09T08:35:14.947-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + J-066 + + OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices. + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:bsdi:bsd_os:3.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + cpe:/o:bsdi:bsd_os:4.0.1 + + CVE-1999-0704 + 1999-09-16T00:00:00.000-04:00 + 2008-09-09T08:35:15.007-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 614 + + Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others. + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0 + cpe:/a:isc:inn + + CVE-1999-0705 + 1999-09-01T00:00:00.000-04:00 + 2008-09-09T08:35:15.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 616 + + Buffer overflow in INN inews program. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:1.5.1 + cpe:/a:isc:inn:1.7 + cpe:/a:isc:inn:2.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/a:isc:inn:2.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + cpe:/a:isc:inn:1.7.2 + + CVE-1999-0706 + 2000-04-27T00:00:00.000-04:00 + 2008-09-09T08:35:15.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 583 + + Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/a:hp:visualize_conference_ftp + + CVE-1999-0707 + 1999-07-01T00:00:00.000-04:00 + 2008-09-09T08:35:15.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CIAC + J-050 + + + HP + HPSBUX9906-099 + + + BID + 493 + + The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization. + + + + + + + + + cpe:/a:infodrom:cfingerd:1.4.2 + + CVE-1999-0708 + 1999-09-21T00:00:00.000-04:00 + 2008-09-09T08:35:15.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 651 + + Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field. + + + + + + + + + + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:6.0 + + CVE-1999-0710 + 1999-07-25T00:00:00.000-04:00 + 2008-09-09T08:35:15.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + http-cgi-cachemgr(2385) + + + BID + 2059 + + + REDHAT + RHSA-2005:489 + + + REDHAT + RHSA-1999:025 + + + CONFIRM + http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid + + + FEDORA + FEDORA-2005-373 + + + DEBIAN + DSA-576 + + + FEDORA + FLSA-2006:152809 + + + + + The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems. + + + + + + + + + + + + + cpe:/a:oracle:oracle8i:8.0.5 + cpe:/a:oracle:oracle8i:8.0.4 + cpe:/a:oracle:oracle8i:8.0.3 + cpe:/a:oracle:oracle8i:8.0.5.1 + cpe:/a:oracle:oracle8i:8.1.5 + + CVE-1999-0711 + 1999-04-29T00:00:00.000-04:00 + 2008-09-09T08:35:15.460-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed + + + BUGTRAQ + 19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh + + The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root. + + + + + + + + + + + + + + + + cpe:/a:caldera:coas:1.0.6 + cpe:/a:caldera:coas:1.0.5 + cpe:/o:caldera:openlinux:2.2 + cpe:/a:caldera:coas:1.0.7 + + CVE-1999-0712 + 1999-04-27T00:00:00.000-04:00 + 2008-09-09T08:35:15.523-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable. + + + + + + + + + + + + + + + + cpe:/a:transarc:afs + cpe:/a:mit:kerberos:5 + cpe:/a:cde:cde + cpe:/o:digital:unix + + CVE-1999-0713 + 1999-06-11T00:00:00.000-04:00 + 2008-09-09T08:35:15.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + J-044 + + The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges. + + + + + + + + + + + + + + + cpe:/o:digital:unix:3.2g + cpe:/o:digital:unix:4.0e + cpe:/o:digital:unix:4.0d + cpe:/o:digital:unix:4.0c + cpe:/o:digital:unix:4.0b + cpe:/o:digital:unix:4.0a + cpe:/o:digital:unix:4.0 + + CVE-1999-0714 + 1999-02-15T00:00:00.000-05:00 + 2008-09-09T08:35:15.663-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Vulnerability in Compaq Tru64 UNIX edauth command. + + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0715 + 1999-05-20T00:00:00.000-04:00 + 2008-09-09T08:35:15.727-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MSKB + Q230677 + + + MS + MS99-016 + + Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. + + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0716 + 1999-05-17T00:00:00.000-04:00 + 2008-09-09T08:35:15.807-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS99-015 + + + MSKB + Q231605 + + Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:excel + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0717 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:15.867-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q231304 + + + MS + MS99-014 + + A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. + + + + + + + + + cpe:/a:ibm:gina:1.0 + + CVE-1999-0718 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:48.857-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ibm-gina-group-add + + + BID + 608 + + + NTBUGTRAQ + 19990823 IBM Gina security warning + + IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key. + + + + + + + + + cpe:/a:gnu:gnumeric:0.27 + + CVE-1999-0719 + 1999-08-05T00:00:00.000-04:00 + 2008-09-09T08:35:16.007-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 563 + + The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-1999-0720 + 1999-08-23T00:00:00.000-04:00 + 2008-09-09T08:35:16.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19990823 [Linux] glibc 2.1.x / wu-ftpd <=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x + + + BID + 597 + + The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0721 + 1999-07-20T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-020 + + + CIAC + J-049 + + + MSKB + Q231457 + + Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. + + + + + + + + + cpe:/h:sun:cobalt_raq_2 + + CVE-1999-0722 + 1999-08-08T00:00:00.000-04:00 + 2008-09-09T08:35:17.993-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 558 + + The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages. + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0723 + 1999-06-23T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-021 + + + BID + 478 + + + CIAC + J-049 + + + MSKB + Q233323 + + The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + + CVE-1999-0724 + 1999-08-12T00:00:00.000-04:00 + 2008-09-09T08:35:18.133-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6128 + + Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function. + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0:unknown:unknown:korean + cpe:/a:microsoft:internet_information_server:4.0:unknown:unknown:chinese + cpe:/a:microsoft:internet_information_server:3.0:unknown:unknown:japanese + cpe:/a:microsoft:internet_information_server:3.0:unknown:unknown:korean + cpe:/a:microsoft:internet_information_server:3.0:unknown:unknown:chinese + cpe:/a:microsoft:internet_information_server:4.0:unknown:unknown:japanese + + CVE-1999-0725 + 1999-08-19T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + iis-double-byte-code-page(2302) + + + BID + 477 + + + MS + MS99-022 + + + MSKB + Q233335 + + When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0726 + 1999-06-30T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 499 + + + MS + MS99-023 + + + MSKB + Q234557 + + An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + + CVE-1999-0727 + 1999-08-06T00:00:00.000-04:00 + 2008-09-09T08:35:18.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6127 + + A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0728 + 1999-07-06T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-024 + + + MSKB + Q236359 + + A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. + + + + + + + + + cpe:/a:ibm:lotus_domino_server:4.6 + + CVE-1999-0729 + 2001-03-12T00:00:00.000-05:00 + 2008-09-09T08:35:18.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6 + + + BID + 601 + + + CIAC + J-061 + + + OSVDB + 1057 + + Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request. + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + + CVE-1999-0730 + 1999-06-12T00:00:00.000-04:00 + 2008-09-05T16:17:50.577-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. + + + + + + + + + + cpe:/o:caldera:openlinux:1.3 + cpe:/o:caldera:openlinux:2.2 + + CVE-1999-0731 + 1999-06-23T00:00:00.000-04:00 + 2008-09-09T08:35:18.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 489 + + The KDE klock program allows local users to unlock a session using malformed input. + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + + CVE-1999-0732 + 1999-08-19T00:00:00.000-04:00 + 2008-09-09T08:35:18.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links. + + + + + + + + + cpe:/a:vmware:workstation:1.0.1 + + CVE-1999-0733 + 1999-06-26T00:00:00.000-04:00 + 2008-09-09T08:35:18.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 490 + + Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable. + + + + + + + + + cpe:/a:cisco:ciscosecure + + CVE-1999-0734 + 1999-08-19T00:00:00.000-04:00 + 2008-09-09T08:35:18.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication. + + + + + + + + + cpe:/a:kde:k-mail:1.1 + + CVE-1999-0735 + 2000-01-04T00:00:00.000-05:00 + 2008-09-09T08:35:18.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 300 + + + REDHAT + RHSA-1999:015-01 + + KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0736 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:18.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-013 + + + + + The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0737 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:19.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-013 + + The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0738 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:19.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-013 + + The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-0739 + 1999-05-07T00:00:00.000-04:00 + 2008-09-09T08:35:19.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-013 + + The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. + + + + + + + + + + + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0740 + 1999-08-19T00:00:00.000-04:00 + 2008-09-09T08:35:19.210-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 594 + + Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. + + + + + + + + + cpe:/a:qms:crownnet_unix_utilities:2060 + + CVE-1999-0741 + 1999-08-19T00:00:00.000-04:00 + 2008-09-09T08:35:19.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 593 + + QMS CrownNet Unix Utilities for 2060 allows root to log on without a password. + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + + CVE-1999-0742 + 1999-06-22T00:00:00.000-04:00 + 2008-09-09T08:35:19.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 480 + + The Debian mailman package uses weak authentication, which allows attackers to gain privileges. + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + + CVE-1999-0743 + 1999-08-20T00:00:00.000-04:00 + 2008-09-09T08:35:19.413-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + trn-symlinks(3144) + + Trn allows local users to overwrite other users' files via symlinks. + + + + + + + + + + cpe:/a:netscape:enterprise_server + cpe:/a:netscape:fasttrack_server + + CVE-1999-0744 + 2000-01-04T00:00:00.000-05:00 + 2008-09-05T16:17:52.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 603 + + Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. + + + + + + + + + + + + + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:2.2.1 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-0745 + 1999-08-18T00:00:00.000-04:00 + 2008-09-09T08:35:19.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 590 + + + CIAC + J-059 + + Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:5.2 + cpe:/o:suse:suse_linux:5.3 + cpe:/o:suse:suse_linux:4.4.1 + cpe:/o:suse:suse_linux:5.0 + cpe:/o:suse:suse_linux:5.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:slackware:slackware_linux:3.6 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:slackware:slackware_linux:3.2 + cpe:/o:suse:suse_linux:4.4 + cpe:/o:suse:suse_linux:6.0 + + CVE-1999-0746 + 1999-08-16T00:00:00.000-04:00 + 2008-09-09T08:35:19.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 587 + + A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. + + + + + + + + + cpe:/o:bsdi:bsd_os:4.0.1 + + CVE-1999-0747 + 1999-08-18T00:00:00.000-04:00 + 2008-09-09T08:35:19.697-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1 + + + BID + 589 + + Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-1999-0748 + 1999-06-24T00:00:00.000-04:00 + 2008-09-09T08:35:19.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Buffer overflows in Red Hat net-tools package. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-1999-0749 + 1999-08-16T00:00:00.000-04:00 + 2008-09-09T08:35:19.837-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 586 + + + MS + MS99-033 + + Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. + + + + + + + + + cpe:/a:microsoft:hotmail + + CVE-1999-0750 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:19.913-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 630 + + Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.5.1 + cpe:/a:netscape:enterprise_server:3.6:sp2 + + CVE-1999-0751 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:19.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-accept-bo(3256) + + + BID + 631 + + Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch. + + + + + + + + + cpe:/a:netscape:enterprise_server + + CVE-1999-0752 + 1999-07-06T00:00:00.000-04:00 + 2008-09-09T08:35:20.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. + + + + + + + + + + cpe:/a:hughes:msql:2.0.10 + cpe:/a:hughes:msql:2.0 + + CVE-1999-0753 + 1999-08-17T00:00:00.000-04:00 + 2008-09-09T08:35:20.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 591 + + The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. + + + + + + + + + cpe:/a:isc:inn + + CVE-1999-0754 + 1999-05-11T00:00:00.000-04:00 + 2008-09-09T08:35:20.243-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.redhat.com/corp/support/errata/inn99_05_22.html + + + BID + 255 + + + CALDERA + CSSA-1999-011.0 + + The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-0755 + 1999-05-27T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-017 + + + MSKB + Q230681 + + Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:4.0.1 + + CVE-1999-0756 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:54.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + coldfusion-admin-dos(2207) + + + ALLAIRE + ASB99-07 + + ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility. + + + + + + + + + cpe:/a:allaire:coldfusion_server + + CVE-1999-0757 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:54.403-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + coldfusion-encryption + + + ALLAIRE + ASB99-08 + + The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.5.1 + cpe:/a:netscape:fasttrack_server:3.01 + + CVE-1999-0758 + 2001-03-12T00:00:00.000-05:00 + 2008-09-09T08:35:20.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL. + + + + + + + + + cpe:/a:fuseware:fusemail:2.7 + + CVE-1999-0759 + 1999-09-13T00:00:00.000-04:00 + 2008-09-09T08:35:20.913-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.crosswinds.net/~fuseware/faq.html#8 + + + BID + 634 + + Buffer overflow in FuseMAIL POP service via long USER and PASS commands. + + + + + + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:3.1.1 + cpe:/a:allaire:coldfusion_server:4.0.1 + cpe:/a:allaire:coldfusion_server:2.0 + cpe:/a:allaire:coldfusion_server:3.0 + cpe:/a:allaire:coldfusion_server:3.0.1 + cpe:/a:allaire:coldfusion_server:3.1 + cpe:/a:allaire:coldfusion_server:3.1.2 + + CVE-1999-0760 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:54.827-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 550 + + + XF + coldfusion-server-cfml-tags + + + ALLAIRE + ASB99-10 + + Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + + CVE-1999-0761 + 2000-09-16T00:00:00.000-04:00 + 2008-09-09T08:35:21.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 644 + + + OSVDB + 1074 + + Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program. + + + + + + + + + + + cpe:/a:netscape:communicator:4.6::windows_95 + cpe:/a:netscape:communicator:4.x + cpe:/a:netscape:navigator + + CVE-1999-0762 + 1999-05-24T00:00:00.000-04:00 + 2008-09-09T08:35:21.133-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. + + + + + + + + + cpe:/o:netbsd:netbsd:1.3 + + CVE-1999-0763 + 1999-05-01T00:00:00.000-04:00 + 2008-09-09T08:35:21.197-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6540 + + NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network. + + + + + + + + + cpe:/o:netbsd:netbsd:1.3 + + CVE-1999-0764 + 1999-05-01T00:00:00.000-04:00 + 2008-09-09T08:35:21.273-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6539 + + NetBSD allows ARP packets to overwrite static ARP entries. + + + + + + + + + cpe:/o:sgi:irix:6.0 + + CVE-1999-0765 + 1999-05-19T00:00:00.000-04:00 + 2008-09-09T08:35:21.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 262 + + + SGI + 19990501-01-A + + SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. + + + + + + + + + + cpe:/a:microsoft:java_virtual_machine + + CVE-1999-0766 + 1999-10-21T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 600 + + + MS + MS99-031 + + + MSKB + Q240346 + + The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + + CVE-1999-0767 + 1999-09-08T00:00:00.000-04:00 + 2008-09-09T08:35:21.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:redhat:linux:4.2 + cpe:/o:suse:suse_linux:6.0 + + CVE-1999-0768 + 1999-08-25T00:00:00.000-04:00 + 2008-09-09T08:35:21.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 602 + + Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:caldera:openlinux:2.2 + cpe:/a:paul_vixie:vixie_cron:3.0_pl1 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0769 + 1999-08-25T00:00:00.000-04:00 + 2008-09-09T08:35:21.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 611 + + Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-1999-0770 + 1999-07-29T00:00:00.000-04:00 + 2008-09-09T08:35:21.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 549 + + + OSVDB + 1027 + + Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems. + + + + + + + + + + cpe:/a:compaq:insight_management_agent + cpe:/a:compaq:power_management:2.0 + + CVE-1999-0771 + 1999-05-26T00:00:00.000-04:00 + 2008-09-09T08:35:37.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:compaq:insight_management_agent + cpe:/a:compaq:power_management:2.0 + + CVE-1999-0772 + 1999-06-01T00:00:00.000-04:00 + 2008-09-09T08:35:37.727-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + + CVE-1999-0773 + 1999-05-11T00:00:00.000-04:00 + 2008-09-09T08:35:37.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990511 Solaris2.6 and 2.7 lpset overflow + + Buffer overflow in Solaris lpset program allows local users to gain root access. + + + + + + + + + cpe:/a:martin_stover:mars_nwe:0.99 + + CVE-1999-0774 + 1999-08-31T00:00:00.000-04:00 + 2008-09-09T08:35:37.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 617 + + Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names. + + + + + + + + + + cpe:/o:cisco:ios:11.2%2815%29g + cpe:/o:cisco:ios:11.2%2814%29gs2 + + CVE-1999-0775 + 1999-06-10T00:00:00.000-04:00 + 2008-09-09T08:35:37.947-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. + + + + + + + + + cpe:/a:computer_software_manufaktur:alibaba:2.0 + + CVE-1999-0776 + 1999-05-12T00:00:00.000-04:00 + 2008-09-09T08:35:38.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19990506 ".."-hole in Alibaba 2.0 + + Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:commercial_internet_system:2.5 + + CVE-1999-0777 + 1999-09-23T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 658 + + + MS + MS99-039 + + + MSKB + Q242559 + + + MSKB + Q241407 + + IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. + + + + + + + + + + cpe:/a:xi_graphics:accelerated-x_server:4 + cpe:/a:xi_graphics:accelerated-x_server:5 + + CVE-1999-0778 + 1999-06-25T00:00:00.000-04:00 + 2008-09-09T08:35:38.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 488 + + Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-1999-0779 + 1998-09-03T00:00:00.000-04:00 + 2008-09-09T08:35:38.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9810-086 + + + + + Denial of service in HP-UX SharedX recserv program. + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:kde:kde:1.0 + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0780 + 1998-11-18T00:00:00.000-05:00 + 2008-09-09T08:35:38.353-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19981118 Multiple KDE security vulnerabilities (root compromise) + + KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:kde:kde:1.0 + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0781 + 1998-11-18T00:00:00.000-05:00 + 2008-09-09T08:35:38.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981118 Multiple KDE security vulnerabilities (root compromise) + + KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables. + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:kde:kde:1.0 + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-1999-0782 + 1998-11-18T00:00:00.000-05:00 + 2008-09-09T08:35:38.507-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19981118 Multiple KDE security vulnerabilities (root compromise) + + KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. + + + + + + + + + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0783 + 1998-06-16T00:00:00.000-04:00 + 2011-03-07T21:01:10.657-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6090 + + + CIAC + I-057 + + FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system. + + + + + + + + + + cpe:/a:oracle:database_server:7.3.3 + cpe:/a:oracle:database_server:7.1.4 + + CVE-1999-0784 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:17:58.370-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19980827 NERP DoS attack possible in Oracle + + + BUGTRAQ + 19990104 Re: Fw:"NERP" DoS attack possible in Oracle + + + BUGTRAQ + 19981228 Oracle8 TNSLSNR DoS + + Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP. + + + + + + + + + + + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:2.0 + cpe:/a:isc:inn:2.1 + + CVE-1999-0785 + 1999-05-11T00:00:00.000-04:00 + 2008-09-09T08:35:38.710-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 254 + + The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0786 + 1999-09-22T00:00:00.000-04:00 + 2008-09-09T08:35:38.790-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 659 + + The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack. + + + + + + + + + cpe:/a:ssh:ssh:1.2.27 + + CVE-1999-0787 + 1999-09-17T00:00:00.000-04:00 + 2008-09-09T08:35:38.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 660 + + + BUGTRAQ + 19990924 [Fwd: Truth about ssh 1.2.27 vulnerability] + + + BUGTRAQ + 19990917 A few bugs... + + The SSH authentication agent follows symlinks via a UNIX domain socket. + + + + + + + + + + cpe:/a:knox_software:arkeia:4.0 + cpe:/a:knox_software:arkeia:4.1 + + CVE-1999-0788 + 1999-09-26T00:00:00.000-04:00 + 2008-09-09T08:35:38.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 662 + + + BUGTRAQ + 19990924 Multiple vendor Knox Arkiea local root/remote DoS + + Arkiea nlservd allows remote attackers to conduct a denial of service. + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + + CVE-1999-0789 + 1999-09-28T00:00:00.000-04:00 + 2008-09-09T08:35:38.993-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 679 + + + CIAC + J-072 + + Buffer overflow in AIX ftpd in the libc library. + + + + + + + + + cpe:/a:netscape:communicator:4.0 + + CVE-1999-0790 + 2000-04-01T00:00:00.000-05:00 + 2008-09-09T08:35:39.210-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://home.netscape.com/security/notes/jscachebrowsing.html + + A remote attacker can read information from a Netscape user's cache via JavaScript. + + + + + + + + + + + + + + cpe:/h:hybrid_network:cable_modem + cpe:/a:hybrid_network:hsmp + + CVE-1999-0791 + 1999-10-06T00:00:00.000-04:00 + 2008-09-09T08:35:39.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 695 + + Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol. + + + + + + + + + cpe:/h:osicom:routermate + + CVE-1999-0792 + 1998-09-01T00:00:00.000-04:00 + 2008-09-09T08:35:39.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www2.merton.ox.ac.uk/~security/rootshell/0022.html + + ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0793 + 1999-11-17T00:00:00.000-05:00 + 2008-09-09T08:35:39.557-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-043 + + Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. + + + + + + + + + + cpe:/a:microsoft:excel + + CVE-1999-0794 + 1999-10-01T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + MS + MS99-044 + + + MSKB + Q241902 + + + MSKB + Q241901 + + + MSKB + Q241900 + + Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. + + + + + + + + + + cpe:/o:sun:sunos + cpe:/o:sun:solaris + + CVE-1999-0795 + 1998-03-01T00:00:00.000-05:00 + 2008-09-09T08:35:39.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches. + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0796 + 1998-05-01T00:00:00.000-04:00 + 2008-09-09T08:35:39.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 6089 + + FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks. + + + + + + + + + cpe:/o:sun:sunos + + CVE-1999-0797 + 1998-06-29T00:00:00.000-04:00 + 2008-09-09T08:35:39.837-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + I-070 + + NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries. + + + + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:sco:openserver + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:redhat:linux + cpe:/o:sco:unixware:7.0 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:internet_faststart + + CVE-1999-0798 + 1998-12-04T00:00:00.000-05:00 + 2008-09-09T08:35:39.897-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981204 bootpd remote vulnerability + + Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. + + + + + + + + + cpe:/o:cmu:bootpd:2.4.3 + + CVE-1999-0799 + 1997-06-01T00:00:00.000-04:00 + 2008-09-09T08:35:39.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. + + + + + + + + + cpe:/a:allaire:forums:2.0.4 + + CVE-1999-0800 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:18:00.667-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB99-05 + + + NTBUGTRAQ + 19990211 ACFUG List: Alert: Allaire Forums GetFile bug + + + XF + allaire-forums-file-read(1748) + + + OSVDB + 944 + + The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. + + + + + + + + + cpe:/a:bmc:patrol_agent:3.2.3 + + CVE-1999-0801 + 1999-04-09T00:00:00.000-04:00 + 2008-09-09T08:35:40.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990409 Patrol security bugs + + + XF + bmc-patrol-frames(2075) + + BMC Patrol allows remote attackers to gain access to an agent by spoofing frames. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-0802 + 1999-05-27T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + MS + MS99-018 + + + MSKB + Q231450 + + Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. + + + + + + + + + + cpe:/a:ibm:aix_enetwork_firewall:3.3 + cpe:/a:ibm:aix_enetwork_firewall:3.2 + + CVE-1999-0803 + 1999-05-25T00:00:00.000-04:00 + 2008-09-09T08:35:40.243-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 962 + + + BUGTRAQ + 19990525 IBM eNetwork Firewall for AIX + + The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:suse:suse_linux:6.1 + + CVE-1999-0804 + 1999-06-01T00:00:00.000-04:00 + 2008-09-09T08:35:40.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 302 + + Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. + + + + + + + + + cpe:/o:novell:netware:4.11 + + CVE-1999-0805 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:18:01.370-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + novell-tts-dos + + + BUGTRAQ + 19990512 DoS with Netware 4.x's TTS + + Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests. + + + + + + + + + cpe:/o:sun:solaris:2.0 + + CVE-1999-0806 + 1999-05-10T00:00:00.000-04:00 + 2008-09-09T08:35:40.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 6552 + + Buffer overflow in Solaris dtprintinfo program. + + + + + + + + + cpe:/a:netscape:directory_server + + CVE-1999-0807 + 1999-05-01T00:00:00.000-04:00 + 2008-09-09T08:35:40.507-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users. + + + + + + + + + + cpe:/a:isc:dhcp_client:1.0 + cpe:/a:isc:dhcp_client:2.0 + + CVE-1999-0808 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:01.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + I-053 + + + MISC + ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz + + + BUGTRAQ + 19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd) + + Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options. + + + + + + + + + cpe:/a:netscape:communicator:4.0 + + CVE-1999-0809 + 1999-07-09T00:00:00.000-04:00 + 2008-09-09T08:35:40.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed". + + + + + + + + + cpe:/a:samba:samba:2.0.5 + + CVE-1999-0810 + 1999-07-21T00:00:00.000-04:00 + 2008-09-05T16:18:02.060-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Samba NETBIOS name service daemon (nmbd). + + + + + + + + + cpe:/a:samba:samba:2.0.4 + + CVE-1999-0811 + 1999-07-21T00:00:00.000-04:00 + 2008-09-09T08:35:40.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 536 + + Buffer overflow in Samba smbd program via a malformed message command. + + + + + + + + + cpe:/a:samba:samba:2.0.5 + + CVE-1999-0812 + 2000-07-12T00:00:00.000-04:00 + 2008-09-05T16:18:02.340-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations. + + + + + + + + + cpe:/a:infodrom:cfingerd:1.4.0 + + CVE-1999-0813 + 1999-08-10T00:00:00.000-04:00 + 2008-09-09T08:35:41.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-1999-0814 + 1999-08-11T00:00:00.000-04:00 + 2008-09-09T08:35:41.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-1999:027 + + Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0::server + + CVE-1999-0815 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:02.763-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MSKB + Q196270 + + + XF + nt-snmpagent-leak(1974) + + + + + Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. + + + + + + + + + cpe:/h:motorola:motorola_cablerouter + + CVE-1999-0816 + 1998-05-10T00:00:00.000-04:00 + 2008-09-09T08:35:41.257-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980510 Security Vulnerability in Motorola CableRouters + + The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024. + + + + + + + + + cpe:/a:university_of_kansas:lynx + + CVE-1999-0817 + 1999-09-15T00:00:00.000-04:00 + 2008-09-05T16:18:03.027-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet. + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + + CVE-1999-0818 + 1999-11-20T00:00:00.000-05:00 + 2008-09-09T08:35:41.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 831 + + + BUGTRAQ + 19991130 another hole of Solaris7 kcms_configure + + Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0819 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:35:41.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991130 NTmail and VRFY + + NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0820 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:35:41.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 838 + + + OSVDB + 5996 + + FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0821 + 1999-11-08T00:00:00.000-05:00 + 2008-09-09T08:36:00.337-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 838 + + FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument. + + + + + + + + + + cpe:/a:qualcomm:qpopper:3.0b20 + cpe:/a:qualcomm:qpopper:3.0 + + CVE-1999-0822 + 1999-11-30T00:00:00.000-05:00 + 2008-09-09T08:36:00.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 830 + + Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0823 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:00.587-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 839 + + + OSVDB + 1150 + + Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0824 + 1999-11-30T00:00:00.000-05:00 + 2008-09-09T08:36:00.710-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 833 + + A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. + + + + + + + + + + + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0825 + 1999-12-03T00:00:00.000-05:00 + 2008-09-09T08:36:00.837-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 849 + + The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0826 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:00.913-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 840 + + + OSVDB + 1151 + + Buffer overflow in FreeBSD angband allows local users to gain privileges. + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0:a_mac_os + cpe:/a:netscape:navigator:4.5 + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + cpe:/a:microsoft:ie:4.0.1:sp2 + cpe:/a:microsoft:ie:4.5 + cpe:/a:microsoft:ie:3.1 + cpe:/a:microsoft:ie:3.2 + + CVE-1999-0827 + 1999-11-01T00:00:00.000-05:00 + 2008-09-09T08:36:00.993-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. + + + + + + + + + + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0828 + 1999-12-02T00:00:00.000-05:00 + 2008-09-09T08:36:01.057-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 853 + + UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. + + + + + + + + + cpe:/a:hp:secure_web_console + + CVE-1999-0829 + 1999-11-01T00:00:00.000-05:00 + 2008-09-09T08:36:01.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + HP Secure Web Console uses weak encryption. + + + + + + + + + cpe:/o:sco:unixware:7.0 + + CVE-1999-0830 + 1999-11-01T00:00:00.000-05:00 + 2008-09-09T08:36:01.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in SCO UnixWare Xsco command via a long argument. + + + + + + + + + + + + + + + + + + + + cpe:/a:cobalt:qube:2.0 + cpe:/o:debian:debian_linux:2.2 + cpe:/h:sun:cobalt_raq_2 + cpe:/a:cobalt:qube:1.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/h:sun:cobalt_raq_3i + cpe:/a:sun:cobalt_raq:1.1 + + CVE-1999-0831 + 1999-11-19T00:00:00.000-05:00 + 2008-09-09T08:36:01.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 809 + + + CALDERA + CSSA-1999-035.0 + + Denial of service in Linux syslogd via a large number of connections. + + + + + + + + + + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:debian:debian_linux:2.1 + + CVE-1999-0832 + 1999-11-09T00:00:00.000-05:00 + 2008-09-09T08:36:01.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19991109 undocumented bugs - nfsd + + + BID + 782 + + + REDHAT + RHSA-1999:053-01 + + + SUSE + 19991110 Security hole in nfs-server < 2.2beta47 within nkita + + + DEBIAN + 19991111 buffer overflow in nfs server + + + CALDERA + CSSA-1999-033.0 + + Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2 + + CVE-1999-0833 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:01.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 788 + + + CALDERA + CSSA-1999-034.1 + + Buffer overflow in BIND 8.2 via NXT records. + + + + + + + + + cpe:/a:rsa:rsaref:2.0 + + CVE-1999-0834 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:01.540-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 843 + + Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library. + + + + + + + + + + + + + cpe:/o:sco:unixware:7 + cpe:/o:ibm:aix:4.3 + cpe:/o:sco:openserver:5 + cpe:/o:sun:solaris:7.0 + cpe:/o:sco:unixware:2 + + CVE-1999-0835 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:01.617-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 788 + + + CALDERA + CSSA-1999-034.1 + + Denial of service in BIND named via malformed SIG records. + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0836 + 1998-12-02T00:00:00.000-05:00 + 2008-09-09T08:36:01.727-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19991202 UnixWare 7 uidadmin exploit + discussion + + + BID + 842 + + + SCO + SB-99.22a + + UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2 + + CVE-1999-0837 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:01.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 788 + + + SUN + 00194 + + + CALDERA + CSSA-1999-034.1 + + Denial of service in BIND by improperly closing TCP sessions via so_linger. + + + + + + + + + cpe:/a:deerfield:serv-u_ftp-server:2.5a + + CVE-1999-0838 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:01.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 859 + + Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command. + + + + + + + + + + + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:5::windows_nt_4.0 + + CVE-1999-0839 + 1999-11-29T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 828 + + + MS + MS99-051 + + + MSKB + Q246972 + + Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. + + + + + + + + + cpe:/o:sun:solaris:7.0 + + CVE-1999-0840 + 1999-11-30T00:00:00.000-05:00 + 2008-09-09T08:36:02.133-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 832 + + + XF + solaris-dtmailpr-overflow(3580) + + + XF + solaris-dtmail-overflow(3579) + + + BUGTRAQ + 19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow + + + MISC + http://www.securiteam.com/exploits/3J5QQPPQ0O.html + + Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option. + + + + + + + + + cpe:/o:sun:solaris:7.0 + + CVE-1999-0841 + 1999-11-30T00:00:00.000-05:00 + 2008-09-09T08:36:02.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 832 + + + XF + cde-mailtool-bo(3732) + + + BUGTRAQ + 19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow + + + MISC + http://www.securiteam.com/exploits/3J5QQPPQ0O.html + + Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type. + + + + + + + + + cpe:/a:symantec:mail-gear:1.0 + + CVE-1999-0842 + 1999-11-29T00:00:00.000-05:00 + 2008-09-09T08:36:02.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability + + + BID + 827 + + + OSVDB + 1144 + + Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/h:cisco:router + + CVE-1999-0843 + 1999-11-04T00:00:00.000-05:00 + 2008-09-09T08:36:02.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port. + + + + + + + + + + cpe:/a:deerfield:mdaemon:2.8.5 + cpe:/a:deerfield:mdaemon:2.8.6 + + CVE-1999-0844 + 1999-11-24T00:00:00.000-05:00 + 2008-09-09T08:36:02.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 823 + + + BID + 820 + + Denial of service in MDaemon WorldClient and WebConfig services via a long URL. + + + + + + + + + cpe:/o:sco:unixware:7.0 + + CVE-1999-0845 + 1999-11-25T00:00:00.000-05:00 + 2008-09-09T08:36:02.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in SCO su program allows local users to gain root access via a long username. + + + + + + + + + + cpe:/a:deerfield:mdaemon:2.8.5 + cpe:/a:deerfield:mdaemon:2.8.6 + + CVE-1999-0846 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:02.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in MDaemon 2.7 via a large number of connection attempts. + + + + + + + + + cpe:/a:freechess.org:fics_program + + CVE-1999-0847 + 1999-11-29T00:00:00.000-05:00 + 2008-09-05T16:18:07.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in free internet chess server (FICS) program, xboard. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2 + + CVE-1999-0848 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:02.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 788 + + + SUN + 00194 + + + CALDERA + CSSA-1999-034.1 + + Denial of service in BIND named via consuming more than "fdmax" file descriptors. + + + + + + + + + + + + + + + + + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:8.1.1 + cpe:/a:isc:bind:8.2:p1 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.1 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + + CVE-1999-0849 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:02.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 788 + + + SUN + 00194 + + + CALDERA + CSSA-1999-034.1 + + Denial of service in BIND named via maxdname. + + + + + + + + + cpe:/a:endymion:mailman_webmail:3.0.18 + + CVE-1999-0850 + 1999-12-02T00:00:00.000-05:00 + 2008-09-09T08:36:02.807-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 845 + + The default permissions for Endymion MailMan allow local users to read email or modify files. + + + + + + + + + + + + + cpe:/o:sco:unixware:7 + cpe:/o:ibm:aix:4.3 + cpe:/o:sco:openserver:5 + cpe:/o:sun:solaris:7.0 + cpe:/o:sco:unixware:2 + + CVE-1999-0851 + 1999-11-10T00:00:00.000-05:00 + 2008-09-09T08:36:02.883-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 788 + + + SUN + 00194 + + + CALDERA + CSSA-1999-034.1 + + Denial of service in BIND named via naptr. + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.0 + + CVE-1999-0852 + 1999-12-02T00:00:00.000-05:00 + 2008-09-09T08:36:02.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 844 + + IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. + + + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.5.1 + cpe:/a:netscape:fasttrack_server:3.01 + cpe:/a:netscape:enterprise_server:3.6 + cpe:/a:netscape:enterprise_server:3.6:sp2 + + CVE-1999-0853 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 847 + + Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure. + + + + + + + + + cpe:/a:infopop:ultimate_bulletin_board:5.07 + + CVE-1999-0854 + 1999-11-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.ultimatebb.com/home/versions.shtml + + + BUGTRAQ + 20000225 FW: Important UBB News For Licensed Users + + Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0855 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 834 + + Buffer overflow in FreeBSD gdc program. + + + + + + + + + cpe:/o:slackware:slackware_linux:7.0 + + CVE-1999-0856 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0857 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.397-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 835 + + FreeBSD gdc program allows local users to modify files via a symlink attack. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-0858 + 1999-12-02T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 846 + + + MS + MS99-054 + + + MSKB + Q247333 + + Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6:hw5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.6:hw5:x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.6:hw3:x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0859 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 837 + + + OSVDB + 6994 + + Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6:hw5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.6:hw5:x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.6:hw3:x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0860 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:03.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 837 + + Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:commercial_internet_system:2.5 + cpe:/a:microsoft:commercial_internet_system:2.0 + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-0861 + 1999-08-11T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-053 + + + MSKB + Q244613 + + Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.5.3.1 + cpe:/a:postgresql:postgresql:6.3.2 + + CVE-1999-0862 + 1999-12-02T00:00:00.000-05:00 + 2008-09-09T08:36:03.743-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-0863 + 1999-11-08T00:00:00.000-05:00 + 2008-09-09T08:36:03.820-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI. + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0864 + 1999-12-03T00:00:00.000-05:00 + 2008-09-09T08:36:03.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19991202 UnixWare coredumps follow symlinks + + + BID + 851 + + + BUGTRAQ + 19991223 FYI, SCO Security patches available. + + + BUGTRAQ + 19991220 SCO OpenServer Security Status + + + BUGTRAQ + 19991215 Recent postings about SCO UnixWare 7 + + UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file. + + + + + + + + + cpe:/a:stalker:communigate_pro:3.1 + + CVE-1999-0865 + 1999-12-03T00:00:00.000-05:00 + 2008-09-09T08:36:03.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 860 + + + NTBUGTRAQ + 19991203 CommuniGatePro 3.1 for NT Buffer Overflow + + + BUGTRAQ + 19991203 CommuniGatePro 3.1 for NT DoS + + Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0866 + 1999-12-03T00:00:00.000-05:00 + 2008-09-09T08:36:04.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 848 + + + BUGTRAQ + 19991223 FYI, SCO Security patches available. + + + BUGTRAQ + 19991220 SCO OpenServer Security Status + + + BUGTRAQ + 19991215 Recent postings about SCO UnixWare 7 + + + SCO + SB-99.24a + + Buffer overflow in UnixWare xauto program allows local users to gain root privilege. + + + + + + + + + + + + cpe:/a:microsoft:site_server:3.0:unknown:commerce + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:commercial_internet_system:2.5 + cpe:/a:microsoft:commercial_internet_system:2.0 + + CVE-1999-0867 + 1999-08-11T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 579 + + + MS + MS99-029 + + + CIAC + J-058 + + + MSKB + Q238349 + + Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:sun:sparc + cpe:/h:nec:goah_networksv:r2.2 + cpe:/a:netscape:news_server:1.1 + cpe:/a:isc:inn:1.5.1 + cpe:/h:nec:goah_networksv:r1.2 + cpe:/o:redhat:linux:4.0 + cpe:/h:nec:goah_intrasv:r1.1 + cpe:/o:redhat:linux:4.1 + cpe:/h:nec:goah_networksv:r3.1 + + CVE-1999-0868 + 1997-02-20T00:00:00.000-05:00 + 2008-09-09T08:36:04.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:netscape:navigator + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + cpe:/a:microsoft:ie:3.0.1 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:3.2 + + CVE-1999-0869 + 1998-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:04.227-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-020 + + Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. + + + + + + + + + + cpe:/a:microsoft:ie:4.0.1:sp1 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0870 + 1998-10-01T00:00:00.000-04:00 + 2008-09-09T08:36:04.290-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-015 + + Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. + + + + + + + + + + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-0871 + 1998-09-04T00:00:00.000-04:00 + 2008-09-09T08:36:06.507-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-crossframe-file-read(3668) + + + OSVDB + 7837 + + + MS + MS98-013 + + Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:caldera:openlinux:2.2 + cpe:/a:paul_vixie:vixie_cron:3.0_pl1 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-0872 + 1999-08-25T00:00:00.000-04:00 + 2008-09-09T08:36:06.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 759 + + + BID + 611 + + Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. + + + + + + + + + cpe:/a:sky_communications:skyfull:1.1.4 + + CVE-1999-0873 + 1999-10-30T00:00:00.000-04:00 + 2008-09-09T08:36:06.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 759 + + Buffer overflow in Skyfull mail server via MAIL FROM command. + + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0874 + 1999-06-16T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MS + MS99-019 + + + EEYE + AD06081999 + + + CIAC + J-048 + + + MSKB + Q234905 + + + + + Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95:0a + cpe:/o:microsoft:windows_95:0b + cpe:/o:microsoft:windows_2000 + + CVE-1999-0875 + 1999-08-11T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 578 + + + MSKB + Q216141 + + DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. + + + + + + + + + + + + + cpe:/a:microsoft:ie:4.0:a + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0::mac_os + cpe:/a:microsoft:ie:3.1::mac_os + + CVE-1999-0876 + 2000-01-04T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MSKB + Q176697 + + + MSKB + Q185959 + + Buffer overflow in Internet Explorer 4.0 via EMBED tag. + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.01:sp1 + cpe:/a:microsoft:ie:4.01 + + CVE-1999-0877 + 1999-10-01T00:00:00.000-04:00 + 2008-09-10T13:08:49.697-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-042 + + + MSKB + Q243638 + + Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:beroftpd:beroftpd:1.3.2 + cpe:/a:beroftpd:beroftpd:1.3.3 + cpe:/a:washington_university:wu-ftpd:2.5 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr16 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr17 + cpe:/a:beroftpd:beroftpd:1.3.4 + + CVE-1999-0878 + 1999-08-22T00:00:00.000-04:00 + 2008-09-09T08:36:06.993-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 599 + + Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. + + + + + + + + + + + cpe:/o:caldera:openlinux:1.0 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0879 + 1999-10-01T00:00:00.000-04:00 + 2008-09-09T08:36:07.070-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. + + + + + + + + + + + cpe:/o:caldera:openlinux:1.0 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:bsdi:bsd_os:2.1 + + CVE-1999-0880 + 1999-10-01T00:00:00.000-04:00 + 2008-09-09T08:36:07.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly. + + + + + + + + + cpe:/a:blueface:falcon_web_server:1.0 + + CVE-1999-0881 + 1999-10-26T00:00:00.000-04:00 + 2008-09-09T08:36:07.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 743 + + + OSVDB + 1127 + + Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:falcon:falcon_web_server:1.0.0.1006 + + CVE-1999-0882 + 1999-10-28T00:00:00.000-04:00 + 2008-09-09T08:36:07.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. + + + + + + + + + + cpe:/a:zeus_technologies:zeus_web_server:3.3.1 + cpe:/a:zeus_technologies:zeus_web_server:3.3.2 + + CVE-1999-0883 + 1999-10-25T00:00:00.000-04:00 + 2008-09-09T08:36:07.337-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + zeus-remote-root(3380) + + + BID + 742 + + + OSVDB + 1126 + + Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine. + + + + + + + + + + cpe:/a:zeus_technologies:zeus_web_server:3.3.1 + cpe:/a:zeus_technologies:zeus_web_server:3.3.2 + + CVE-1999-0884 + 1999-10-25T00:00:00.000-04:00 + 2008-09-09T08:36:07.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + zeus-weak-password(3833) + + + BID + 742 + + + OSVDB + 8186 + + The Zeus web server administrative interface uses weak encryption for its passwords. + + + + + + + + + cpe:/a:computer_software_manufaktur:alibaba:2.0 + + CVE-1999-0885 + 1999-11-03T00:00:00.000-05:00 + 2008-09-09T08:36:07.477-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 770 + + + BUGTRAQ + 19991103 More Alibaba Web Server problems... + + Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0886 + 1999-09-17T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 9.0 + NETWORK + LOW + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 645 + + + MS + MS99-041 + + + MSKB + Q242294 + + The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. + + + + + + + + + cpe:/a:floosietek:ftgate:2.1 + + CVE-1999-0887 + 1999-11-04T00:00:00.000-05:00 + 2008-09-09T08:36:07.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 1137 + + + EEYE + AD05261999 + + FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack. + + + + + + + + + + + + + + + cpe:/a:oracle:oracle8i:8.0.5 + cpe:/a:oracle:oracle8i:8.0.4 + cpe:/a:oracle:database_server:7.3.3 + cpe:/a:oracle:oracle8i:8.0.3 + cpe:/a:oracle:database_server:7.3.4 + cpe:/a:oracle:oracle8i:8.0.5.1 + cpe:/a:oracle:oracle8i:8.1.5 + + CVE-1999-0888 + 1999-08-16T00:00:00.000-04:00 + 2008-09-09T08:36:07.680-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 585 + + dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script. + + + + + + + + + cpe:/h:cisco:675_router + + CVE-1999-0889 + 1999-07-01T00:00:00.000-04:00 + 2008-09-09T08:36:07.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 39 + + Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set. + + + + + + + + + cpe:/a:ihtml_merchant:ihtml_merchant + + CVE-1999-0890 + 1999-09-16T00:00:00.000-04:00 + 2008-09-09T08:36:07.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.ihtmlmerchant.com/support_patches_feedback.htm + + + BID + 694 + + iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-0891 + 1999-09-01T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#37828 + + + BID + 674 + + + OSVDB + 11274 + + + MS + MS99-040 + + + CIAC + K-002 + + + MSKB + Q242542 + + The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. + + + + + + + + + cpe:/a:netscape:communicator:4.5 + + CVE-1999-0892 + 1999-12-24T00:00:00.000-05:00 + 2008-09-09T08:36:08.133-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font. + + + + + + + + + cpe:/o:sco:openserver:5.0 + + CVE-1999-0893 + 1999-10-11T00:00:00.000-04:00 + 2008-09-09T08:36:08.197-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack. + + + + + + + + + cpe:/o:redhat:linux + + CVE-1999-0894 + 2000-01-04T00:00:00.000-05:00 + 2008-09-05T16:18:14.153-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals. + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.0 + + CVE-1999-0895 + 1999-10-20T00:00:00.000-04:00 + 2008-09-09T08:36:08.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication + + + BID + 725 + + + OSVDB + 1117 + + Firewall-1 does not properly restrict access to LDAP attributes. + + + + + + + + + cpe:/a:realnetworks:realserver_g2:1.0 + + CVE-1999-0896 + 1999-11-04T00:00:00.000-05:00 + 2008-09-09T08:36:08.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://service.real.com/help/faq/servg260.html + + + BID + 767 + + Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password. + + + + + + + + + cpe:/a:apple:ichat_server:3.0 + + CVE-1999-0897 + 1998-09-09T00:00:00.000-04:00 + 2008-09-09T08:36:08.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980908 bug in iChat 3.0 (maybe others) + + iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0898 + 1999-11-04T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 768 + + + MS + MS99-047 + + + MSKB + Q243649 + + Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0899 + 1999-11-04T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 769 + + + MS + MS99-047 + + + MSKB + Q243649 + + The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. + + + + + + + + + cpe:/a:linux-nis:rpc.yppasswdd + + CVE-1999-0900 + 1999-10-23T00:00:00.000-04:00 + 2008-09-09T08:36:08.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation. + + + + + + + + + cpe:/a:linux-nis:ypserv + + CVE-1999-0901 + 1999-10-23T00:00:00.000-04:00 + 2008-09-09T08:36:08.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ypserv allows a local user to modify the GECOS and login shells of other users. + + + + + + + + + cpe:/a:linux-nis:ypserv + + CVE-1999-0902 + 1999-10-23T00:00:00.000-04:00 + 2008-09-09T08:36:08.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ypserv allows local administrators to modify password tables. + + + + + + + + + cpe:/o:ibm:aix:4.3.2 + + CVE-1999-0903 + 1999-10-26T00:00:00.000-04:00 + 2008-09-09T08:36:09.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767. + + + + + + + + + cpe:/a:byte_fusion:bftelnet:1.1 + + CVE-1999-0904 + 1999-11-03T00:00:00.000-05:00 + 2008-09-09T08:36:09.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 771 + + Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username. + + + + + + + + + cpe:/a:axent:raptor_firewall + + CVE-1999-0905 + 1999-10-21T00:00:00.000-04:00 + 2008-09-09T08:36:09.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 736 + + + OSVDB + 1121 + + Denial of service in Axent Raptor firewall via malformed zero-length IP options. + + + + + + + + + cpe:/o:suse:suse_linux:6.2 + + CVE-1999-0906 + 1999-09-23T00:00:00.000-04:00 + 2008-09-09T08:36:09.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 656 + + Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable. + + + + + + + + + cpe:/a:steven_j._merrifield:soundcard_cw:1.1::linux + + CVE-1999-0907 + 1999-09-16T00:00:00.000-04:00 + 2008-09-09T08:36:09.307-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + sccw allows local users to read arbitrary files. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0908 + 1999-09-23T00:00:00.000-04:00 + 2008-09-09T08:36:09.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 655 + + Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_95:0a + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_95:0b + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0909 + 1999-09-20T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + MS + MS99-038 + + + BID + 646 + + + MSKB + Q238453 + + Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:site_server_commerce:3.0:alpha + cpe:/a:microsoft:commercial_internet_system:2.5 + cpe:/a:microsoft:commercial_internet_system:2.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-0910 + 1999-09-10T00:00:00.000-04:00 + 2008-09-09T08:36:09.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-035 + + + BID + 625 + + Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. + + + + + + + + + + + + + cpe:/a:proftpd_project:proftpd:1.2_pre5 + cpe:/a:proftpd_project:proftpd:1.2_pre3 + cpe:/a:proftpd_project:proftpd:1.2_pre4 + cpe:/a:proftpd_project:proftpd:1.2_pre1 + cpe:/a:proftpd_project:proftpd:1.2_pre2 + + CVE-1999-0911 + 1999-08-27T00:00:00.000-04:00 + 2008-09-09T08:36:09.587-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 612 + + + DEBIAN + 19990210 + + Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. + + + + + + + + + + + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + + CVE-1999-0912 + 1999-09-22T00:00:00.000-04:00 + 2008-09-09T08:36:09.647-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 653 + + + OSVDB + 1079 + + FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files. + + + + + + + + + cpe:/a:network_security_wizards:dragon-fire_ids:1.0 + + CVE-1999-0913 + 1999-08-05T00:00:00.000-04:00 + 2008-09-09T08:36:09.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 564 + + + BUGTRAQ + 19990804 NSW Dragon Fire gets drowned + + dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. + + + + + + + + + + + + + cpe:/o:debian:debian_linux:1.3.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:1.1 + cpe:/o:debian:debian_linux:1.2 + cpe:/o:debian:debian_linux:1.3 + + CVE-1999-0914 + 1999-01-03T00:00:00.000-05:00 + 2008-09-09T08:36:09.773-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 324 + + Buffer overflow in the FTP client in the Debian GNU/Linux netstd package. + + + + + + + + + cpe:/a:pacific_software:url_live:1.0 + + CVE-1999-0915 + 1999-10-28T00:00:00.000-04:00 + 2008-09-09T08:36:09.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 746 + + + OSVDB + 1129 + + URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + cpe:/a:webtrends:webtrends_security_analyzer:v2.0 + cpe:/a:webtrends:webtrends_log_analyzer:v4.51 + cpe:/a:webtrends:webtrends_professional_suite:v3.01 + cpe:/a:webtrends:webtrends_for_firewalls:v1.2 + cpe:/a:webtrends:webtrends_enterprise_suite:v3.5 + + CVE-1999-0916 + 1999-06-29T00:00:00.000-04:00 + 2008-09-09T08:36:09.913-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + WebTrends software stores account names and passwords in a file which does not have restricted access permissions. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + + CVE-1999-0917 + 1999-05-27T00:00:00.000-04:00 + 2008-09-09T08:36:09.977-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q231452 + + + MS + MS99-018 + + The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0918 + 1999-07-03T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-034 + + + BID + 514 + + + MSKB + Q238329 + + Denial of service in various Windows systems via malformed, fragmented IGMP packets. + + + + + + + + + cpe:/h:motorola:motorola_cablerouter + + CVE-1999-0919 + 1998-05-10T00:00:00.000-04:00 + 2008-09-05T16:18:17.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + motorola-cable-crash(2004) + + + BUGTRAQ + 19980510 Security Vulnerability in Motorola CableRouters + + A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections. + + + + + + + + + + cpe:/a:university_of_washington:imap:4.4 + cpe:/a:university_of_washington:pop2d + + CVE-1999-0920 + 1999-05-26T00:00:00.000-04:00 + 2008-09-09T08:36:10.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 283 + + Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. + + + + + + + + + cpe:/a:bmc:patrol_agent:3.2.5 + + CVE-1999-0921 + 1999-04-01T00:00:00.000-05:00 + 2008-09-09T08:36:12.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1879 + + + BUGTRAQ + 19990409 Patrol security bugs + + + XF + bmc-patrol-udp-dos(4291) + + BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service. + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + + CVE-1999-0922 + 2001-03-12T00:00:00.000-05:00 + 2008-09-09T08:36:12.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB99-02 + + An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file. + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + + CVE-1999-0923 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:18:18.370-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + ALLAIRE + ASB99-02 + + Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + + CVE-1999-0924 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:18:18.510-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB99-02 + + + XF + coldfusion-syntax-checker(1742) + + + OSVDB + 3236 + + The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service. + + + + + + + + + cpe:/a:messagemedia:unitymail:2.0 + + CVE-1999-0925 + 1999-09-03T00:00:00.000-04:00 + 2008-09-09T08:36:12.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980903 Web servers / possible DOS Attack / mime header flooding + + UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers. + + + + + + + + + cpe:/a:apache:http_server:1.2.5 + + CVE-1999-0926 + 1999-09-03T00:00:00.000-04:00 + 2008-09-05T16:18:18.793-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990903 Web servers / possible DOS Attack / mime header flooding + + Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. + + + + + + + + + cpe:/a:gordano:ntmail:4.20 + + CVE-1999-0927 + 1999-05-26T00:00:00.000-04:00 + 2008-09-09T08:36:12.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 279 + + + EEYE + AD05261999 + + NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:smartdesk:websuite:2.1 + + CVE-1999-0928 + 1999-05-23T00:00:00.000-04:00 + 2008-09-09T08:36:12.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 278 + + Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + + + + + + cpe:/o:novell:netware:4.1 + cpe:/a:novell:http_server:3.1r1 + cpe:/a:novell:http_server:2.51r1 + cpe:/o:novell:netware:4.11 + + CVE-1999-0929 + 1999-06-16T00:00:00.000-04:00 + 2008-09-09T08:36:12.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests. + + + + + + + + + cpe:/a:matt_wright:wwwboard + + CVE-1999-0930 + 1998-09-03T00:00:00.000-04:00 + 2008-09-09T08:36:13.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml + + + XF + http-cgi-wwwboard(2344) + + + BID + 1795 + + wwwboard allows a remote attacker to delete message board articles via a malformed argument. + + + + + + + + + + cpe:/a:mediahouse_software:statistics_server:5.0 + cpe:/a:mediahouse_software:statistics_server:4.28 + + CVE-1999-0931 + 1999-09-30T00:00:00.000-04:00 + 2008-09-09T08:36:13.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 734 + + Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. + + + + + + + + + + cpe:/a:mediahouse_software:statistics_server:5.1 + cpe:/a:mediahouse_software:statistics_server:4.28 + + CVE-1999-0932 + 1999-09-30T00:00:00.000-04:00 + 2008-09-09T08:36:13.133-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 735 + + Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file. + + + + + + + + + cpe:/a:teamshare:teamtrack:3.0 + + CVE-1999-0933 + 1999-10-01T00:00:00.000-04:00 + 2008-09-09T08:36:13.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 689 + + + OSVDB + 1096 + + TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + CVE-1999-0934 + 1999-12-15T00:00:00.000-05:00 + 2005-05-02T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-classifieds-read(3102) + + + BID + 2020 + + classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. + + + CVE-1999-0935 + 1999-12-15T00:00:00.000-05:00 + 2005-05-02T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form. + + + CVE-1999-0936 + 1998-12-03T00:00:00.000-05:00 + 2005-05-02T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. + + + CVE-1999-0937 + 1998-12-03T00:00:00.000-05:00 + 2005-05-02T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. + + + + + + + + + cpe:/a:university_college_london:sdr:2.6.2 + + CVE-1999-0938 + 1999-06-28T00:00:00.000-04:00 + 2008-09-09T08:36:13.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages. + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::pre_potato + cpe:/o:debian:debian_linux:2.1 + + CVE-1999-0939 + 1999-08-26T00:00:00.000-04:00 + 2008-09-09T08:36:13.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 605 + + Denial of service in Debian IRC Epic/epic4 client via a long string. + + + + + + + + + cpe:/a:mutt:mutt_mail_client + + CVE-1999-0940 + 1999-09-27T00:00:00.000-04:00 + 2008-09-05T16:18:20.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages. + + + + + + + + + cpe:/a:mutt:mutt:0.95.6 + + CVE-1999-0941 + 1998-07-28T00:00:00.000-04:00 + 2008-09-09T08:36:13.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19980728 mutt x.x + + Mutt mail client allows a remote attacker to execute commands via shell metacharacters. + + + + + + + + + cpe:/o:sco:unixware:7.1 + + CVE-1999-0942 + 1999-10-04T00:00:00.000-04:00 + 2008-09-09T08:36:13.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes. + + + + + + + + + cpe:/a:openlink:openlink:a + + CVE-1999-0943 + 1999-10-15T00:00:00.000-04:00 + 2008-09-09T08:36:13.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 720 + + Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator. + + + CVE-1999-0944 + 1999-10-24T00:00:00.000-04:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.0 + + CVE-1999-0945 + 2001-03-12T00:00:00.000-05:00 + 2008-09-15T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + ISS + 19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5 + + + CIAC + I-080 + + + XF + exchange-dos(1223) + + + MSKB + Q169174 + + Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. + + + + + + + + + cpe:/a:yamaha:midiplug:1.1bj + + CVE-1999-0946 + 1999-11-02T00:00:00.000-05:00 + 2008-09-09T08:36:14.087-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 760 + + + BUGTRAQ + 19991102 Some holes for Win/UNIX softwares + + Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. + + + + + + + + + cpe:/a:an:an-httpd:1.2b + + CVE-1999-0947 + 1999-11-02T00:00:00.000-05:00 + 2008-09-09T08:36:14.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 762 + + + BUGTRAQ + 19991102 Some holes for Win/UNIX softwares + + AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:5.3 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0948 + 1999-11-02T00:00:00.000-05:00 + 2008-09-09T08:36:14.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 757 + + Buffer overflow in uum program for Canna input system allows local users to gain root privileges. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:5.3 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-0949 + 1999-11-02T00:00:00.000-05:00 + 2008-09-09T08:36:14.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 757 + + Buffer overflow in canuum program for Canna input system allows local users to gain root privileges. + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-1999-0950 + 1999-10-28T00:00:00.000-04:00 + 2008-09-09T08:36:14.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 747 + + Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. + + + + + + + + + + cpe:/a:omnicron:omnihttpd:1.1 + cpe:/a:omnicron:omnihttpd:2.4pro + + CVE-1999-0951 + 1999-10-22T00:00:00.000-04:00 + 2008-09-09T08:36:14.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 739 + + + OSVDB + 3380 + + Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands. + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + + CVE-1999-0952 + 1999-01-28T00:00:00.000-05:00 + 2008-09-09T08:36:14.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990126 Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat + + Buffer overflow in Solaris lpstat via class argument allows local users to gain root access. + + + + + + + + + cpe:/a:matt_wright:wwwboard:2.0_alpha_2.1 + + CVE-1999-0953 + 1999-09-16T00:00:00.000-04:00 + 2008-09-09T08:36:14.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. + + + + + + + + + cpe:/a:matt_wright:wwwboard:2.0_alpha_2 + + CVE-1999-0954 + 1999-09-16T00:00:00.000-04:00 + 2008-09-09T08:36:14.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 649 + + WWWBoard has a default username and default password. + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.4.1 + + CVE-1999-0955 + 1997-09-23T00:00:00.000-04:00 + 2008-09-09T08:36:14.697-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command. + + + + + + + + + + + + + cpe:/o:next:nextstep:2.0 + cpe:/o:next:nextstep:2.1 + cpe:/o:next:nextstep:1.0 + cpe:/o:next:nextstep:3.0 + cpe:/o:next:nextstep:1.0a + + CVE-1999-0956 + 1997-09-19T00:00:00.000-04:00 + 2008-09-09T08:36:14.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service. + + + + + + + + + cpe:/a:great_circle_associates:majorcool:1.0.3 + + CVE-1999-0957 + 1997-06-18T00:00:00.000-04:00 + 2008-09-09T08:36:14.837-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + MajorCool mj_key_cache program allows local users to modify files via a symlink attack. + + + + + + + + + + + cpe:/a:todd_miller:sudo:1.5 + cpe:/a:todd_miller:sudo:1.5.2 + cpe:/a:todd_miller:sudo:1.5.3 + + CVE-1999-0958 + 1998-01-12T00:00:00.000-05:00 + 2008-09-09T08:36:14.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980112 Re: hole in sudo for MP-RAS. + + sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0959 + 1997-02-01T00:00:00.000-05:00 + 2008-09-09T08:36:14.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 469 + + + OSVDB + 8447 + + + SGI + 19980301-01-PX + + IRIX startmidi program allows local users to modify arbitrary files via a symlink attack. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-0960 + 1998-03-20T00:00:00.000-05:00 + 2008-09-09T08:36:15.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19980301-01-PX + + IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option. + + + + + + + + + + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.05 + + CVE-1999-0961 + 1996-09-21T00:00:00.000-04:00 + 2008-09-09T08:36:15.103-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19960921 Vunerability in HP sysdiag ? + + HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-0962 + 1997-05-14T00:00:00.000-04:00 + 2008-09-09T08:36:15.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9701-045 + + + OSVDB + 6415 + + Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option. + + + + + + + + + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-0963 + 1999-12-01T00:00:00.000-05:00 + 2008-09-09T08:36:15.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 6088 + + FreeBSD mount_union command allows local users to gain root privileges via a symlink attack. + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.6 + + CVE-1999-0964 + 2000-01-01T00:00:00.000-05:00 + 2008-09-09T08:36:15.367-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 6086 + + Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable. + + + + + + + + + cpe:/a:x.org:xterm + + CVE-1999-0965 + 1997-09-19T00:00:00.000-04:00 + 2008-09-09T08:36:15.430-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Race condition in xterm allows local users to modify arbitrary files via the logging option. + + + + + + + + + cpe:/o:sun:solaris:2.5 + + CVE-1999-0966 + 1997-01-27T00:00:00.000-05:00 + 2008-09-09T08:36:15.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0]. + + + + + + + + + + + cpe:/a:microsoft:outlook_express + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:windows_explorer + + CVE-1999-0967 + 1997-11-01T00:00:00.000-05:00 + 2008-09-09T08:36:15.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. + + + + + + + + + cpe:/a:james_seter:bnc_irc:2.2.4 + + CVE-1999-0968 + 1998-12-26T00:00:00.000-05:00 + 2008-09-09T08:36:15.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + bnc-proxy-bo(1546) + + + BID + 1927 + + + BUGTRAQ + 19981226 bnc exploit + + Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0969 + 1998-09-29T00:00:00.000-04:00 + 2008-09-09T08:36:15.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q193233 + + + MS + MS98-014 + + The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork. + + + + + + + + + cpe:/a:omnicron:omnihttpd + + CVE-1999-0970 + 1999-06-05T00:00:00.000-04:00 + 2008-09-09T08:36:15.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + omnihttpd-dos(2271) + + + BID + 1808 + + + BUGTRAQ + 19990605 Remote Exploit (Bug) in OmniHTTPd Web Server + + The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. + + + + + + + + + cpe:/a:university_of_cambridge:exim:1.62 + + CVE-1999-0971 + 1997-07-22T00:00:00.000-04:00 + 2008-09-09T08:36:34.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19970722 Security hole in exim 1.62: local root exploit + + Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file. + + + + + + + + + + cpe:/a:wolfpack_development:xshipwars:1.0 + cpe:/a:wolfpack_development:xshipwars:1.2.4 + + CVE-1999-0972 + 1999-12-09T00:00:00.000-05:00 + 2008-09-09T08:36:34.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 863 + + Buffer overflow in Xshipwars xsw program. + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0973 + 1999-12-07T00:00:00.000-05:00 + 2008-09-09T08:36:34.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 858 + + Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode. + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0974 + 1999-12-09T00:00:00.000-05:00 + 2008-09-09T08:36:34.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 864 + + + SUN + 00190 + + Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0975 + 1999-12-10T00:00:00.000-05:00 + 2008-09-09T08:36:34.523-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 868 + + The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. + + + + + + + + + cpe:/a:eric_allman:sendmail:8.9.3 + + CVE-1999-0976 + 1999-12-07T00:00:00.000-05:00 + 2008-09-09T08:36:34.633-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 857 + + Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-0977 + 1999-12-10T00:00:00.000-05:00 + 2008-09-09T08:36:34.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 866 + + + BID + 2354 + + + OSVDB + 2558 + + + SUN + 00191 + + Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + + CVE-1999-0978 + 1999-12-09T00:00:00.000-05:00 + 2008-09-09T08:36:34.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 867 + + htdig allows remote attackers to execute commands via filenames with shell metacharacters. + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0979 + 2000-04-11T00:00:00.000-04:00 + 2008-09-09T08:36:34.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 869 + + + BUGTRAQ + 19991215 Recent postings about SCO UnixWare 7 + + The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0980 + 2000-05-16T00:00:00.000-04:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-055 + + + MSKB + Q246045 + + Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request. + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.01 + + CVE-1999-0981 + 1999-12-08T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS99-050 + + + MSKB + Q246094 + + Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." + + + + + + + + + + + + + + + cpe:/a:sun:web-based_enterprise_management:1.0 + cpe:/a:sun:web-based_enterprise_management:2.0 + cpe:/o:sun:solaris:8.0:beta + + CVE-1999-0982 + 1999-12-05T00:00:00.000-05:00 + 2008-09-09T08:36:35.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file. + + + + + + + + + cpe:/a:internic:whois_lookup:1.0 + + CVE-1999-0983 + 1999-11-09T00:00:00.000-05:00 + 2008-09-09T08:36:35.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. + + + + + + + + + cpe:/a:matts_whois:matts_whois:1.0 + + CVE-1999-0984 + 1999-11-09T00:00:00.000-05:00 + 2008-09-09T08:36:35.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. + + + + + + + + + cpe:/a:cc:cc_whois:1.0 + + CVE-1999-0985 + 1999-11-09T00:00:00.000-05:00 + 2008-09-09T08:36:35.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:linux:linux_kernel:2.0.38 + cpe:/o:linux:linux_kernel:2.0.37 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:linux:linux_kernel:2.0.35 + cpe:/o:linux:linux_kernel:2.0.36 + cpe:/o:linux:linux_kernel:2.0.34 + cpe:/o:linux:linux_kernel:2.0 + + CVE-1999-0986 + 1999-12-08T00:00:00.000-05:00 + 2008-09-09T08:36:35.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 870 + + The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-0987 + 1999-11-18T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MSKB + Q237923 + + Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. + + + + + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.16 + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:2.0 + cpe:/o:sco:unixware:2.1 + cpe:/o:sco:unixware:2.0.3 + cpe:/o:sco:unixware:7.1 + + CVE-1999-0988 + 1999-12-04T00:00:00.000-05:00 + 2008-09-09T08:36:35.570-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack. + + + + + + + + + + + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:5::windows_nt_4.0 + + CVE-1999-0989 + 1999-12-06T00:00:00.000-05:00 + 2008-09-09T08:36:35.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 861 + + Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. + + + + + + + + + cpe:/a:gnome:gdm:2.0_beta4 + + CVE-1999-0990 + 1999-12-05T00:00:00.000-05:00 + 2008-09-09T08:36:35.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system. + + + + + + + + + cpe:/a:goodtech:telnet_server_nt:2.2.1 + + CVE-1999-0991 + 1999-12-06T00:00:00.000-05:00 + 2008-09-09T08:36:35.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 862 + + Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name. + + + + + + + + + cpe:/o:hp:vvos + + CVE-1999-0992 + 2000-01-18T00:00:00.000-05:00 + 2008-09-05T16:18:28.057-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9912-107 + + HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP). + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.0 + + CVE-1999-0993 + 1999-12-13T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0994 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 873 + + + MS + MS99-056 + + + MSKB + Q248183 + + Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-0995 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 875 + + + MS + MS99-057 + + + MSKB + Q248185 + + Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." + + + + + + + + + cpe:/a:infoseek:ultraseek_server:3.1 + + CVE-1999-0996 + 1999-12-15T00:00:00.000-05:00 + 2008-09-09T08:36:36.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 6490 + + + EEYE + AD19991215 + + Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request. + + + + + + + + + + + + + + + + + + + cpe:/a:millenux_gmbh:anonftp:2.8.1 + cpe:/a:university_of_washington:wu-ftpd:2.6.0 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:6.0 + cpe:/a:university_of_washington:wu-ftpd:2.4.2 + cpe:/a:university_of_washington:wu-ftpd:2.5.0 + + CVE-1999-0997 + 1999-12-20T00:00:00.000-05:00 + 2008-09-05T16:18:28.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-377 + + wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress. + + + + + + + + + cpe:/h:cisco:cache_engine:2 + + CVE-1999-0998 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T08:36:36.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Cisco Cache Engine allows an attacker to replace content in the cache. + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + + CVE-1999-0999 + 1999-11-19T00:00:00.000-05:00 + 2008-09-09T00:00:00.000-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 817 + + + MS + MS99-059 + + + MSKB + Q248749 + + Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. + + + + + + + + + cpe:/h:cisco:cache_engine:2 + + CVE-1999-1000 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T08:36:36.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics. + + + + + + + + + cpe:/h:cisco:cache_engine:1.0 + + CVE-1999-1001 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T08:36:36.460-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Cisco Cache Engine allows a remote attacker to gain access via a null username and password. + + + + + + + + + cpe:/a:netscape:communicator:4.7 + + CVE-1999-1002 + 2000-01-12T00:00:00.000-05:00 + 2008-09-09T08:36:36.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.rstcorp.com/news/bad-crypto.html + + + BUGTRAQ + 19991220 Netscape password scrambling + + + BUGTRAQ + 19991216 Reinventing the wheel (aka "Decoding Netscape Mail passwords") + + Netscape Navigator uses weak encryption for storing a user's Netscape mail password. + + + + + + + + + cpe:/a:jgaa:warftpd:1.70 + + CVE-1999-1003 + 1999-12-13T00:00:00.000-05:00 + 2008-09-09T08:36:36.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2000 + + CVE-1999-1004 + 1999-12-16T00:00:00.000-05:00 + 2008-09-09T08:36:36.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991220 Norton Email Protection Remote Overflow (Addendum) + + + BUGTRAQ + 19991217 NAV2000 Email Protection DoS + + + OSVDB + 6267 + + + CONFIRM + http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&Highlight=0,poproxy + + Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command. + + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.0.7a + cpe:/a:novell:groupwise:5.2 + cpe:/a:novell:groupwise:5.5 + + CVE-1999-1005 + 1999-12-19T00:00:00.000-05:00 + 2008-09-09T08:36:36.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 879 + + + OSVDB + 3413 + + + BUGTRAQ + 19991219 Groupewise Web Interface + + Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter. + + + + + + + + + + cpe:/a:novell:groupwise:5.2 + cpe:/a:novell:groupwise:5.5 + + CVE-1999-1006 + 1999-12-19T00:00:00.000-05:00 + 2008-09-09T08:36:36.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991219 Groupewise Web Interface + + Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter. + + + + + + + + + cpe:/a:vdonet:vdolive_player:3.0.2 + + CVE-1999-1007 + 1999-12-13T00:00:00.000-05:00 + 2008-09-09T08:36:37.040-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 872 + + + BUGTRAQ + 19991213 VDO Live Player 3.02 Buffer Overflow + + Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file. + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-1008 + 2000-05-17T00:00:00.000-04:00 + 2008-09-09T08:36:37.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 871 + + + MISC + http://marc.theaimsgroup.com/?l=freebsd-security&m=94531826621620&w=2 + + xsoldier program allows local users to gain root access via a long argument. + + + + + + + + + cpe:/a:disney:go_express_search + + CVE-1999-1009 + 1999-12-12T00:00:00.000-05:00 + 2008-09-09T08:36:37.180-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system. + + + + + + + + + cpe:/a:openbsd:openssh:1.2.27 + + CVE-1999-1010 + 1999-12-14T00:00:00.000-05:00 + 2008-09-09T08:36:37.257-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991214 sshd1 allows unencrypted sessions regardless of server policy + + An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy. + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:index_server:2.0 + cpe:/a:microsoft:data_access_components:1.5 + cpe:/a:microsoft:site_server:3.0 + cpe:/a:microsoft:data_access_components:2.1 + cpe:/a:microsoft:data_access_components:2.0 + + CVE-1999-1011 + 1999-07-19T00:00:00.000-04:00 + 2011-03-07T21:01:28.643-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + MS + MS99-025 + + + OSVDB + 272 + + + MS + MS98-004 + + + BID + 529 + + The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:lotus:domino:4.6.1::as_400 + + CVE-1999-1012 + 1999-05-04T00:00:00.000-04:00 + 2008-09-05T16:18:30.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 173 + + + BUGTRAQ + 19990504 AS/400 + + SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string. + + + + + + + + + + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.2.1 + + CVE-1999-1013 + 1999-09-23T00:00:00.000-04:00 + 2008-09-05T16:18:31.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 673 + + + BUGTRAQ + 19990923 named-xfer hole on AIX (fwd) + + named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file. + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.7 + + CVE-1999-1014 + 1999-09-13T00:00:00.000-04:00 + 2008-09-05T16:18:31.183-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-usrbinmail-local-bo(3297) + + + BID + 672 + + + BUGTRAQ + 19990927 Working Solaris x86 /usr/bin/mail exploit + + + BUGTRAQ + 19990913 Solaris 2.7 /usr/bin/mail + + Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument. + + + + + + + + + cpe:/a:apple:appleshare_mail_server:5.0.3:::jp + + CVE-1999-1015 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:18:31.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 61 + + + BUGTRAQ + 19980408 AppleShare IP Mail Server + + Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command. + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:ie:5.0 + cpe:/a:qualcomm:eudora + cpe:/a:microsoft:frontpage:::express + + CVE-1999-1016 + 1999-08-27T00:00:00.000-04:00 + 2008-09-05T16:18:31.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 606 + + + NTBUGTRAQ + 19990827 HTML code to crash IE5 and Outlook Express 5 + + Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. + + + + + + + + + cpe:/a:seattle_lab_software:emurl:2.0 + + CVE-1999-1017 + 1999-07-28T00:00:00.000-04:00 + 2008-09-05T16:18:31.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 544 + + + NTBUGTRAQ + 19990728 Seattle Labs EMURL Vulnerability + + Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.10 + + CVE-1999-1018 + 1999-07-27T00:00:00.000-04:00 + 2008-09-05T16:18:31.760-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 543 + + + BUGTRAQ + 19990727 Linux 2.2.10 ipchains Advisory + + IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets. + + + + + + + + + cpe:/a:cabletron:spectrum_enterprise_manager:5.0 + + CVE-1999-1019 + 1999-06-23T00:00:00.000-04:00 + 2008-09-05T16:18:31.900-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 495 + + + BUGTRAQ + 19990623 Cabletron Spectrum security vulnerability + + + BUGTRAQ + 19990624 Re: Cabletron Spectrum security vulnerability + + SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise. + + + + + + + + + + cpe:/o:novell:netware:4.11:sp5b + cpe:/o:novell:netware:4.1 + + CVE-1999-1020 + 1998-09-18T00:00:00.000-04:00 + 2008-09-05T16:18:32.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + novell-nds(1364) + + + BID + 484 + + + BUGTRAQ + 19980918 NMRC Advisory - Default NDS Rights + + The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE. + + + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1021 + 1992-12-30T00:00:00.000-05:00 + 2008-09-05T16:18:32.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-15 + + + BID + 47 + + + SUN + 00117 + + + XF + nfs-uid(82) + + NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade. + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:4 + + CVE-1999-1022 + 1994-10-02T00:00:00.000-04:00 + 2008-09-05T16:18:32.337-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-serialports(2111) + + + BID + 464 + + + BUGTRAQ + 19941002 + + serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program. + + + + + + + + + cpe:/o:sun:solaris:7.0 + + CVE-1999-1023 + 1999-06-10T00:00:00.000-04:00 + 2008-09-05T16:18:32.480-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 426 + + + BUGTRAQ + 19990610 Sun Useradd program expiration date bug + + useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired. + + + + + + + + + cpe:/a:lbl:tcpdump:3.4 + + CVE-1999-1024 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:18:32.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 313 + + + BUGTRAQ + 19990620 Re: tcpdump 3.4 bug? (final) + + + BUGTRAQ + 19990617 Re: tcpdump 3.4 bug? + + + BUGTRAQ + 19990616 tcpdump 3.4 bug? + + ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet. + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:sunos:5.6 + + CVE-1999-1025 + 1998-11-12T00:00:00.000-05:00 + 2008-09-05T16:18:32.777-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 294 + + + SUNBUG + 4115685 + + + BUGTRAQ + 19981012 Annoying Solaris/CDE/NIS+ bug + + CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string. + + + + + + + + + + + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-1999-1026 + 1996-12-20T00:00:00.000-05:00 + 2008-09-05T16:18:32.917-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 292 + + + BUGTRAQ + 19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole) + + aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file. + + + + + + + + + cpe:/o:sun:solaris:2.6 + + CVE-1999-1027 + 1998-05-07T00:00:00.000-04:00 + 2008-09-05T16:18:33.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 290 + + + BUGTRAQ + 19980507 admintool mode 0777 in Solaris 2.6 HW3/98 + + + XF + solaris-admintool-world-writable(7296) + + Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program. + + + + + + + + + cpe:/a:symantec:pcanywhere:8.0 + + CVE-1999-1028 + 1999-05-28T00:00:00.000-04:00 + 2008-09-05T16:18:33.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 288 + + + NTBUGTRAQ + 19990528 DoS against PC Anywhere + + + XF + pcanywhere-dos(2256) + + Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631. + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh2:2.0.1 + cpe:/a:ssh:ssh2:2.0.2 + cpe:/a:ssh:ssh2:2.0.3 + cpe:/a:ssh:ssh2:2.0.4 + cpe:/a:ssh:ssh2:2.0.5 + cpe:/a:ssh:ssh2:2.0.6 + cpe:/a:ssh:ssh2:2.0 + cpe:/a:ssh:ssh2:2.0.7 + cpe:/a:ssh:ssh2:2.0.9 + cpe:/a:ssh:ssh2:2.0.8 + cpe:/a:ssh:ssh2:2.0.11 + cpe:/a:ssh:ssh2:2.0.10 + + CVE-1999-1029 + 1999-05-13T00:00:00.000-04:00 + 2008-09-05T16:18:33.323-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ssh2-bruteforce(2193) + + + BID + 277 + + + BUGTRAQ + 19990513 - J.J.F. / Hackers Team warns for SSHD 2.x brute force password hacking + + SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs. + + + + + + + + + cpe:/a:behold_software:web_page_counter:2.7 + + CVE-1999-1030 + 1999-05-19T00:00:00.000-04:00 + 2008-09-05T16:18:33.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 267 + + + NTBUGTRAQ + 19990519 Denial of Service in Counter.exe version 2.70 + + + BUGTRAQ + 19990519 Denial of Service in Counter.exe version 2.70 + + counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation. + + + + + + + + + cpe:/a:behold_software:web_page_counter:2.7 + + CVE-1999-1031 + 1999-05-19T00:00:00.000-04:00 + 2008-09-05T16:18:33.637-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 267 + + + NTBUGTRAQ + 19990519 Denial of Service in Counter.exe version 2.70 + + + BUGTRAQ + 19990519 Denial of Service in Counter.exe version 2.70 + + counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument. + + + + + + + + + + cpe:/o:digital:ultrix:4.2 + cpe:/o:digital:ultrix:4.1 + + CVE-1999-1032 + 1991-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:33.777-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-11 + + + BID + 26 + + + XF + ultrix-telnet(584) + + + CIAC + B-36 + + Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges. + + + + + + + + + + + cpe:/a:microsoft:outlook_express:4.72.3120.0 + cpe:/a:microsoft:outlook_express:4.27.3110.1 + cpe:/a:microsoft:outlook_express:4.72.3612.1700 + + CVE-1999-1033 + 1999-05-11T00:00:00.000-04:00 + 2008-09-05T16:18:33.917-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 252 + + + BUGTRAQ + 19990511 Outlook Express Win98 bug + + + BUGTRAQ + 19990512 Outlook Express Win98 bug, addition. + + Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. + + + + + + + + + cpe:/o:att:svr4:4.0 + + CVE-1999-1034 + 1991-05-23T00:00:00.000-04:00 + 2008-09-05T16:18:34.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-08 + + + BID + 23 + + + XF + sysv-login(583) + + + CIAC + B-28 + + Vulnerability in login in AT&T System V Release 4 allows local users to gain privileges. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1035 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:34.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-019 + + + MSKB + Q192296 + + + XF + iis-get-dos(1823) + + IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. + + + + + + + + + cpe:/a:cops:cops:1.04 + + CVE-1999-1036 + 1998-06-26T00:00:00.000-04:00 + 2008-09-05T16:18:34.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980626 vulnerability in satan, cops & tiger + + COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk. + + + + + + + + + cpe:/a:coast:satan:1.1.1 + + CVE-1999-1037 + 1998-06-26T00:00:00.000-04:00 + 2008-09-09T08:36:46.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980626 vulnerability in satan, cops & tiger + + + OSVDB + 3147 + + + XF + satan-rexsatan-symlink(7167) + + + BUGTRAQ + 19980627 Re: vulnerability in satan, cops & tiger + + rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file. + + + + + + + + + cpe:/a:tamu:tiger:2.2.3 + + CVE-1999-1038 + 1998-06-26T00:00:00.000-04:00 + 2008-09-05T16:18:34.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980626 vulnerability in satan, cops & tiger + + Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable. + + + + + + + + + cpe:/o:sgi:irix:6.4 + + CVE-1999-1039 + 1998-05-27T00:00:00.000-04:00 + 2008-09-09T08:36:46.180-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19980502-01-P3030 + + Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise. + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + + CVE-1999-1040 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:18:34.900-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + I-055 + + + SGI + 19980501-01-P + + + BUGTRAQ + 19980408 SGI O2 ipx security issue + + Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable. + + + + + + + + + + cpe:/o:sco:unix:3.2v4 + cpe:/o:sco:openserver:5.0 + + CVE-1999-1041 + 1998-08-27T00:00:00.000-04:00 + 2008-09-05T16:18:35.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + VB-98.10 + + + BUGTRAQ + 19980827 SCO mscreen vul. + + + SCO + SB-98.05a + + + BUGTRAQ + 19980926 Root exploit for SCO OpenServer. + + Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file. + + + + + + + + + + cpe:/a:cisco:resource_manager:1.0 + cpe:/a:cisco:resource_manager:1.1 + + CVE-1999-1042 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:35.183-04:00 + + + 1.2 + LOCAL + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 19980813 CRM Temporary File Vulnerability + + Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings. + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.0 + + CVE-1999-1043 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:35.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-007 + + Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error). + + + + + + + + + + cpe:/o:digital:unix:v4.0d + cpe:/o:digital:unix:v4.0 + + CVE-1999-1044 + 1998-05-07T00:00:00.000-04:00 + 2011-03-07T21:01:31.423-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CIAC + I-050 + + + XF + dgux-advfs-softlinks(7431) + + Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges. + + + + + + + + + cpe:/a:realnetworks:realserver:5.0 + + CVE-1999-1045 + 1998-01-15T00:00:00.000-05:00 + 2008-09-05T16:18:35.603-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://service.real.com/help/faq/serv501.html + + + BUGTRAQ + 19980817 Re: Real Audio Server Version 5 bug? + + + BUGTRAQ + 19980115 pnserver exploit.. + + + BUGTRAQ + 19980115 [rootshell] Security Bulletin #7 + + + OSVDB + 6979 + + + XF + realserver-pnserver-remote-dos(7297) + + pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request. + + + + + + + + + cpe:/a:ipswitch:imail:5.0 + + CVE-1999-1046 + 1999-03-01T00:00:00.000-05:00 + 2008-09-05T16:18:35.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + imail-imonitor-overflow(1897) + + + BID + 504 + + + BUGTRAQ + 19990302 Multiple IMail Vulnerabilites + + Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181. + + + + + + + + + cpe:/a:bsdi:gauntlet:5.0 + + CVE-1999-1047 + 1999-10-18T00:00:00.000-04:00 + 2008-09-05T16:18:35.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19991018 Gauntlet 5.0 BSDI warning + + + XF + gauntlet-bsdi-bypass(3397) + + + BUGTRAQ + 19991019 Re: Gauntlet 5.0 BSDI warning + + When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities. + + + + + + + + + + cpe:/o:debian:debian_linux:1.3.1 + cpe:/o:redhat:linux:4.2 + + CVE-1999-1048 + 1998-09-05T00:00:00.000-04:00 + 2008-09-05T16:18:36.010-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + linux-bash-bo(3414) + + + DEBIAN + 19980909 problem with very long pathnames + + + BUGTRAQ + 19980905 BASH buffer overflow, LiNUX x86 exploit + + + BUGTRAQ + 19970821 Buffer overflow in /bin/bash + + + OSVDB + 8345 + + Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory. + + + + + + + + + cpe:/a:ca:arcserve_backup:6.5 + + CVE-1999-1049 + 1999-02-21T00:00:00.000-05:00 + 2008-09-09T08:36:46.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990222 Severe Security Hole in ARCserve NT agents (fwd) + + ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password. + + + + + + + + + + + cpe:/a:matt_wright:formhandler.cgi:3.0 + cpe:/a:matt_wright:formhandler.cgi:2.0 + cpe:/a:matt_wright:formhandler.cgi:1.0 + + CVE-1999-1050 + 1999-11-12T00:00:00.000-05:00 + 2008-09-05T16:18:36.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + formhandler-cgi-absolute-path(3550) + + + BID + 799 + + + BID + 798 + + + BUGTRAQ + 19991116 Re: FormHandler.cgi + + + BUGTRAQ + 19991112 FormHandler.cgi + + Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template. + + + + + + + + + + + cpe:/a:matt_wright:formhandler.cgi:3.0 + cpe:/a:matt_wright:formhandler.cgi:2.0 + cpe:/a:matt_wright:formhandler.cgi:1.0 + + CVE-1999-1051 + 1999-11-16T00:00:00.000-05:00 + 2008-09-05T16:18:36.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991116 Re: FormHandler.cgi + + Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. + + + + + + + + + cpe:/a:microsoft:frontpage + + CVE-1999-1052 + 1999-08-24T00:00:00.000-04:00 + 2008-09-05T16:18:36.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990824 Front Page form_results + + Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. + + + + + + + + + + cpe:/a:apache:http_server:1.3.9 + cpe:/a:matt_wright:matt_wright_guestbook:2.3 + + CVE-1999-1053 + 1999-09-13T00:00:00.000-04:00 + 2008-09-05T16:18:36.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 776 + + + VULN-DEV + 19990916 Re: Guestbook perl script (error fix) + + + VULN-DEV + 19990913 Guestbook perl script (long) + + + BUGTRAQ + 19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2) + + guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". + + + + + + + + + cpe:/a:globetrotter:flexlm:6.0d + + CVE-1999-1054 + 1998-09-25T00:00:00.000-04:00 + 2008-09-05T16:18:36.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980925 Globetrotter FlexLM 'lmdown' bogosity + + The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command. + + + + + + + + + cpe:/a:microsoft:excel:97 + + CVE-1999-1055 + 1999-12-31T00:00:00.000-05:00 + 2008-09-09T08:36:47.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + excel-call(1737) + + + MS + MS98-018 + + + BID + 179 + + Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability." + + + CVE-1999-1056 + 1992-12-31T00:00:00.000-05:00 + 2008-09-09T08:36:47.930-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1395. Reason: This candidate is a duplicate of CVE-1999-1395. Notes: All CVE users should reference CVE-1999-1395 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/o:digital:vms:5.3 + + CVE-1999-1057 + 1990-10-25T00:00:00.000-04:00 + 2008-09-05T16:18:37.230-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1990-07 + + + CIAC + B-04 + + + BID + 12 + + + XF + vms-analyze-processdump-privileges(7137) + + VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command. + + + + + + + + + cpe:/a:arcane_software:vermillion_ftp_daemon:1.23 + + CVE-1999-1058 + 1999-11-22T00:00:00.000-05:00 + 2008-09-09T08:36:48.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vermillion-ftp-cwd-overflow(3543) + + + BID + 818 + + + BUGTRAQ + 19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability + + + NTBUGTRAQ + 19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability + + Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands. + + + + + + + + + cpe:/o:att:svr4:4.0 + + CVE-1999-1059 + 1992-02-25T00:00:00.000-05:00 + 2008-09-05T16:18:37.527-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-04 + + + BID + 36 + + + XF + att-rexecd(3159) + + Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:tetrix:tetrinet:1.13.16 + + CVE-1999-1060 + 1999-02-17T00:00:00.000-05:00 + 2008-09-05T16:18:37.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 340 + + + BUGTRAQ + 19990217 Tetrix 1.13.16 is Vulnerable + + Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname. + + + + + + + + + cpe:/h:hp:jetdirect + + CVE-1999-1061 + 1997-10-04T00:00:00.000-04:00 + 2008-09-05T16:18:37.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + laserjet-unpassworded(1876) + + + BUGTRAQ + 19971004 HP Laserjet 4M Plus DirectJet Problem + + HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging. + + + + + + + + + cpe:/h:hp:jetdirect + + CVE-1999-1062 + 1997-10-04T00:00:00.000-04:00 + 2008-09-05T16:18:37.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + laserjet-unpassworded(1876) + + + BUGTRAQ + 19971004 HP Laserjet 4M Plus DirectJet Problem + + HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100. + + + + + + + + + + + + + + cpe:/a:cdomain:cdomainfree:2.1 + cpe:/a:cdomain:cdomainfree:2.0 + cpe:/a:cdomain:cdomainfree:1.0 + cpe:/a:cdomain:cdomainfree:2.3 + cpe:/a:cdomain:cdomainfree:2.2 + cpe:/a:cdomain:cdomainfree:2.4 + + CVE-1999-1063 + 1999-06-01T00:00:00.000-04:00 + 2008-09-05T16:18:38.120-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-cdomain(2251) + + + BID + 304 + + + BUGTRAQ + 19990601 whois_raw.cgi problem + + CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. + + + + + + + + + cpe:/a:windowmaker:windowmaker:0.60.0 + + CVE-1999-1064 + 1999-08-22T00:00:00.000-04:00 + 2008-09-05T16:18:38.260-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 596 + + + BUGTRAQ + 19990824 Re: WindowMaker bugs (was sub:none ) + + + BUGTRAQ + 19990822 + + Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]). + + + + + + + + + cpe:/a:palm_pilot:hotsync_manager:3.0.4 + + CVE-1999-1065 + 1999-11-04T00:00:00.000-05:00 + 2008-09-05T16:18:38.400-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991104 Palm Hotsync vulnerable to DoS attack + + Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode. + + + + + + + + + cpe:/a:sgi:quake_1_server + + CVE-1999-1066 + 1999-12-22T00:00:00.000-05:00 + 2008-09-05T16:18:38.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991222 Quake "smurf" - Quake War Utils + + Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request. + + + + + + + + + cpe:/o:sgi:irix:6.3 + + CVE-1999-1067 + 1997-05-07T00:00:00.000-04:00 + 2008-09-09T08:36:48.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi + + SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities. + + + + + + + + + cpe:/a:oracle:http_server:2.1 + + CVE-1999-1068 + 1997-07-23T00:00:00.000-04:00 + 2008-09-05T16:18:38.823-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures + + Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request. + + + + + + + + + cpe:/a:icat:electronic_commerce_suite:3.0.0 + + CVE-1999-1069 + 1997-11-08T00:00:00.000-05:00 + 2008-09-05T16:18:38.963-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + icat-carbo-server-vuln(1620) + + + BID + 2126 + + + BUGTRAQ + 19971108 Security bug in iCat Suite version 3.0 + + Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter. + + + + + + + + + cpe:/a:xylogics:annex + + CVE-1999-1070 + 1998-07-25T00:00:00.000-04:00 + 2008-09-05T16:18:39.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980725 Annex DoS + + Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter. + + + + + + + + + cpe:/a:excite:ews:1.1 + + CVE-1999-1071 + 1998-11-30T00:00:00.000-05:00 + 2008-09-05T16:18:39.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + excite-world-write(1417) + + + BUGTRAQ + 19981130 Security bugs in Excite for Web Servers 1.1 + + Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file. + + + + + + + + + cpe:/a:excite:ews:1.1 + + CVE-1999-1072 + 1998-11-30T00:00:00.000-05:00 + 2008-09-05T16:18:39.370-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981130 Security bugs in Excite for Web Servers 1.1 + + Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi. + + + + + + + + + cpe:/a:excite:ews:1.1 + + CVE-1999-1073 + 1998-11-30T00:00:00.000-05:00 + 2008-09-05T16:18:39.510-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981130 Security bugs in Excite for Web Servers 1.1 + + Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack. + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.42 + cpe:/a:webmin:webmin:0.41 + cpe:/a:webmin:webmin:0.31 + cpe:/a:webmin:webmin:0.22 + cpe:/a:webmin:webmin:0.21 + cpe:/a:webmin:webmin:0.3 + cpe:/a:webmin:webmin:0.1 + cpe:/a:webmin:webmin:0.2 + cpe:/a:webmin:webmin:0.4 + + CVE-1999-1074 + 1999-12-31T00:00:00.000-05:00 + 2008-09-09T08:36:49.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980501 Warning! Webmin Security Advisory + + + CONFIRM + http://www.webmin.com/webmin/changes.html + + + BID + 98 + + Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking. + + + + + + + + + cpe:/o:ibm:aix:4.1.5 + + CVE-1999-1075 + 1998-03-18T00:00:00.000-05:00 + 2008-09-05T16:18:39.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980318 AIX 4.1.5 DoS attack (aka "Port 1025 problem") + + inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd. + + + + + + + + + cpe:/o:apple:mac_os:9 + + CVE-1999-1076 + 1999-10-26T00:00:00.000-04:00 + 2008-09-05T16:18:39.947-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 745 + + + BUGTRAQ + 19991026 Mac OS 9 Idle Lock Bug + + Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session. + + + + + + + + + cpe:/o:apple:mac_os:9 + + CVE-1999-1077 + 1999-11-01T00:00:00.000-05:00 + 2008-09-05T16:18:40.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 756 + + + BUGTRAQ + 19991101 Re: Mac OS 9 Idle Lock Bug + + Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock. + + + + + + + + + cpe:/a:ipswitch:ws_ftp_pro:6.0 + + CVE-1999-1078 + 1999-07-29T00:00:00.000-04:00 + 2008-09-05T16:18:40.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 547 + + + NTBUGTRAQ + 19990729 WS_FTP Pro 6.0 Weak Password Encryption Vulnerability + + WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges. + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-1079 + 1999-05-06T00:00:00.000-04:00 + 2008-09-05T16:18:40.353-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 439 + + + AIXAPAR + IX80470 + + + BUGTRAQ + 19990825 AIX security summary + + + BUGTRAQ + 19990506 AIX Security Fixes Update + + Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. + + + + + + + + + cpe:/o:sun:sunos:5.7 + + CVE-1999-1080 + 1995-05-10T00:00:00.000-04:00 + 2008-09-05T16:18:40.527-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990510 SunOS 5.7 rmmount, no nosuid. + + + BUGTRAQ + 19991011 + + + XF + solaris-rmmount-gain-root(8350) + + + BID + 250 + + rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf. + + + + + + + + + cpe:/a:novell:web_server:2.0::examples_toolkit + + CVE-1999-1081 + 2002-01-15T00:00:00.000-05:00 + 2008-09-05T16:18:40.667-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-nov-files(2054) + + + MISC + http://www.w3.org/Security/Faq/wwwsf8.html#Q87 + + + MISC + http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35 + + Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files. + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:1.40 + + CVE-1999-1082 + 1999-10-08T00:00:00.000-04:00 + 2008-09-05T16:18:40.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 699 + + + BUGTRAQ + 19991008 Jana webserver exploit + + Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack. + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:1.0 + + CVE-1999-1083 + 1999-10-08T00:00:00.000-04:00 + 2008-09-05T16:18:40.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 699 + + + BUGTRAQ + 20000502 Security Bug in Jana HTTP Server + + Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0::server + + CVE-1999-1084 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:41.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1044 + + + MS + MS00-008 + + + CIAC + K-029 + + + MSKB + Q103861 + + + NTBUGTRAQ + 19980622 Yet another "get yourself admin rights exploit": + + The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash. + + + + + + + + + + cpe:/a:ssh:secure_shell:1.2.25 + cpe:/a:ssh:secure_shell:1.2.23 + + CVE-1999-1085 + 1998-06-12T00:00:00.000-04:00 + 2008-09-05T16:18:41.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#13877 + + + BUGTRAQ + 19980703 UPDATE: SSH insertion attack + + + BUGTRAQ + 19980612 CORE-SDI-04: SSH insertion attack + + + XF + ssh-insert(1126) + + SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack." + + + + + + + + + + + cpe:/o:novell:netware:4.11:sp5b + cpe:/o:novell:netware:5.0 + cpe:/o:novell:netware:4.1 + + CVE-1999-1086 + 1999-07-15T00:00:00.000-04:00 + 2008-09-05T16:18:41.370-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 528 + + + BUGTRAQ + 19990715 NMRC Advisory: Netware 5 Client Hijacking + + Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls. + + + + + + + + + + + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1:sp1 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1087 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:41.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-dotless(2209) + + + MS + MS98-016 + + + MSKB + Q168617 + + + CONFIRM + http://www.microsoft.com/Windows/Ie/security/dotless.asp + + + OSVDB + 7828 + + Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.02 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1088 + 1997-01-09T00:00:00.000-05:00 + 2008-09-05T16:18:41.667-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-chsh(2012) + + + CIAC + H-21 + + Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges. + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1089 + 1996-12-13T00:00:00.000-05:00 + 2008-09-05T16:18:41.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + H-21 + + + CIAC + H-16 + + + BUGTRAQ + 19961209 the HP Bug of the Week! + + Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument. + + + + + + + + + cpe:/a:ncsa:telnet + + CVE-1999-1090 + 1991-09-10T00:00:00.000-04:00 + 2008-09-05T16:18:41.963-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1991-15 + + + XF + ftp-ncsa(1844) + + The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files. + + + + + + + + + + cpe:/a:rtin:rtin + cpe:/a:tin:tin:1.2 + + CVE-1999-1091 + 2002-01-15T00:00:00.000-05:00 + 2008-09-05T16:18:42.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tin-tmpfile(431) + + + BUGTRAQ + 19970329 symlink bug in tin/rtin + + + BUGTRAQ + 19960903 Re: BoS: [BUG] Vulnerability in TIN + + + BUGTRAQ + 19960903 [BUG] Vulnerability in TIN + + UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack. + + + + + + + + + cpe:/a:iain_lea:tin:1.40 + + CVE-1999-1092 + 1999-11-17T00:00:00.000-05:00 + 2008-09-05T16:18:42.227-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991117 default permissions for tin + + tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file. + + + + + + + + + + + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1:sp1 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1093 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:42.383-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-011 + + + XF + java-script-patch(1276) + + + MSKB + Q191200 + + Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. + + + + + + + + + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1094 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:42.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iemk-bug(917) + + + MSKB + Q176697 + + + BUGTRAQ + 19980114 L0pht Advisory MSIE4.0(1) + + Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue." + + + + + + + + + + cpe:/o:slackware:slackware_linux:3.3 + cpe:/o:redhat:linux:4.1 + + CVE-1999-1095 + 1997-10-06T00:00:00.000-04:00 + 2008-09-05T16:18:42.667-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980303 updatedb stuff + + + BUGTRAQ + 19971006 KSR[T] Advisory #3: updatedb / crontabs + + + BUGTRAQ + 19980302 overwrite any file with updatedb + + sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort. + + + + + + + + + cpe:/o:kde:kde:1.0 + + CVE-1999-1096 + 1998-05-16T00:00:00.000-04:00 + 2008-09-05T16:18:42.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kde-klock-home-bo(1644) + + + BUGTRAQ + 19980517 simple kde exploit fix + + + BUGTRAQ + 19980516 kde exploit + + Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable. + + + + + + + + + cpe:/a:microsoft:netmeeting:2.1 + + CVE-1999-1097 + 1999-05-04T00:00:00.000-04:00 + 2008-09-05T16:18:42.947-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netmeeting-clipboard(2187) + + + BUGTRAQ + 19990504 Microsoft Netmeeting Hole + + Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. + + + + + + + + + cpe:/o:bsd:bsd + + CVE-1999-1098 + 1995-03-03T00:00:00.000-05:00 + 2008-09-05T16:18:43.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1995-03 + + + CIAC + F-12 + + + OSVDB + 4881 + + + XF + bsd-telnet(516) + + Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing. + + + + + + + + + cpe:/a:kth:kth_kerberos:4 + + CVE-1999-1099 + 1996-11-22T00:00:00.000-05:00 + 2008-09-05T16:18:43.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kerberos-user-grab(65) + + + BUGTRAQ + 19961122 L0pht Kerberos Advisory + + Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user. + + + + + + + + + cpe:/a:cisco:pix_private_link:4.1%286%29 + + CVE-1999-1100 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:43.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-pix-parse-error(1579) + + + CISCO + 19980616 PIX Private Link Key Processing and Cryptography Issues + + + CIAC + I-056 + + Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack. + + + + + + + + + cpe:/a:kab_software:lydia:3.2 + + CVE-1999-1101 + 1999-02-19T00:00:00.000-05:00 + 2008-09-09T08:36:51.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw) + + Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.2 + cpe:/o:apple:a_ux:2.0.1 + cpe:/o:bsd:bsd:4.3 + cpe:/o:sun:sunos:4.1.1 + + CVE-1999-1102 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:43.633-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + E-25a + + + MISC + http://www.phreak.org/archives/security/8lgm/8lgm.lpr + + + BUGTRAQ + 19940307 8lgm Advisory Releases + + lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times. + + + + + + + + + cpe:/o:digital:osf_1:3.2c + + CVE-1999-1103 + 1996-04-03T00:00:00.000-05:00 + 2008-09-05T16:18:43.777-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + VB-96.05 + + + CIAC + G-18 + + + MISC + http://www.tao.ca/fire/bos/0209.html + + + XF + osf-dxconsole-gain-privileges(7138) + + dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter. + + + + + + + + + cpe:/o:microsoft:windows_95 + + CVE-1999-1104 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:43.917-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19980121 How to recover private keys for various Microsoft products + + + BUGTRAQ + 19980120 How to recover private keys for various Microsoft products + + + BUGTRAQ + 19951205 Cracked: WINDOWS.PWL + + + XF + win95-nbsmbpwl(71) + + + MSKB + Q140557 + + Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords. + + + + + + + + + cpe:/o:microsoft:windows_95 + + CVE-1999-1105 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:44.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.zdnet.com/eweek/reviews/1016/tr42bug.html + + + MISC + http://www.net-security.sk/bugs/NT/netware1.html + + + XF + win95-netware-hidden-share(7231) + + Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive. + + + + + + + + + cpe:/o:kde:kde + + CVE-1999-1106 + 1998-04-29T00:00:00.000-04:00 + 2008-09-05T16:18:44.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kde-kppp-account-bo(1643) + + + BID + 92 + + + BUGTRAQ + 19980429 Security hole in kppp + + Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument. + + + + + + + + + cpe:/o:kde:kde:1.0 + + CVE-1999-1107 + 1998-11-18T00:00:00.000-05:00 + 2008-09-05T16:18:44.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kde-kppp-path-bo(1650) + + + BUGTRAQ + 19981118 Multiple KDE security vulnerabilities (root compromise) + + Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable. + + + CVE-1999-1108 + 1998-11-18T00:00:00.000-05:00 + 2008-09-09T08:36:53.930-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1107. Reason: This candidate is a duplicate of CVE-1999-1107. Notes: All CVE users should reference CVE-1999-1107 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/a:sendmail:sendmail:8.10.0 + + CVE-1999-1109 + 1999-12-22T00:00:00.000-05:00 + 2008-09-05T16:18:44.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000113 Re: procmail / Sendmail - five bugs + + + BUGTRAQ + 19991222 Re: procmail / Sendmail - five bugs + + + BID + 904 + + + XF + sendmail-etrn-dos(7760) + + Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-1110 + 1999-11-14T00:00:00.000-05:00 + 2008-09-05T16:18:44.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 793 + + + BUGTRAQ + 19991114 IE 5.0 and Windows Media Player ActiveX object allow checking the existence of local files and directories + + Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. + + + + + + + + + cpe:/a:immunix:stackguard:1.21 + + CVE-1999-1111 + 1999-11-09T00:00:00.000-05:00 + 2008-09-05T16:18:44.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + immunix-stackguard-bo(3524) + + + BUGTRAQ + 19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released + + + BID + 786 + + Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself. + + + + + + + + + cpe:/a:irfanview:irfanview:3.0.7 + + CVE-1999-1112 + 1999-11-09T00:00:00.000-05:00 + 2008-09-05T16:18:44.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + irfan-view32-bo(3549) + + + BID + 781 + + + BUGTRAQ + 19991109 Irfan view 3.07 buffer overflow + + + MISC + http://stud4.tuwien.ac.at/~e9227474/main2.html + + Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header. + + + + + + + + + + + cpe:/a:eudora:internet_mail_server:1.2 + cpe:/a:eudora:internet_mail_server:2.01 + cpe:/a:eudora:internet_mail_server:2.0 + + CVE-1999-1113 + 1998-04-14T00:00:00.000-04:00 + 2008-09-05T16:18:45.120-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 75 + + + BUGTRAQ + 19980414 MacOS based buffer overflows... + + Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106. + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-1114 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:18:45.260-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ksh-suid_exec(2100) + + + BID + 467 + + + CIAC + H-15A + + + SGI + 19980405-01-I + + + AUSCERT + AA-96.17 + + Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges. + + + + + + + + + + cpe:/o:hp:apollo_domain_os:sr10.3:beta + cpe:/o:hp:apollo_domain_os:sr10.2 + + CVE-1999-1115 + 1990-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:45.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1990-04 + + + BID + 7 + + + XF + apollo-suidexec-unauthorized-access(6721) + + + CIAC + A-30 + + Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh). + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + + CVE-1999-1116 + 1997-05-03T00:00:00.000-04:00 + 2008-09-05T16:18:45.573-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-runpriv(2108) + + + BID + 462 + + + SGI + 19970503-01-PX + + + OSVDB + 1009 + + Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges. + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + + CVE-1999-1117 + 1999-12-31T00:00:00.000-05:00 + 2008-09-09T08:36:54.820-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ibm-lquerypv(1752) + + + CIAC + H-13 + + + BUGTRAQ + 19961125 AIX lquerypv + + + BID + 455 + + + BUGTRAQ + 19961124 + + + BUGTRAQ + 19961125 lquerypv fix + + lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter. + + + + + + + + + cpe:/o:sun:solaris:2.6 + + CVE-1999-1118 + 1998-03-11T00:00:00.000-05:00 + 2008-09-05T16:18:45.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-ndd(817) + + + BID + 433 + + + SUN + 00165 + + ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters. + + + + + + + + + cpe:/o:ibm:aix:::32-bit + + CVE-1999-1119 + 1992-04-27T00:00:00.000-04:00 + 2008-09-05T16:18:45.993-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-09 + + + XF + aix-anon-ftp(3154) + + + BID + 41 + + FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-1120 + 1997-01-04T00:00:00.000-05:00 + 2008-09-05T16:18:46.133-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sgi-netprint(2107) + + + BID + 395 + + + BUGTRAQ + 19970104 Irix: netprint story + + + SGI + 19961203-02-PX + + + OSVDB + 993 + + + SGI + 19961203-01-PX + + netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges. + + + + + + + + + cpe:/o:ibm:aix:3.2 + + CVE-1999-1121 + 1992-03-19T00:00:00.000-05:00 + 2008-09-05T16:18:46.277-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-06 + + + XF + ibm-uucp(554) + + + BID + 38 + + + OSVDB + 891 + + The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges. + + + + + + + + + + + cpe:/o:sun:sunos:4.0.1 + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.0 + + CVE-1999-1122 + 1989-07-26T00:00:00.000-04:00 + 2008-09-05T16:18:46.417-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1989-02 + + + XF + sun-restore-gain-privileges(6695) + + + BID + 3 + + + CIAC + CIAC-08 + + Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges. + + + + + + + + + + + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1123 + 1991-05-20T00:00:00.000-04:00 + 2008-09-05T16:18:46.573-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-07 + + + XF + sun-sourcetapes(582) + + + SUN + 00107 + + + BID + 22 + + + BID + 21 + + The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall. + + + + + + + + + cpe:/a:allaire:coldfusion + + CVE-1999-1124 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:46.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://packetstorm.securify.com/mag/phrack/phrack54/P54-08 + + HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host. + + + + + + + + + + cpe:/a:oracle:http_server:1.0 + cpe:/a:oracle:http_server:2.1 + + CVE-1999-1125 + 1997-09-19T00:00:00.000-04:00 + 2008-09-10T15:01:09.477-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19970919 Instresting practises of Oracle [Oracle Webserver] + + Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. + + + + + + + + + cpe:/a:cisco:resource_manager:1.1 + + CVE-1999-1126 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:46.977-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-crm-file-vuln(1575) + + + CISCO + 19980813 CRM Temporary File Vulnerability + + + CIAC + I-086 + + Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_". + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1127 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:47.120-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS98-017 + + + MSKB + Q195733 + + + XF + nt-spoolss(523) + + Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability. + + + + + + + + + cpe:/a:microsoft:ie:3.0.1 + + CVE-1999-1128 + 1997-03-01T00:00:00.000-05:00 + 2008-09-10T15:01:09.773-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html + + + MISC + http://members.tripod.com/~unibyte/iebug3.htm + + Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.2%288%29sa5 + cpe:/h:cisco:catalyst_2900_vlan + + CVE-1999-1129 + 1999-09-01T00:00:00.000-04:00 + 2008-09-05T16:18:47.400-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-catalyst-vlan-frames(3294) + + + BID + 615 + + + BUGTRAQ + 19990901 VLAN Security + + + MISC + http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm + + Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag. + + + + + + + + + cpe:/a:netscape:enterprise_server:3.5.1 + + CVE-1999-1130 + 1999-07-30T00:00:00.000-04:00 + 2008-09-05T16:18:47.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990730 Netscape Enterprise Server yeilds source of JHTML + + + BID + 559 + + + NTBUGTRAQ + 19990730 Netscape Enterprise Server yeilds source of JHTML + + Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file. + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-1131 + 1997-10-24T00:00:00.000-04:00 + 2008-09-05T16:18:47.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + VB-97.12 + + + XF + sgi-osf-dce-dos(1123) + + + CIAC + I-060 + + + SGI + 19980601-01-PX + + Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1132 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:47.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q179157 + + + BUGTRAQ + 19981005 NMRC Advisory - Lame NT Token Ring DoS + + + XF + token-ring-dos(1399) + + + NTBUGTRAQ + 19981002 NMRC Advisory - Lame NT Token Ring DoS + + Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1133 + 1997-09-01T00:00:00.000-04:00 + 2008-09-05T16:18:48.027-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-vue-dt(499) + + + HP + HPSBUX9709-069 + + HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users. + + + + + + + + + cpe:/o:hp:hp-ux:9 + + CVE-1999-1134 + 1994-05-18T00:00:00.000-04:00 + 2008-09-10T15:01:10.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + E-23 + + + XF + hp-vue(2284) + + + HP + HPSBUX9404-008 + + Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066. + + + + + + + + + cpe:/o:hp:hp-ux:9 + + CVE-1999-1135 + 1994-04-20T00:00:00.000-04:00 + 2008-09-10T15:01:10.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-vue(2284) + + + HP + HPSBUX9504-027 + + Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438. + + + + + + + + + + + + + + + cpe:/o:hp:mpe_ix:5.5 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:mpe_ix:5.0 + + CVE-1999-1136 + 1998-07-30T00:00:00.000-04:00 + 2013-09-10T13:08:29.893-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2013-08-15T05:53:57.000-04:00 + + + + + XF + mpeix-predictive(1413) + + + CIAC + I-081 + + + BUGTRAQ + 19980729 HP-UX Predictive & Netscape SSL Vulnerabilities + + + HP + HPSBMP9807-005 + + + HP + HPSBUX9807-081 + + + + + Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems. + + + + + + + + + + + + + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:sunos + cpe:/o:sun:sunos:5.0 + cpe:/o:sun:sunos:4.1 + cpe:/o:sun:solaris + + CVE-1999-1137 + 1993-10-01T00:00:00.000-04:00 + 2008-09-05T16:18:48.587-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-audio(549) + + + CIAC + E-01 + + + SUN + 00122 + + + OSVDB + 6436 + + The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone. + + + + + + + + + + + + + + + + + cpe:/o:sco:open_desktop_lite:3.0 + cpe:/o:sco:open_desktop:1.0 + cpe:/o:sco:unix:system_v386_3.2_operating_system_4.0 + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:system_v386_3.2_operating_system + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:system_v386_3.2_operating_system_4.x + cpe:/o:sco:unix:system_v386_3.2_operating_system_2.0 + cpe:/o:sco:openserver:3.0 + + CVE-1999-1138 + 1993-09-17T00:00:00.000-04:00 + 2008-09-05T16:18:48.727-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1993-13 + + + XF + sco-homedir(546) + + SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-1999-1139 + 1997-09-01T00:00:00.000-04:00 + 2008-09-05T16:18:48.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9801-074 + + + BUGTRAQ + 19980121 HP-UX CUE, CUD and LAND vulnerabilities + + + BUGTRAQ + 19970901 HP UX Bug :) + + + XF + hp-cue(2007) + + + CIAC + I-027B + + Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file. + + + + + + + + + cpe:/a:alec_muffet:cracklib:2.5 + + CVE-1999-1140 + 1997-12-14T00:00:00.000-05:00 + 2008-09-05T16:18:49.027-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + VB-97.16 + + + XF + cracklib-bo(1539) + + + BUGTRAQ + 19971214 buffer overflows in cracklib?! + + Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field. + + + + + + + + + cpe:/h:ascom:timeplex_routers + + CVE-1999-1141 + 1997-05-15T00:00:00.000-04:00 + 2008-09-05T16:18:49.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ascom-timeplex-debug(1824) + + + BUGTRAQ + 19970515 MicroSolved finds hole in Ascom Timeplex Router Security + + Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters. + + + + + + + + + cpe:/o:sun:sunos:4.1.2 + + CVE-1999-1142 + 1992-05-27T00:00:00.000-04:00 + 2008-09-05T16:18:49.323-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-11 + + + XF + sun-env(3152) + + + SUN + 00116 + + SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-1143 + 1997-05-28T00:00:00.000-04:00 + 2008-09-05T16:18:49.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-rld(2109) + + + CIAC + H-065 + + + SGI + 19970504-01-PX + + Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + + CVE-1999-1144 + 1997-01-30T00:00:00.000-05:00 + 2008-09-05T16:18:49.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-mpower(2056) + + + HP + HPSBUX9701-051 + + Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1145 + 1997-01-07T00:00:00.000-05:00 + 2008-09-05T16:18:49.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-glanceplus(2059) + + + CIAC + H-21 + + + HP + HPSBUX9701-044 + + Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:8 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1146 + 1994-05-04T00:00:00.000-04:00 + 2008-09-05T16:18:49.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-glanceplus-gpm(2060) + + + HP + HPSBUX9405-011 + + Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges. + + + + + + + + + cpe:/a:platinum:policy_compliance_manager:7.0 + + CVE-1999-1147 + 1998-12-04T00:00:00.000-05:00 + 2008-09-05T16:18:50.027-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pcm-dos-execute(1430) + + + BUGTRAQ + 19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0 + + + OSVDB + 3164 + + Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1148 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:50.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-passive-ftp(1215) + + + MS + MS98-006 + + + MSKB + Q189262 + + FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. + + + + + + + + + cpe:/a:computer_software_manufaktur:csm_proxy:4.1 + + CVE-1999-1149 + 1998-07-16T00:00:00.000-04:00 + 2008-09-05T16:18:50.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + csm-proxy-dos(1422) + + + BUGTRAQ + 19980716 S.A.F.E.R. Security Bulletin 980708.DOS.1.1 + + Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port. + + + + + + + + + cpe:/h:livingston_portmaster:portmaster:initial + + CVE-1999-1150 + 1998-06-30T00:00:00.000-04:00 + 2008-09-05T16:18:50.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + portmaster-fixed-isn(1882) + + + BUGTRAQ + 19980630 Livingston Portmaster - ISN generation is loosy! + + Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions. + + + + + + + + + cpe:/h:compaq_microcom:microcom_6000_access_integrator:initial + + CVE-1999-1151 + 1998-06-03T00:00:00.000-04:00 + 2008-09-05T16:18:50.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + microcom-dos(2089) + + + BUGTRAQ + 19980603 Compaq/Microcom 6000 DoS + more + + Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password. + + + + + + + + + cpe:/h:compaq_microcom:microcom_6000_access_integrator + + CVE-1999-1152 + 1998-06-03T00:00:00.000-04:00 + 2008-09-05T16:18:50.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980603 Compaq/Microcom 6000 DoS + more + + Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack. + + + + + + + + + cpe:/a:hamcards_postcard_cgi:hamcards_postcard_cgi:1.0 + + CVE-1999-1153 + 1998-11-09T00:00:00.000-05:00 + 2008-09-05T16:18:50.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cgi-perl-mail-programs(1400) + + HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. + + + + + + + + + cpe:/a:lakeweb:filemail_cgi_script + + CVE-1999-1154 + 1998-11-09T00:00:00.000-05:00 + 2008-09-05T16:18:50.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cgi-perl-mail-programs(1400) + + + BUGTRAQ + 19981109 Several new CGI vulnerabilities + + + MISC + http://lakeweb.com/scripts/ + + LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. + + + + + + + + + cpe:/a:lakeweb:mail_list_cgi_script + + CVE-1999-1155 + 1998-11-09T00:00:00.000-05:00 + 2008-09-05T16:18:51.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cgi-perl-mail-programs(1400) + + + BUGTRAQ + 19981109 Several new CGI vulnerabilities + + + MISC + http://lakeweb.com/scripts/ + + LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. + + + + + + + + + cpe:/a:bisonware:bisonware_ftp_server:4.1 + + CVE-1999-1156 + 1999-05-17T00:00:00.000-04:00 + 2008-09-10T15:01:13.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bisonware-port-crash(2254) + + BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1157 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:51.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tcpipsys-icmp-dos(3894) + + + MSKB + Q192774 + + Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1158 + 1997-05-13T00:00:00.000-04:00 + 2008-09-05T16:18:51.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00139 + + + AUSCERT + AA-97.09 + + Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd. + + + + + + + + + cpe:/a:ssh:ssh2:2.0.11 + + CVE-1999-1159 + 1998-12-29T00:00:00.000-05:00 + 2008-09-05T16:18:51.697-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ssh-privileged-port-forward(1471) + + + BUGTRAQ + 19981229 ssh2 security problem (and patch) (fwd) + + SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1160 + 1997-02-02T00:00:00.000-05:00 + 2008-09-05T16:18:51.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9702-055 + + + CIAC + H-33 + + + XF + hp-ftpd-kftpd(7437) + + Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1161 + 1996-11-03T00:00:00.000-05:00 + 2008-09-05T16:18:51.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX9704-057 + + + CIAC + H-32 + + + BUGTRAQ + 19961104 ppl bugs + + + BUGTRAQ + 19961103 Re: Untitled + + + XF + hp-ppl(7438) + + Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump. + + + + + + + + + + + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:4.0 + cpe:/o:sco:open_desktop:1.1 + + CVE-1999-1162 + 1993-05-24T00:00:00.000-04:00 + 2008-09-05T16:18:52.117-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1993-08 + + + XF + sco-passwd-deny(542) + + Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system. + + + + + + + + + cpe:/h:hp:9000:800 + + CVE-1999-1163 + 1999-11-24T00:00:00.000-05:00 + 2008-09-10T15:01:14.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBUX9911-105 + + + XF + hp-ssp(7439) + + Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation. + + + + + + + + + + + + cpe:/a:microsoft:outlook_express + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook:2000 + + CVE-1999-1164 + 1999-06-25T00:00:00.000-04:00 + 2008-09-05T16:18:52.400-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990625 Outlook denial of service + + Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang. + + + + + + + + + cpe:/a:gnu:fingerd:1.37 + + CVE-1999-1165 + 1999-07-21T00:00:00.000-04:00 + 2008-09-05T16:18:52.540-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 535 + + + BUGTRAQ + 19950317 GNU finger 1.37 executes ~/.fingerrc with gid root + + + BUGTRAQ + 19990721 old gnu finger bugs + + GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files. + + + + + + + + + cpe:/o:linux:linux_kernel:2.0.37 + + CVE-1999-1166 + 1999-07-11T00:00:00.000-04:00 + 2008-09-05T16:18:52.680-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 523 + + + BUGTRAQ + 19990711 Linux 2.0.37 segment limit bug + + Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory. + + + + + + + + + cpe:/a:third_voice:third_voice_web + + CVE-1999-1167 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:52.820-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.wired.com/news/technology/0,1282,20677,00.html + + + MISC + http://www.wired.com/news/technology/0,1282,20636,00.html + + + XF + thirdvoice-cross-site-scripting(7252) + + Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation. + + + + + + + + + cpe:/a:iss:internet_security_scanner:5.3::linux + + CVE-1999-1168 + 1999-02-20T00:00:00.000-05:00 + 2008-09-05T16:18:52.963-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990220 ISS install.iss security hole + + install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:flavio_veloso:nobo:1.2 + + CVE-1999-1169 + 1999-02-04T00:00:00.000-05:00 + 2008-09-10T15:01:14.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990204 NOBO denial of service + + nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets. + + + + + + + + + + + cpe:/a:ipswitch:ws_ftp_server:1.0.1.e + cpe:/a:ipswitch:ws_ftp_server:1.0.2.e + cpe:/a:ipswitch:imail:5.0 + + CVE-1999-1170 + 1999-01-02T00:00:00.000-05:00 + 2008-09-05T16:18:53.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 218 + + + NTBUGTRAQ + 19990204 WS FTP Server Remote DoS Attack + + IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. + + + + + + + + + + + cpe:/a:ipswitch:ws_ftp_server:1.0.1.e + cpe:/a:ipswitch:ws_ftp_server:1.0.2.e + cpe:/a:ipswitch:imail:5.0 + + CVE-1999-1171 + 1999-02-02T00:00:00.000-05:00 + 2008-09-05T16:18:53.383-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 218 + + + NTBUGTRAQ + 19990204 WS FTP Server Remote DoS Attack + + IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. + + + + + + + + + cpe:/a:maximizer:maximizer_enterprise:4 + + CVE-1999-1172 + 1999-01-14T00:00:00.000-05:00 + 2008-09-05T16:18:53.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990114 security hole in Maximizer + + By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared. + + + + + + + + + cpe:/a:corel:wordperfect:8::linux + + CVE-1999-1173 + 1998-12-18T00:00:00.000-05:00 + 2008-09-05T16:18:53.667-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19981218 wordperfect 8 for linux security + + Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack. + + + + + + + + + cpe:/h:iomega:zip_100_mb_drive + + CVE-1999-1174 + 2001-12-21T00:00:00.000-05:00 + 2008-09-10T15:01:15.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.counterpane.com/crypto-gram-9812.html#doghouse + + ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk. + + + + + + + + + cpe:/o:cisco:ios:11.2 + + CVE-1999-1175 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:18:53.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 19980513 Cisco Web Cache Control Protocol Router Vulnerability + + + CIAC + I-054 + + + XF + cisco-wccp-vuln(1577) + + Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048. + + + + + + + + + + cpe:/a:aaron_ledbetter:cidentd + cpe:/a:jidentd:jidentd + + CVE-1999-1176 + 1998-01-10T00:00:00.000-05:00 + 2008-09-05T16:18:54.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980911 Re: security problems with jidentd + + + BUGTRAQ + 19980110 Cidentd + + Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script. + + + + + + + + + cpe:/a:lincoln_d._stein:nph-publish:1.2 + + CVE-1999-1177 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:17.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish + + + MISC + http://www.w3.org/Security/Faq/wwwsf4.html + + + XF + http-cgi-nphpublish(2055) + + Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation. + + + + + + + + + cpe:/a:sambar:sambar_server:4.1:beta + + CVE-1999-1178 + 1998-06-10T00:00:00.000-04:00 + 2008-09-05T16:18:54.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sambar-dump-env(3223) + + + BUGTRAQ + 19980610 Sambar Server Beta BUG.. + + Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script. + + + + + + + + + cpe:/a:sysadmin_magazine:man.sh + + CVE-1999-1179 + 1998-05-15T00:00:00.000-04:00 + 2008-09-05T16:18:54.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19980515 May SysAdmin man.sh security hole + + Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands. + + + + + + + + + + + + cpe:/a:oreilly:website_pro:2.0 + cpe:/a:oreilly:website:1.1e + cpe:/a:oreilly:website_pro:2.4 + cpe:/a:oreilly:website_pro:2.1 + + CVE-1999-1180 + 1999-02-16T00:00:00.000-05:00 + 2008-09-10T15:01:17.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat. + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.2 + + CVE-1999-1181 + 1998-09-29T00:00:00.000-04:00 + 2008-09-05T16:18:54.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + J-003 + + + SGI + 19980901-01-PX + + + XF + irix-register(7441) + + Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges. + + + + + + + + + + + + + + + + + + + + cpe:/o:lst:lst_power_linux:2.2 + cpe:/o:debian:debian_linux:4.0 + cpe:/o:caldera:openlinux_lite:1.1 + cpe:/a:delix:dld:5.2 + cpe:/o:suse:suse_linux:5.0 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + + CVE-1999-1182 + 1997-07-17T00:00:00.000-04:00 + 2008-09-05T16:18:54.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19970722 ld.so vulnerability + + + BUGTRAQ + 19970717 KSR[T] Advisory #2: ld.so + + + BUGTRAQ + 19980204 An old ld-linux.so hole + + Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error. + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + + CVE-1999-1183 + 1998-04-02T00:00:00.000-05:00 + 2013-08-21T00:05:33.603-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19980403-02-PX + + + SGI + 19980403-01-PX + + + OSVDB + 8556 + + + XF + sgi-mailcap(809) + + System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type. + + + + + + + + + + cpe:/a:elm_development_group:elm:2.4 + cpe:/a:elm_development_group:elm:2.3 + + CVE-1999-1184 + 1997-05-13T00:00:00.000-04:00 + 2008-09-05T16:18:55.260-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19970514 Re: ELM overflow + + + BUGTRAQ + 19970513 + + Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable. + + + + + + + + + + + + + + + + + + cpe:/o:sco:openserver_enterprise_system:5.0.4p + cpe:/a:sco:cmw:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:internet_faststart:all_versions + cpe:/o:sco:openserver:3.0 + + CVE-1999-1185 + 1998-10-06T00:00:00.000-04:00 + 2008-09-10T15:01:18.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980926 Root exploit for SCO OpenServer. + + Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file. + + + + + + + + + + + + + + + cpe:/o:redhat:linux:2.1 + cpe:/a:rxvt:rxvt + cpe:/o:slackware:slackware_linux:3.0 + + CVE-1999-1186 + 1996-01-02T00:00:00.000-05:00 + 2008-09-05T16:18:55.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19960102 rxvt security hole + + rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter. + + + + + + + + + + + + + + + cpe:/a:university_of_washington:pine:3.94 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:slackware:slackware_linux:3.0 + + CVE-1999-1187 + 1996-08-26T00:00:00.000-04:00 + 2008-09-05T16:18:55.697-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + pine-tmpfile(416) + + + BUGTRAQ + 19960826 [BUG] Vulnerability in PINE + + Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail. + + + + + + + + + cpe:/a:mysql:mysql:3.21 + + CVE-1999-1188 + 1998-12-27T00:00:00.000-05:00 + 2008-09-05T16:18:55.837-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + mysql-readable-log-files(1568) + + + BUGTRAQ + 19981227 mysql: mysqld creates world readable logs.. + + mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database. + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:navigator:4.7 + + CVE-1999-1189 + 1999-11-24T00:00:00.000-05:00 + 2008-09-05T16:18:55.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 822 + + + XF + netscape-long-argument-bo(7884) + + + BUGTRAQ + 19991127 Netscape Communicator 4.7 - Navigator Overflows + + + BUGTRAQ + 19991124 Netscape Communicator 4.7 - Navigator Overflows + + Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. + + + + + + + + + cpe:/a:admiral_systems:emailclub:1.0.0.5 + + CVE-1999-1190 + 1999-11-15T00:00:00.000-05:00 + 2008-09-05T16:18:56.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 801 + + + MISC + http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html + + Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1191 + 1997-05-19T00:00:00.000-04:00 + 2008-09-05T16:18:56.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + AUSCERT + AA-97.18 + + + BID + 207 + + + SUN + 00144 + + + BUGTRAQ + 19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps. + + + XF + solaris-chkey-bo(7442) + + Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1192 + 1997-06-24T00:00:00.000-04:00 + 2008-09-05T16:18:56.417-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 206 + + + SUN + 00143 + + + XF + solaris-eeprom-bo(7444) + + Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. + + + + + + + + + cpe:/a:next:next:2.1 + + CVE-1999-1193 + 1991-05-14T00:00:00.000-04:00 + 2008-09-05T16:18:56.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-06 + + + XF + next-me(581) + + + BID + 20 + + The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root. + + + + + + + + + + cpe:/o:digital:ultrix:4.1 + cpe:/o:digital:ultrix:4.0 + + CVE-1999-1194 + 1991-05-01T00:00:00.000-04:00 + 2008-09-05T16:18:56.713-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-05 + + + XF + dec-chroot(577) + + + BID + 17 + + chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges. + + + + + + + + + cpe:/a:network_associates:virusscan:4.0.2 + + CVE-1999-1195 + 1999-05-05T00:00:00.000-04:00 + 2008-09-05T16:18:56.837-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990505 NAI AntiVirus Update Problem + + + BID + 169 + + + NTBUGTRAQ + 19990505 NAI AntiVirus Update Problem + + NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly. + + + + + + + + + cpe:/a:hummingbird:exceed:5.0 + + CVE-1999-1196 + 1999-04-07T00:00:00.000-04:00 + 2008-09-05T16:18:56.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 158 + + + BUGTRAQ + 19990427 NT/Exceed D.O.S. + + Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000. + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + + CVE-1999-1197 + 1990-12-20T00:00:00.000-05:00 + 2008-09-05T16:18:57.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1990-12 + + + BID + 14 + + + XF + sunos-tioccons-console-redirection(7140) + + TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges. + + + + + + + + + cpe:/a:next:next:2.0 + + CVE-1999-1198 + 1990-10-03T00:00:00.000-04:00 + 2008-09-05T16:18:57.260-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1990-06 + + + CIAC + B-01 + + + BID + 11 + + + XF + nextstep-builddisk-root-access(7141) + + BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges. + + + + + + + + + cpe:/a:apache:http_server:1.3.1 + + CVE-1999-1199 + 1998-08-07T00:00:00.000-04:00 + 2008-09-05T16:18:57.400-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980807 YA Apache DoS attack + + + CONFIRM + http://www.redhat.com/support/errata/rh51-errata-general.html#apache + + + BUGTRAQ + 19980810 Apache DoS Attack + + + BUGTRAQ + 19980811 Apache 'sioux' DOS fix for TurboLinux + + + BUGTRAQ + 19980808 Debian Apache Security Update + + Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability. + + + + + + + + + cpe:/a:vintra_systems:smtp_mailserver + + CVE-1999-1200 + 1998-07-20T00:00:00.000-04:00 + 2008-09-05T16:18:57.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vintra-mail-dos(1617) + + + NTBUGTRAQ + 19980720 DOS in Vintra systems Mailserver software. + + Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed "EXPN *@" command. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-1999-1201 + 1999-02-06T00:00:00.000-05:00 + 2008-09-10T15:01:20.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + win-multiple-ip-dos(7542) + + + BID + 225 + + + NTBUGTRAQ + 19990206 New Windows 9x Bug: TCP Chorusing + + Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing. + + + + + + + + + + cpe:/a:startech:telnet_server + cpe:/a:startech:pop3_proxy_server + + CVE-1999-1202 + 1998-07-03T00:00:00.000-04:00 + 2008-09-05T16:18:57.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + startech-pop3-overflow(2088) + + + BUGTRAQ + 19980703 Windows95 Proxy DoS Vulnerabilites + + StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command. + + + + + + + + + cpe:/o:ascend:multilink_ppp_for_isdn:4.6 + + CVE-1999-1203 + 1999-02-12T00:00:00.000-05:00 + 2008-09-10T15:01:21.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + ascend-ppp-isdn-dos(7498) + + + BUGTRAQ + 19990212 PPP/ISDN multilink security issue - summary + + + BUGTRAQ + 19990210 Security problems in ISDN equipment authentication + + Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier. + + + + + + + + + cpe:/a:checkpoint:firewall-1 + + CVE-1999-1204 + 1998-05-11T00:00:00.000-04:00 + 2008-09-05T16:18:58.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980511 Firewall-1 Reserved Keywords Vulnerability + + + CONFIRM + http://www.checkpoint.com/techsupport/config/keywords.html + + + XF + fw1-user-defined-keywords-access(7293) + + + OSVDB + 4416 + + Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default "ANY" address and result in access to more systems than intended by the administrator. + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + + CVE-1999-1205 + 1996-06-07T00:00:00.000-04:00 + 2008-09-05T16:18:58.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX9607-035 + + + BUGTRAQ + 19960607 HP-UX B.10.01 vulnerability + + + XF + hp-nettune(414) + + nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information. + + + + + + + + + cpe:/a:systemsoft:systemwizard + + CVE-1999-1206 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:22.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm + + + BUGTRAQ + 19990729 New ActiveX security problems in Windows 98 PCs + + + BID + 555 + + SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control. + + + + + + + + + cpe:/a:network_general:netxray:all_versions + + CVE-1999-1207 + 1998-02-18T00:00:00.000-05:00 + 2008-09-05T16:18:58.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netxray-bo(907) + + + MISC + http://www.efri.hr/~crv/security/bugs/NT/netxtray.html + + Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request. + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:3.2.5 + + CVE-1999-1208 + 1997-07-21T00:00:00.000-04:00 + 2008-09-05T16:18:58.727-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ping-bo(803) + + + BUGTRAQ + 19970721 AIX ping, lchangelv, xlock fixes + + + BUGTRAQ + 19970721 AIX ping (Exploit) + + Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument. + + + + + + + + + + + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:openserver:3.0 + + CVE-1999-1209 + 1997-11-20T00:00:00.000-05:00 + 2008-09-05T16:18:58.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + VB-97.14 + + + XF + sco-scoterm(690) + + + BUGTRAQ + 19971204 scoterm exploit + + Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges. + + + + + + + + + cpe:/o:digital:unix:4.0b + + CVE-1999-1210 + 1997-11-12T00:00:00.000-05:00 + 2008-09-05T16:18:59.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + dec-xterm(613) + + + BUGTRAQ + 19971112 Digital Unix Security Problem + + xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access. + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + + CVE-1999-1211 + 1991-03-27T00:00:00.000-05:00 + 2008-09-05T16:18:59.167-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-02 + + + XF + sun-intelnetd(574) + + Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges. + + + + + + + + + + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.0.3c + + CVE-1999-1212 + 1991-03-27T00:00:00.000-05:00 + 2008-09-05T16:18:59.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-02 + + + XF + sun-intelnetd(574) + + Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges. + + + + + + + + + cpe:/o:hp:hp-ux:10.30 + + CVE-1999-1213 + 1997-10-01T00:00:00.000-04:00 + 2008-09-05T16:18:59.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-telnetdos(571) + + + HP + HPSBUX9710-070 + + Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service. + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:sgi:irix + cpe:/o:bsd:bsd:4.4 + cpe:/o:bsd:bsd + + CVE-1999-1214 + 1997-09-15T00:00:00.000-04:00 + 2011-03-10T00:00:00.000-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + openbsd-iosig(556) + + + OSVDB + 11062 + + + OPENBSD + 19970915 Vulnerability in I/O Signal Handling + + The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID. + + + + + + + + + + cpe:/o:novell:netware:4.0 + cpe:/o:novell:netware:4.01 + + CVE-1999-1215 + 1993-09-16T00:00:00.000-04:00 + 2008-09-05T16:18:59.727-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1993-12 + + + XF + novell-login(545) + + + CIAC + D-21 + + LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges. + + + + + + + + + + + + + cpe:/h:cisco:router:8.2 + cpe:/h:cisco:router:8.3 + cpe:/h:cisco:router:9.17 + cpe:/h:cisco:router:9.1 + cpe:/h:cisco:router:9.0 + + CVE-1999-1216 + 1993-04-22T00:00:00.000-04:00 + 2008-09-05T16:18:59.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-1993-07 + + + XF + cisco-sourceroute(541) + + + CIAC + D-15 + + Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-1217 + 1997-07-25T00:00:00.000-04:00 + 2008-09-05T16:19:00.023-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + nt-path(526) + + + NTBUGTRAQ + 19970725 Re: NT security - why bother? + + + NTBUGTRAQ + 19970723 NT security - why bother? + + The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories. + + + + + + + + + cpe:/o:commodore:amiga_unix:2.1p2a + + CVE-1999-1218 + 1993-02-18T00:00:00.000-05:00 + 2008-09-05T16:19:00.167-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1993-04 + + + XF + amiga-finger(522) + + Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files. + + + + + + + + + + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + + CVE-1999-1219 + 1994-08-11T00:00:00.000-04:00 + 2008-09-05T16:19:00.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1994-13 + + + XF + sgi-prn-mgr(511) + + + BID + 468 + + + CIAC + E-33 + + Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command. + + + + + + + + + cpe:/a:great_circle_associates:majordomo:1.94.3 + + CVE-1999-1220 + 1997-08-24T00:00:00.000-04:00 + 2008-09-05T16:19:00.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + majordomo-advertise(502) + + + BUGTRAQ + 19970824 Vulnerability in Majordomo + + Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header. + + + + + + + + + cpe:/o:digital:unix:3 + + CVE-1999-1221 + 1996-11-17T00:00:00.000-05:00 + 2008-09-05T16:19:00.587-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dgux-chpwd(399) + + + BUGTRAQ + 19961117 Digital Unix v3.x (v4.x?) security vulnerability + + dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1222 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:00.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dns-netbtsys-dos(3893) + + + MSKB + Q188571 + + Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup. + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + + CVE-1999-1223 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:00.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + url-asp-av(3892) + + + MSKB + Q187503 + + IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. + + + + + + + + + + cpe:/a:university_of_washington:imapd + cpe:/a:university_of_washington:imapd:4.1 + + CVE-1999-1224 + 1997-10-08T00:00:00.000-04:00 + 2008-09-05T16:19:01.007-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + imapd-core(349) + + + BUGTRAQ + 19971008 L0pht Advisory: IMAP4rev1 imapd server + + IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information. + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:openbsd:openbsd + cpe:/o:digital:ultrix + cpe:/o:sun:solaris + + CVE-1999-1225 + 1997-08-24T00:00:00.000-04:00 + 2008-09-10T15:01:25.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mountd-file-exists(347) + + + BUGTRAQ + 19970824 Serious security flaw in rpc.mountd on several operating systems. + + rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not. + + + + + + + + + cpe:/a:netscape:communicator:4.7 + + CVE-1999-1226 + 1999-10-28T00:00:00.000-04:00 + 2008-09-10T15:01:25.977-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + netscape-huge-key-dos(3436) + + Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key. + + + + + + + + + cpe:/a:ethereal_group:ethereal + + CVE-1999-1227 + 1999-07-30T00:00:00.000-04:00 + 2008-09-05T16:19:01.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ethereal-dev-capturec-root(3334) + + + MISC + http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html + + + MISC + http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html + + Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file. + + + + + + + + + + + + + + + + cpe:/h:us_robotics:us_robotics:33.6 + cpe:/a:logicode:quicktel:28.8 + cpe:/h:diamond:supra:v.90 + cpe:/h:diamond:supra:33.6 + + CVE-1999-1228 + 1998-09-27T00:00:00.000-04:00 + 2008-09-05T16:19:01.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + global-village-modem-dos(3320) + + + BUGTRAQ + 19980927 1+2=3, +++ATH0=Old school DoS + + + MISC + http://www.macintouch.com/modemsecurity.html + + Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others. + + + + + + + + + cpe:/a:id_software:quake_2_server:3.13 + + CVE-1999-1229 + 1998-02-25T00:00:00.000-05:00 + 2008-09-05T16:19:01.757-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-quake2(733) + + + BUGTRAQ + 19980225 Quake 2 Linux 3.13 (and lower) allow users to read arbitrary files + + Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file. + + + + + + + + + cpe:/a:id_software:quake_2 + + CVE-1999-1230 + 1997-12-24T00:00:00.000-05:00 + 2008-09-05T16:19:01.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + quake2-dos(698) + + + BUGTRAQ + 19971224 Quake II Remote Denial of Service + + Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself. + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh2:2.0 + cpe:/a:ssh:ssh2:2.0.9 + cpe:/a:ssh:ssh2:2.0.8 + cpe:/a:ssh:ssh2:2.0.1 + cpe:/a:ssh:ssh2:2.0.2 + cpe:/a:ssh:ssh2:2.0.3 + cpe:/a:ssh:ssh2:2.0.4 + cpe:/a:ssh:ssh2:2.0.5 + cpe:/a:ssh:ssh2:2.0.6 + cpe:/a:ssh:ssh2:2.0.7 + cpe:/a:ssh:ssh2:2.0.12 + cpe:/a:ssh:ssh2:2.0.11 + cpe:/a:ssh:ssh2:2.0.10 + + CVE-1999-1231 + 1999-06-09T00:00:00.000-04:00 + 2008-09-05T16:19:02.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990609 ssh advirsory + + + XF + ssh-leak(2276) + + ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-1999-1232 + 1997-05-16T00:00:00.000-04:00 + 2008-09-05T16:19:02.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-day5datacopier(3316) + + + OSVDB + 8559 + + + BUGTRAQ + 19970516 Irix and WWW + + Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1233 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:02.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-unresolved-domain-access(3306) + + + BID + 657 + + + MS + MS99-039 + + + MSKB + 241562 + + IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1234 + 1999-10-26T00:00:00.000-04:00 + 2008-09-05T16:19:02.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + msrpc-samr-open-dos(3293) + + + BUGTRAQ + 19991026 Re: LSA vulnerability on NT40 SP5 + + LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-1235 + 1999-08-25T00:00:00.000-04:00 + 2008-09-05T16:19:02.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + nt-ie5-user-ftp-password(3289) + + Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link. + + + + + + + + + + cpe:/a:true_north:internet_anywhere_mail_server:2.3.1 + cpe:/a:true_north:internet_anywhere_mail_server:3.1 + + CVE-1999-1236 + 1999-10-01T00:00:00.000-04:00 + 2008-09-05T16:19:02.757-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iams-passwords-plaintext(3285) + + + BID + 731 + + + NTBUGTRAQ + 19991001 Vulnerabilities in the Internet Anywhere Mail Server + + Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf. + + + + + + + + + cpe:/a:apache:http_server + + CVE-1999-1237 + 1999-06-06T00:00:00.000-04:00 + 2008-09-05T16:19:02.900-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + smbvalid-bo(2272) + + + BUGTRAQ + 19990606 Buffer overflows in smbval library + + Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods. + + + + + + + + + + + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:8 + cpe:/o:hp:hp-ux:9 + + CVE-1999-1238 + 1994-09-21T00:00:00.000-04:00 + 2008-09-05T16:19:03.040-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-core-diag-fileset(2262) + + + HP + HPSBUX9409-017 + + Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges. + + + + + + + + + cpe:/o:hp:hp-ux:9 + + CVE-1999-1239 + 1994-07-13T00:00:00.000-04:00 + 2008-09-05T16:19:03.180-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-xauthority(2261) + + + HP + HPSBUX9407-015 + + HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so. + + + + + + + + + cpe:/a:gracenote:cddbd + + CVE-1999-1240 + 1996-11-26T00:00:00.000-05:00 + 2008-09-05T16:19:03.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cddbd-bo(2203) + + Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message. + + + + + + + + + cpe:/a:microsoft:ie:6.0.2900 + + CVE-1999-1241 + 1999-05-06T00:00:00.000-04:00 + 2008-09-05T16:19:03.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ie-filesystemobject(2173) + + + MISC + http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html + + Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. + + + + + + + + + + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:9.01 + + CVE-1999-1242 + 1994-02-07T00:00:00.000-05:00 + 2008-09-05T16:19:03.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-subnet-config(2162) + + + HP + HPSBUX9402-003 + + Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges. + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.0 + + CVE-1999-1243 + 1995-03-03T00:00:00.000-05:00 + 2008-09-05T16:19:03.743-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sgi-permissions(2113) + + + CIAC + F-16 + + + SGI + 19950301-01-P373 + + SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges. + + + + + + + + + + + + + + + + cpe:/a:darren_reed:ipfilter:3.2.5 + cpe:/a:darren_reed:ipfilter:3.2.10 + cpe:/a:darren_reed:ipfilter:3.2.6 + cpe:/a:darren_reed:ipfilter:3.2.7 + cpe:/a:darren_reed:ipfilter:3.2.8 + cpe:/a:darren_reed:ipfilter:3.2.9 + cpe:/a:darren_reed:ipfilter:3.2.4 + cpe:/a:darren_reed:ipfilter:3.2.3 + + CVE-1999-1244 + 1999-04-15T00:00:00.000-04:00 + 2008-09-05T16:19:03.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ipfilter-temp-file(2087) + + + BUGTRAQ + 19990415 FSA-99.04-IPFILTER-v3.2.10 + + IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file. + + + + + + + + + cpe:/a:ucd-snmp:ucd-snmp:3.52 + + CVE-1999-1245 + 1999-04-06T00:00:00.000-04:00 + 2008-09-05T16:19:04.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ucd-snmpd-community(2086) + + vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information. + + + + + + + + + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-1246 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:04.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + siteserver-directmail-passwords(2068) + + + MSKB + Q229972 + + Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges. + + + + + + + + + cpe:/o:hp:hp-ux:9 + + CVE-1999-1247 + 1999-02-24T00:00:00.000-05:00 + 2008-09-05T16:19:04.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hp-dce9000(2061) + + + HP + HPSBUX9402-006 + + Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges. + + + + + + + + + + + + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:8.06 + cpe:/o:hp:hp-ux:8.00 + cpe:/o:hp:hp-ux:8.02 + + CVE-1999-1248 + 1994-11-30T00:00:00.000-05:00 + 2008-09-05T16:19:04.460-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-supportwatch(2058) + + + HP + HPSBUX9411-019 + + Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges. + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + + CVE-1999-1249 + 1997-01-06T00:00:00.000-05:00 + 2008-09-05T16:19:04.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-movemail(2057) + + + HP + HPSBUX9701-047 + + + OSVDB + 8099 + + movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges. + + + + + + + + + cpe:/a:blue_world_communications:lasso_cgi + + CVE-1999-1250 + 1997-08-19T00:00:00.000-04:00 + 2008-09-05T16:19:04.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-lasso(2044) + + + BUGTRAQ + 19970819 Lasso CGI security hole (fwd) + + Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + + CVE-1999-1251 + 1996-12-24T00:00:00.000-05:00 + 2008-09-05T16:19:04.883-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-audio-panic(2010) + + + HP + HPSBUX9612-043 + + Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service. + + + + + + + + + + cpe:/o:sco:unixware:2.0.x + cpe:/o:sco:unixware:2.1.0 + + CVE-1999-1252 + 1996-09-04T00:00:00.000-04:00 + 2008-09-05T16:19:05.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + VB-96.15 + + + XF + sco-system-call(1966) + + + SCO + 96:002 + + Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges. + + + + + + + + + + + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:internet_faststart:1.0 + + CVE-1999-1253 + 1996-06-07T00:00:00.000-04:00 + 2008-09-05T16:19:05.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + VB-96.10 + + + XF + sco-kernel(1965) + + + SCO + 96:001 + + Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt + + CVE-1999-1254 + 1999-03-08T00:00:00.000-05:00 + 2008-09-05T16:19:05.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win-redirects-freeze(1947) + + + NTBUGTRAQ + 19990308 Winfreeze EXPLOIT Win9x/NT + + Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. + + + + + + + + + cpe:/a:ccs_network:hyperseek_search_engine:2000 + + CVE-1999-1255 + 1999-02-19T00:00:00.000-05:00 + 2008-09-05T16:19:05.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hyperseek-modify(1914) + + Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter. + + + + + + + + + cpe:/a:oracle:database_assistant:1.0 + + CVE-1999-1256 + 1999-03-04T00:00:00.000-05:00 + 2008-09-05T16:19:05.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + oracle-passwords(1902) + + + BUGTRAQ + 19990304 Oracle Plaintext Password + + + NTBUGTRAQ + 19990304 Oracle Plaintext Password + + Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file. + + + + + + + + + + cpe:/h:xyplex:maxserver_xyplex_terminal_server:6.0.1_s1 + cpe:/h:xyplex:maxserver_xyplex_terminal_server:6.0.2_s4 + + CVE-1999-1257 + 1997-11-26T00:00:00.000-05:00 + 2008-09-05T16:19:05.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + xyplex-question-login(1826) + + + XF + xyplex-controlz-login(1825) + + + BUGTRAQ + 19971126 Xyplex terminal server bug + + Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark). + + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1258 + 1991-01-15T00:00:00.000-05:00 + 2008-09-05T16:19:05.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-pwdauthd(1782) + + + SUN + 00102 + + rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information. + + + + + + + + + cpe:/a:microsoft:office:98::mac + + CVE-1999-1259 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:06.023-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + office-extraneous-data(1780) + + + MSKB + Q189529 + + Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information. + + + + + + + + + cpe:/a:hughes:msql:2.0.6 + + CVE-1999-1260 + 1999-02-15T00:00:00.000-05:00 + 2008-09-05T16:19:06.150-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + msql-serverstats(1777) + + + BUGTRAQ + 19990215 KSR[T] Advisory #10: mSQL ServerStats + + mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. + + + + + + + + + cpe:/a:metamail_corporation:metamail:7.2 + + CVE-1999-1261 + 1997-10-24T00:00:00.000-04:00 + 2008-09-10T15:01:32.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rainbowsix-nick-bo(1772) + + + BUGTRAQ + 19990211 Rainbow Six Buffer Overflow..... + + Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command. + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.01 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.07 + + CVE-1999-1262 + 1997-08-01T00:00:00.000-04:00 + 2008-09-10T15:01:33.040-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + java-socket-open(1727) + + + BUGTRAQ + 19990202 Unsecured server in applets under Netscape + + Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities. + + + + + + + + + cpe:/a:metamail_corporation:metamail:2.7 + + CVE-1999-1263 + 2003-08-15T00:00:00.000-04:00 + 2008-09-10T15:01:33.117-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + metamail-file-creation(1677) + + + BUGTRAQ + 19971024 Vulnerability in metamail + + Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file. + + + + + + + + + + + + cpe:/h:ramp_networks:webramp:m3t + cpe:/h:ramp_networks:webramp:m3 + cpe:/h:ramp_networks:webramp:m3i + cpe:/h:ramp_networks:webramp:300 + + CVE-1999-1264 + 1999-01-21T00:00:00.000-05:00 + 2008-09-05T16:19:06.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19990203 WebRamp M3 Perceived Bug + + + XF + webramp-remote-access(1670) + + + BUGTRAQ + 19990121 WebRamp M3 remote network access bug + + WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been expliticly disabled. + + + + + + + + + cpe:/a:seatle_lab_software:slmail:3.1 + + CVE-1999-1265 + 1998-09-22T00:00:00.000-04:00 + 2008-09-05T16:19:06.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + slmail-parens-overload(1664) + + + NTBUGTRAQ + 19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1 + + + BUGTRAQ + 19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1 + + SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO. + + + + + + + + + cpe:/a:metamail_corporation:metamail:7.2 + + CVE-1999-1266 + 1997-06-13T00:00:00.000-04:00 + 2008-09-05T16:19:07.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rsh-username-leaks(1660) + + + BUGTRAQ + 19970613 rshd gives away usernames + + rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system. + + + + + + + + + cpe:/o:kde:kde + + CVE-1999-1267 + 1997-05-05T00:00:00.000-04:00 + 2008-09-05T16:19:07.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kde-flawed-ipc(1646) + + + BUGTRAQ + 19970505 Hole in the KDE desktop + + KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server. + + + + + + + + + cpe:/o:kde:kde + + CVE-1999-1268 + 1999-01-06T00:00:00.000-05:00 + 2008-09-05T16:19:07.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://lists.kde.org/?l=kde-devel&m=91560433413263&w=2 + + + XF + kde-konsole-hijack(1645) + + Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices. + + + + + + + + + cpe:/o:kde:kde_beta_3:initial + + CVE-1999-1269 + 1998-02-06T00:00:00.000-05:00 + 2008-09-05T16:19:07.430-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kde-kss-file-clobber(1641) + + + BUGTRAQ + 19980206 serious security hole in KDE Beta 3 + + Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file. + + + + + + + + + cpe:/o:kde:kde:1.0 + + CVE-1999-1270 + 1998-07-11T00:00:00.000-04:00 + 2008-09-05T16:19:07.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kde-kmail-passphrase-leak(1639) + + + MISC + http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2 + + KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps. + + + + + + + + + cpe:/a:macromedia:dreamweaver:initial + + CVE-1999-1271 + 1998-06-11T00:00:00.000-04:00 + 2008-09-05T16:19:07.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dreamweaver-weak-passwords(1636) + + + BUGTRAQ + 19980611 Unsecure passwords in Macromedia Dreamweaver + + Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-1272 + 1998-03-01T00:00:00.000-05:00 + 2008-09-05T16:19:07.853-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + irix-cdrom-confidence(1635) + + + SGI + 19980301-01-PX + + Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges. + + + + + + + + + cpe:/a:national_science_foundation:squid_web_proxy:1.1.20 + + CVE-1999-1273 + 1998-02-20T00:00:00.000-05:00 + 2008-09-05T16:19:07.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + squid-regexp-acl(1627) + + + BUGTRAQ + 19980220 Simple way to bypass squid ACLs + + Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences. + + + + + + + + + cpe:/a:ipass:roamserver:3.1 + + CVE-1999-1274 + 1997-12-29T00:00:00.000-05:00 + 2008-09-05T16:19:08.150-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ipass-temporary-files(1625) + + + BUGTRAQ + 19971229 iPass RoamServer 3.1 + + iPass RoamServer 3.1 creates temporary files with world-writable permissions. + + + + + + + + + cpe:/a:ibm:lotus_cc_mail:8.0 + + CVE-1999-1275 + 1997-09-08T00:00:00.000-04:00 + 2008-09-05T16:19:08.290-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + lotus-ccmail-passwords(1619) + + + BUGTRAQ + 19970908 Password unsecurity in cc:Mail release 8 + + Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + cpe:/o:debian:debian_linux:2.1 + + CVE-1999-1276 + 1998-12-07T00:00:00.000-05:00 + 2008-09-05T16:19:08.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + fte-console-privileges(1609) + + + DEBIAN + 19981207 fte-console: does not drop its root priviliges + + fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. + + + + + + + + + cpe:/a:backweb_technologies:backweb_client + + CVE-1999-1277 + 1998-12-24T00:00:00.000-05:00 + 2008-09-05T16:19:08.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + backweb-cleartext-passwords(1565) + + + NTBUGTRAQ + 19981224 BackWeb - Password issue (used by NAI for Corporate customer notification). + + BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. + + + + + + + + + cpe:/a:nlog:nlog + + CVE-1999-1278 + 1998-12-25T00:00:00.000-05:00 + 2008-09-05T16:19:08.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-nlog-netbios(1550) + + + BUGTRAQ + 19981226 Nlog 1.1b released - security holes fixed + + + BUGTRAQ + 19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool + + nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl. + + + + + + + + + + cpe:/a:microsoft:sna_server:2.11 + cpe:/a:microsoft:sna_server:3.0 + + CVE-1999-1279 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:08.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q138001 + + + XF + snaserver-shared-folders(1548) + + An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. + + + + + + + + + cpe:/a:hummingbird:exceed:6.0.1.0 + + CVE-1999-1280 + 1998-12-03T00:00:00.000-05:00 + 2008-09-05T16:19:08.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + exceed-cleartext-passwords(1547) + + + BUGTRAQ + 19981203 Remote Tools w/Exceed v.6.0.1.0 fer 95 + + Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file. + + + + + + + + + cpe:/a:winddance_networks_corporation:breeze_network_server + + CVE-1999-1281 + 1998-12-26T00:00:00.000-05:00 + 2008-09-05T16:19:09.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + breeze-remote-reboot(1544) + + + BUGTRAQ + 19981226 Breeze Network Server remote reboot and other bogosity. + + Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program. + + + + + + + + + cpe:/a:realnetworks:realsystem_g2_server + + CVE-1999-1282 + 1998-12-10T00:00:00.000-05:00 + 2008-09-05T16:19:09.273-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + realsystem-readable-conf-file(1542) + + + BUGTRAQ + 19981210 RealSystem passwords + + RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:3.2.1 + + CVE-1999-1283 + 1998-08-14T00:00:00.000-04:00 + 2008-09-05T16:19:09.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + opera-slash-crash(1541) + + + BUGTRAQ + 19980814 URL exploit to crash Opera Browser + + Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag. + + + + + + + + + cpe:/a:puppets_place:nukenabber + + CVE-1999-1284 + 1998-11-05T00:00:00.000-05:00 + 2008-09-05T16:19:09.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nukenabber-timeout-dos(1540) + + + BUGTRAQ + 19981105 various *lame* DoS attacks + + + MISC + http://www.dynamsol.com/puppet/text/new.txt + + + BUGTRAQ + 19981107 Re: various *lame* DoS attacks + + NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection. + + + + + + + + + cpe:/o:linux:linux_kernel:2.1.132 + + CVE-1999-1285 + 1998-12-27T00:00:00.000-05:00 + 2008-09-05T16:19:09.697-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19981227 [patch] fix for urandom read(2) not interruptible + + + XF + linux-random-read-dos(1472) + + Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.2 + + CVE-1999-1286 + 1997-05-09T00:00:00.000-04:00 + 2008-09-05T16:19:09.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + irix-addnetpr(1433) + + + BUGTRAQ + 19970509 Re: Irix: misc + + + BID + 330 + + + OSVDB + 8560 + + + MISC + ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX + + addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:stephen_turner:analog:3.0 + + CVE-1999-1287 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:09.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + analog-remote-file(1410) + + + CONFIRM + http://www.statslab.cam.ac.uk/~sret1/analog/security.html + + Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface. + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux:1.1 + cpe:/o:caldera:openlinux:1.2 + cpe:/o:caldera:openlinux:1.0 + cpe:/o:caldera:openlinux:1.3 + cpe:/o:turbolinux:turbolinux + cpe:/o:redhat:linux + cpe:/a:samba:samba:1.9.18 + + CVE-1999-1288 + 1998-11-19T00:00:00.000-05:00 + 2008-09-05T16:19:10.103-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + samba-wsmbconf(1406) + + + CALDERA + SA-1998.35 + + + BUGTRAQ + 19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux + + Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. + + + + + + + + + cpe:/a:mirabilis:icq:98_beta + + CVE-1999-1289 + 1998-11-11T00:00:00.000-05:00 + 2008-09-05T16:19:10.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + icq-ip-info(1398) + + + BUGTRAQ + 19981111 WARNING: Another ICQ IP address vulnerability + + ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration. + + + + + + + + + cpe:/a:chris_matthee:nftp:1.40 + + CVE-1999-1290 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:10.397-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nftp-bo(1397) + + + CONFIRM + http://www.ayukov.com/nftp/history.html + + + BUGTRAQ + 19981117 nftp vulnerability (fwd) + + Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string. + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1291 + 1998-10-05T00:00:00.000-04:00 + 2008-09-05T16:19:10.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-brkill(1383) + + + BUGTRAQ + 19981005 New Windows Vulnerability + + TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target. + + + + + + + + + cpe:/a:kolban:webcam32:4.8.3 + + CVE-1999-1292 + 1998-09-01T00:00:00.000-04:00 + 2008-09-05T16:19:10.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + webcam32-buffer-overflow(1366) + + + ISS + 19980901 Remote Buffer Overflow in the Kolban Webcam32 Program + + Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL. + + + + + + + + + cpe:/a:apache:http_server:1.2.5 + + CVE-1999-1293 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:10.820-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.apache.org/info/security_bulletin_1.2.5.html + + + BUGTRAQ + 19980106 Apache security advisory + + mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. + + + + + + + + + cpe:/o:microsoft:windows_nt:3.51 + + CVE-1999-1294 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:10.960-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q146604 + + + XF + nt-filemgr(562) + + Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. + + + + + + + + + cpe:/a:transarc:dce_distributed_file_system:1.1 + + CVE-1999-1295 + 1996-09-17T00:00:00.000-04:00 + 2011-03-07T21:01:54.437-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + VB-96.16 + + + XF + dfs-login-groups(7154) + + Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS. + + + + + + + + + cpe:/a:mit:kerberos:5-1.5.2 + + CVE-1999-1296 + 1997-04-29T00:00:00.000-04:00 + 2008-09-05T16:19:11.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19970429 vulnerabilities in kerberos + + Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable. + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:1.0.1 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sun:sunos:4.1.4 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:solaris:1.0 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:solaris:1.1 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1297 + 1998-07-15T00:00:00.000-04:00 + 2008-09-05T16:19:11.383-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-cmdtool-echo(7482) + + + SUNBUG + 1077164 + + cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.1.7 + cpe:/o:freebsd:freebsd:2.2.1 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-1298 + 1997-04-07T00:00:00.000-04:00 + 2008-09-10T15:01:40.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + FREEBSD + FreeBSD-SA-97:03 + + + OSVDB + 6087 + + + XF + freebsd-sysinstall-ftp-password(7537) + + Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources. + + + + + + + + + + cpe:/o:redhat:linux:4.0 + cpe:/o:slackware:slackware_linux:3.1 + + CVE-1999-1299 + 1997-02-03T00:00:00.000-05:00 + 2008-09-05T16:19:11.680-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19970203 Linux rcp bug + + rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file. + + + + + + + + + + cpe:/o:cray:unicos:6.1 + cpe:/o:cray:unicos:6.0 + + CVE-1999-1300 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:11.820-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + B-31 + + Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration. + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.5 + + CVE-1999-1301 + 1996-07-16T00:00:00.000-04:00 + 2008-09-05T16:19:11.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CIAC + G-31 + + + FREEBSD + FreeBSD-SA-96:17 + + + XF + rzsz-command-execution(7540) + + A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs. + + + + + + + + + + + + + + + + + cpe:/o:sco:unix:4.2 + cpe:/o:sco:unix:4.1 + cpe:/o:sco:open_desktop_lite:3.0 + cpe:/o:sco:openserver_network_system:3.0 + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:4.0 + cpe:/o:sco:openserver_enterprise_system:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2 + + CVE-1999-1302 + 1994-11-30T00:00:00.000-05:00 + 2011-03-10T00:00:00.000-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sco-pt_chmod(7586) + + + OSVDB + 8797 + + + CERT + VB-94:01 + + + CIAC + F-05 + + Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access. + + + + + + + + + + + + + + + + + cpe:/o:sco:unix:4.2 + cpe:/o:sco:unix:4.1 + cpe:/o:sco:open_desktop_lite:3.0 + cpe:/o:sco:openserver_network_system:3.0 + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:4.0 + cpe:/o:sco:openserver_enterprise_system:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2 + + CVE-1999-1303 + 1994-11-30T00:00:00.000-05:00 + 2011-03-07T21:01:55.033-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SCO + 94:001 + + Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access. + + + + + + + + + + + + + + + + + cpe:/o:sco:unix:4.2 + cpe:/o:sco:unix:4.1 + cpe:/o:sco:open_desktop_lite:3.0 + cpe:/o:sco:openserver_network_system:3.0 + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:4.0 + cpe:/o:sco:openserver_enterprise_system:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2 + + CVE-1999-1304 + 1994-11-30T00:00:00.000-05:00 + 2011-03-07T21:01:55.110-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SCO + 94:001 + + Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access. + + + + + + + + + + + + + + + + + cpe:/o:sco:unix:4.2 + cpe:/o:sco:unix:4.1 + cpe:/o:sco:open_desktop_lite:3.0 + cpe:/o:sco:openserver_network_system:3.0 + cpe:/o:sco:open_desktop:2.0 + cpe:/o:sco:unix:4.0 + cpe:/o:sco:openserver_enterprise_system:3.0 + cpe:/o:sco:open_desktop:3.0 + cpe:/o:sco:unix:3.2 + + CVE-1999-1305 + 1994-11-30T00:00:00.000-05:00 + 2011-03-07T21:01:55.187-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + F-05 + + Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access. + + + + + + + + + cpe:/o:cisco:ios:9.1 + + CVE-1999-1306 + 1992-12-10T00:00:00.000-05:00 + 2008-09-05T16:19:12.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1992-20 + + Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters. + + + + + + + + + cpe:/o:novell:unixware:1.1 + + CVE-1999-1307 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:12.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + F-06 + + + BUGTRAQ + 19941209 Novell security advisory on sadc, urestore and the suid_exec feature + + Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges. + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + + CVE-1999-1308 + 1997-07-31T00:00:00.000-04:00 + 2011-03-07T21:01:55.407-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-large-uid-gid(7594) + + + HP + HPSBUX9611-041 + + + CIAC + H-09 + + Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges. + + + + + + + + + cpe:/a:sendmail:sendmail:8.6.7 + + CVE-1999-1309 + 1996-08-30T00:00:00.000-04:00 + 2008-09-05T16:19:13.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1994-12 + + + BUGTRAQ + 19940315 Security problem in sendmail versions 8.x.x + + + BUGTRAQ + 19940315 anyone know details? + + + BUGTRAQ + 19940314 sendmail -d problem (OLD yet still here) + + + XF + sendmail-debug-gain-root(7155) + + + BUGTRAQ + 19940327 sendmail exploit script - resend + + + BUGTRAQ + 19940315 so... + + Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option. + + + CVE-1999-1310 + 1994-11-04T00:00:00.000-05:00 + 2008-09-10T15:01:41.883-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1022. Reason: This candidate is a duplicate of CVE-1999-1022. Notes: All CVE users should reference CVE-1999-1022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + + CVE-1999-1311 + 1997-01-07T00:00:00.000-05:00 + 2011-03-07T21:01:55.547-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CIAC + H-21 + + Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges. + + + + + + + + + + cpe:/a:dec:dec_openvms_vax:5.5.2 + cpe:/a:dec:dec_openvms_axp:1.0 + + CVE-1999-1312 + 1993-02-24T00:00:00.000-05:00 + 2008-09-05T16:19:13.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1993-05 + + + XF + openvms-local-privilege-elevation(7142) + + Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2 + + CVE-1999-1313 + 1996-05-23T00:00:00.000-04:00 + 2008-09-05T16:19:13.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CIAC + G-24 + + + FREEBSD + FreeBSD-SA-96:11 + + + XF + bsd-man-command-sequence(7348) + + Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.1:stable + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:freebsd:freebsd:2.2:current + + CVE-1999-1314 + 1996-05-17T00:00:00.000-04:00 + 2008-09-10T15:01:42.147-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-96:10 + + + XF + unionfs-mount-ordering(7429) + + + CIAC + G-24 + + Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands. + + + + + + + + + cpe:/a:dec:dec_openvms:5.8 + + CVE-1999-1315 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:13.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + F-04 + + Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp2:server + + CVE-1999-1316 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:14.100-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q247975 + + + XF + passfilt-fullname(7391) + + Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp4 + + CVE-1999-1317 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:14.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q222159 + + + NTBUGTRAQ + 19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links + + + NTBUGTRAQ + 19990312 [ ALERT ] Case Sensitivity and Symbolic Links + + + XF + nt-symlink-case(7398) + + Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:1.0.1 + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:solaris:1.1c + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:solaris:1.0 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:solaris:1.1 + + CVE-1999-1318 + 1993-09-17T00:00:00.000-04:00 + 2008-09-10T15:01:42.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUNBUG + 1121935 + + + XF + sun-su-path(7480) + + /usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs. + + + + + + + + + + + + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.1 + + CVE-1999-1319 + 1996-01-03T00:00:00.000-05:00 + 2008-09-10T15:01:42.493-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 19960101-01-PX + + + XF + irix-object-server(7430) + + Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations. + + + + + + + + + cpe:/o:novell:netware:3.0 + + CVE-1999-1320 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:14.680-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + D-01 + + + XF + netware-packet-spoofing-privileges(7213) + + Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing. + + + + + + + + + cpe:/a:mit:kerberos:v + + CVE-1999-1321 + 1998-11-05T00:00:00.000-05:00 + 2008-09-05T16:19:14.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19981105 security patch for ssh-1.2.26 kerberos code + + + OSVDB + 4883 + + Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing. + + + + + + + + + + + cpe:/a:microsoft:exchange_server + cpe:/a:ca:inoculan + cpe:/a:ca:arcserve_backup + + CVE-1999-1322 + 1998-11-12T00:00:00.000-05:00 + 2008-09-05T16:19:14.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + NTBUGTRAQ + 19981117 Re: exchverify.log - update #1 + + + NTBUGTRAQ + 19981112 exchverify.log + + The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. + + + + + + + + + + cpe:/a:symantec:norton_antivirus:1.5::exchange + cpe:/a:symantec:norton_antivirus:1.0.1.7::internet_email_gateways + + CVE-1999-1323 + 1999-04-09T00:00:00.000-04:00 + 2008-09-05T16:19:15.100-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + NTBUGTRAQ + 19990409 NAV for MS Exchange & Internet Email Gateways + + Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE. + + + + + + + + + + cpe:/a:dec:dec_openvms_vax:5.5.2 + cpe:/a:dec:dec_openvms_vax:5.3 + + CVE-1999-1324 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:15.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + D-06 + + + XF + openvms-sysgen-enabled(7225) + + VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing. + + + + + + + + + cpe:/a:vax_vms:sas_system:5.18 + + CVE-1999-1325 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:15.383-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + C-19 + + + XF + vaxvms-sas-gain-privileges(7261) + + SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges. + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.4 + + CVE-1999-1326 + 1997-07-04T00:00:00.000-04:00 + 2008-09-05T16:19:15.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970105 BoS: serious security bug in wu-ftpd v2.4 -- PATCH + + + BUGTRAQ + 19970104 serious security bug in wu-ftpd v2.4 + + + XF + wuftpd-abor-gain-privileges(7169) + + wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files. + + + + + + + + + cpe:/o:redhat:linux:5.1 + + CVE-1999-1327 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:43.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf + + + BUGTRAQ + 19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd) + + + OSVDB + 6065 + + + XF + linuxconf-lang-bo(7239) + + Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable. + + + + + + + + + cpe:/o:redhat:linux:5.1 + + CVE-1999-1328 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:15.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980823 Security concerns in linuxconf shipped w/RedHat 5.1 + + + CONFIRM + http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf + + + OSVDB + 6068 + + + XF + linuxconf-symlink-gain-privileges(7232) + + linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack. + + + + + + + + + cpe:/o:redhat:linux:5.1 + + CVE-1999-1329 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:43.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit + + + XF + sysvinit-root-bo(7250) + + Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges. + + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + cpe:/o:redhat:linux:4.2 + + CVE-1999-1330 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:44.257-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd) + + + CONFIRM + http://www.redhat.com/support/errata/rh42-errata-general.html#db + + + CONFIRM + http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html + + + XF + linux-libdb-snprintf-bo(7244) + + The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf. + + + + + + + + + cpe:/o:redhat:linux:4.2 + + CVE-1999-1331 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:44.337-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg + + + XF + netcfg-ethernet-dos(7245) + + netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface. + + + + + + + + + cpe:/o:redhat:linux:5.0 + + CVE-1999-1332 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:16.350-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#gzip + + + BUGTRAQ + 19980128 GZEXE - the big problem + + + BID + 7845 + + + OSVDB + 3812 + + + XF + gzip-gzexe-tmp-symlink(7241) + + + DEBIAN + DSA-308 + + gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file. + + + + + + + + + cpe:/o:redhat:linux:5.0 + + CVE-1999-1333 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:16.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980319 ncftp 2.4.2 MkDirs bug + + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp + + + OSVDB + 6111 + + + XF + ncftp-autodownload-command-execution(7240) + + automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded. + + + + + + + + + cpe:/a:elm_development_group:elm:2.4 + + CVE-1999-1334 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:16.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980129 KSR[T] Advisory #7: filter + + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#elm + + Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument. + + + + + + + + + cpe:/o:redhat:linux:4.0 + + CVE-1999-1335 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:44.633-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp + + + XF + cmusnmp-read-write(7251) + + snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information. + + + + + + + + + cpe:/h:3com:hiperarc:4.2.29 + + CVE-1999-1336 + 1999-08-12T00:00:00.000-04:00 + 2008-09-05T16:19:16.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990816 Re: 3com hiperarch flaw [hiperbomb.c] + + + BUGTRAQ + 19990812 3com hiperarch flaw [hiperbomb.c] + + + OSVDB + 6057 + + 3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port. + + + + + + + + + cpe:/a:midnight_commander:midnight_commander:4.5.11 + + CVE-1999-1337 + 1999-08-01T00:00:00.000-04:00 + 2008-09-10T15:01:44.773-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990801 midnight commander vulnerability(?) (fwd) + + + OSVDB + 5921 + + + XF + midnight-commander-data-disclosure(9873) + + FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. + + + + + + + + + cpe:/a:delegate:delegate:5.9.3 + + CVE-1999-1338 + 1999-07-21T00:00:00.000-04:00 + 2008-09-05T16:19:17.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990721 Delegate creates directories writable for anyone + + Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:freebsd:freebsd:3.2 + + CVE-1999-1339 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:17.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz + + + BUGTRAQ + 19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10) + + + BUGTRAQ + 19990722 Linux +ipchains+ ping -R + + + OSVDB + 6105 + + + XF + ipchains-ping-route-dos(7257) + + Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command. + + + + + + + + + cpe:/a:hylafax:hylafax:4.0.2 + + CVE-1999-1340 + 1999-11-04T00:00:00.000-05:00 + 2008-09-05T16:19:17.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 765 + + + BUGTRAQ + 19991104 hylafax-4.0.2 local exploit + + Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.13:pre15 + cpe:/o:linux:linux_kernel:2.3.18 + + CVE-1999-1341 + 1999-10-22T00:00:00.000-04:00 + 2008-09-05T16:19:17.600-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19991022 Local user can send forged packets + + + XF + linux-tiocsetd-forge-packets(7858) + + Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices. + + + + + + + + + cpe:/a:icq:activelist_server + + CVE-1999-1342 + 1999-10-17T00:00:00.000-04:00 + 2008-09-05T16:19:17.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19991017 ICQ ActiveList Server Exploit... + + ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port. + + + + + + + + + cpe:/h:xerox:docucolor_4lp + + CVE-1999-1343 + 1999-10-13T00:00:00.000-04:00 + 2008-09-05T16:19:17.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991013 Xerox DocuColor 4 LP D.O.S + + HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters. + + + + + + + + + cpe:/a:auto_ftp:auto_ftp:0.2 + + CVE-1999-1344 + 1999-10-05T00:00:00.000-04:00 + 2008-09-05T16:19:18.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991005 Auto_FTP v0.02 Advisory + + Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file. + + + + + + + + + cpe:/a:auto_ftp:auto_ftp:0.2 + + CVE-1999-1345 + 1999-10-05T00:00:00.000-04:00 + 2008-09-05T16:19:18.163-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991005 Auto_FTP v0.02 Advisory + + Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred. + + + + + + + + + cpe:/o:redhat:linux:6.1 + + CVE-1999-1346 + 1999-10-07T00:00:00.000-04:00 + 2008-09-05T16:19:18.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991007 Problems with redhat 6 Xsession and pam.d/rlogin. + + PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file. + + + + + + + + + cpe:/o:redhat:linux:6.1 + + CVE-1999-1347 + 1999-10-07T00:00:00.000-04:00 + 2008-09-05T16:19:18.447-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19991007 Problems with redhat 6 Xsession and pam.d/rlogin. + + Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-1999-1348 + 1999-06-30T00:00:00.000-04:00 + 2008-09-05T16:19:18.587-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990630 linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot + + Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service. + + + + + + + + + cpe:/a:xlink_technology:omni-nfs_x_enterprise:6.1 + + CVE-1999-1349 + 1999-10-06T00:00:00.000-04:00 + 2008-09-05T16:19:18.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991006 Omni-NFS/X Enterprise (nfsd.exe) DOS + + NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111. + + + + + + + + + cpe:/a:arcad_systemhaus:arcad:0.078_5 + + CVE-1999-1350 + 1999-09-29T00:00:00.000-04:00 + 2008-09-05T16:19:18.867-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990929 Multiple Vendor ARCAD permission problems + + ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse. + + + + + + + + + cpe:/a:kvirc:irc_client:0.9.0 + + CVE-1999-1351 + 1999-09-24T00:00:00.000-04:00 + 2008-09-10T15:01:46.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kvirc-dot-directory-traversal(7761) + + + BUGTRAQ + 19990924 Kvirc bug + + Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.0 + + CVE-1999-1352 + 1999-09-28T00:00:00.000-04:00 + 2008-09-05T16:19:19.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990928 Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy] + + mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges. + + + + + + + + + cpe:/a:nosque:msgcore:2.14 + + CVE-1999-1353 + 1999-09-07T00:00:00.000-04:00 + 2008-09-05T16:19:19.290-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990907 MsgCore mailserver stores passwords in clear text + + Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privielges. + + + + + + + + + cpe:/a:softarc:firstclass_internet_server:5.506 + + CVE-1999-1354 + 1999-08-30T00:00:00.000-04:00 + 2008-09-05T16:19:19.413-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + NTBUGTRAQ + 19990909 SoftArc's FirstClass E-mail Client + + + NTBUGTRAQ + 19990830 SoftArc's FirstClass E-mail Client + + E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. + + + + + + + + + + cpe:/a:compaq:management_agents_for_servers:4.40 + cpe:/a:compaq:insight_management_agent:4.20 + + CVE-1999-1355 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:19.553-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + management-pfcuser(3231) + + + CONFIRM + http://www.compaq.com/products/servers/management/advisory.html + + + NTBUGTRAQ + 19990905 Case ID SSRT0620 - PFCUser account communication + + + NTBUGTRAQ + 19990817 Compaq PFCUser account + + + NTBUGTRAQ + 19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B PFCUser issues + + + NTBUGTRAQ + 19990915 (I) UPDATE - PFCUser Account, + + BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges. + + + + + + + + + cpe:/a:compaq:smartstart:4.50 + + CVE-1999-1356 + 1999-09-02T00:00:00.000-04:00 + 2008-09-05T16:19:19.697-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + NTBUGTRAQ + 19990917 Re: Compaq CIM UG Overwrites Legal Notice + + + BUGTRAQ + 19990902 Compaq CIM UG Overwrites Legal Notice + + + XF + compaq-smartstart-legal-notice(7763) + + + NTBUGTRAQ + 19990902 Compaq CIM UG Overwrites Legal Notice + + Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy. + + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.04 + + CVE-1999-1357 + 1999-10-05T00:00:00.000-04:00 + 2008-09-05T16:19:19.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991005 Time to update those CGIs again + + Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-1999-1358 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:19.993-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MSKB + Q157673 + + + XF + nt-user-policy-update(7400) + + When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-1359 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:20.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q163875 + + + XF + nt-group-policy-longname(7401) + + When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1360 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:20.273-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q160650 + + + XF + nt-kernel-handle-dos(7402) + + Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-1361 + 1998-05-09T00:00:00.000-04:00 + 2008-09-05T16:19:20.397-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980509 coke.c + + Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1362 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:20.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q160601 + + + XF + nt-win32k-dos(7403) + + Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_nt:3.5.1 + + CVE-1999-1363 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:20.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q163143 + + + XF + nt-nonpagedpool-dos(7405) + + Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1364 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:20.820-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q142653 + + + XF + nt-threadcontext-dos(7421) + + Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-1999-1365 + 1999-06-28T00:00:00.000-04:00 + 2008-09-05T16:19:20.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 0515 + + + NTBUGTRAQ + 19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location + + + XF + nt-login-default-folder(2336) + + + NTBUGTRAQ + 19990630 Update: NT runs explorer.exe, etc... + + Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default. + + + + + + + + + cpe:/a:david_harris:pegasus_mail:3.0 + + CVE-1999-1366 + 1999-05-15T00:00:00.000-04:00 + 2008-09-05T16:19:21.100-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990515 Pegasus Mail weak encryption + + Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-1367 + 1999-05-06T00:00:00.000-04:00 + 2008-09-05T16:19:21.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.pcworld.com/news/article/0,aid,10842,00.asp + + Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. + + + + + + + + + cpe:/a:ca:inoculateit:4.53 + + CVE-1999-1368 + 1999-05-12T00:00:00.000-04:00 + 2008-09-05T16:19:21.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20001116 InoculateIT AV Option for MS Exchange Server + + + NTBUGTRAQ + 19990512 InoculateIT 4.53 Real-Time Exchange Scanner Flawed + + AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox. + + + + + + + + + cpe:/a:realnetworks:realserver:6.0.3.353 + + CVE-1999-1369 + 1999-04-14T00:00:00.000-04:00 + 2008-09-10T15:01:47.773-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19990414 Real Media Server stores passwords in plain text + + Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-1999-1370 + 1999-03-23T00:00:00.000-05:00 + 2008-09-05T16:19:21.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NTBUGTRAQ + 19990323 MSIE 5 installer disables screen saver + + The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs. + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1371 + 1999-03-08T00:00:00.000-05:00 + 2008-09-05T16:19:21.787-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + solaris-write-bo(7546) + + + MISC + http://www.securiteam.com/exploits/5ZP0O1P35O.html + + + BUGTRAQ + 19990308 Solaris "/usr/bin/write" bug + + Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument. + + + + + + + + + cpe:/a:triactive:remote_management + + CVE-1999-1372 + 1999-02-19T00:00:00.000-05:00 + 2008-09-10T15:01:48.367-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19990219 Plaintext Password in Tractive's Remote Manager Software + + Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges. + + + + + + + + + cpe:/a:fore:powerhub_software:5.0.0 + + CVE-1999-1373 + 2005-01-05T00:00:00.000-05:00 + 2008-09-05T16:19:22.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990105 Re: Network Scan Vulnerability [SUMMARY] + + FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap. + + + + + + + + + cpe:/a:arpanet:perlshop + + CVE-1999-1374 + 2005-05-02T00:00:00.000-04:00 + 2008-09-10T15:01:48.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990427 Re: Shopping Carts exposing CC data + + perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1375 + 1999-02-11T00:00:00.000-05:00 + 2008-09-05T16:19:22.350-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 230 + + + NTBUGTRAQ + 19990211 Using FSO in ASP to view just about anything + + FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1376 + 1999-01-14T00:00:00.000-05:00 + 2008-09-10T15:01:48.757-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NTBUGTRAQ + 19990114 MS IIS 4.0 Security Advisory + + + BUGTRAQ + 19990114 MS IIS 4.0 Security Advisory + + Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:matt_wright:download.cgi:1.0 + + CVE-1999-1377 + 1999-09-09T00:00:00.000-04:00 + 2008-09-05T16:19:22.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://pulhas.org/phrack/55/P55-07.html + + Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. + + + + + + + + + cpe:/a:dbmlparser.exe:dbmlparser.exe + + CVE-1999-1378 + 1999-07-19T00:00:00.000-04:00 + 2008-09-05T16:19:22.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990917 improper chroot in dbmlparser.exe + + dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/a:dnstools_software:dnstools + + CVE-1999-1379 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:22.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AUSCERT + AL-1999.004 + + + BUGTRAQ + 19990810 Possible Denial Of Service using DNS + + + CIAC + J-063 + + + BUGTRAQ + 19990730 Possible Denial Of Service using DNS + + + XF + dns-udp-query-dos(7238) + + DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker. + + + + + + + + + cpe:/a:symantec:norton_utilities:2.0 + + CVE-1999-1380 + 1997-05-04T00:00:00.000-04:00 + 2008-09-05T16:19:23.037-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://mlarchive.ima.com/win95/1997/May/0342.html + + + MISC + http://www.net-security.sk/bugs/NT/nu20.html + + + MISC + http://news.zdnet.co.uk/story/0,,s2065518,00.html + + + XF + nu-tuneocx-activex-control(7188) + + Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0. + + + + + + + + + cpe:/a:dbadmin:dbadmin:1.0.1 + + CVE-1999-1381 + 1998-10-08T00:00:00.000-04:00 + 2008-09-05T16:19:23.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19981008 buffer overflow in dbadmin + + Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/o:novell:netware + + CVE-1999-1382 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:23.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551 + + + BUGTRAQ + 19980812 Re: Netware NFS (fwd) + + + BUGTRAQ + 19980108 NetWare NFS + + + XF + netware-nfs-file-ownership(7246) + + NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program. + + + + + + + + + + + + + + + + cpe:/a:gnu:bash:1.14.6 + cpe:/a:gnu:bash:1.14.5 + cpe:/a:gnu:bash:1.14.4 + cpe:/a:tcsh:tcsh:6.05 + cpe:/a:gnu:bash:1.14.3 + cpe:/a:gnu:bash:1.14.2 + cpe:/a:gnu:bash:1.14.1 + cpe:/a:gnu:bash:1.14.0 + + CVE-1999-1383 + 1996-09-13T00:00:00.000-04:00 + 2011-08-08T00:00:00.000-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BUGTRAQ + 19960919 Vulnerability in expansion of PS1 in bash & tcsh + + + BUGTRAQ + 19960913 tee see shell problems + + (1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.1.1 + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + + CVE-1999-1384 + 1996-10-30T00:00:00.000-05:00 + 2008-09-05T16:19:23.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + AUSCERT + AA-96.08 + + + BID + 470 + + + BUGTRAQ + 19961030 (Another) vulnerability in new SGIs + + + SGI + 19961101-01-I + + + XF + irix-systour(7456) + + Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:1.0 + cpe:/o:freebsd:freebsd:2.1.6.1 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:1.1 + + CVE-1999-1385 + 1996-12-19T00:00:00.000-05:00 + 2008-09-10T15:01:50.570-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-96:20 + + + OSVDB + 6085 + + + XF + ppp-bo(7465) + + + BUGTRAQ + 19961219 Exploit for ppp bug (FreeBSD 2.1.0). + + Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable. + + + + + + + + + cpe:/a:larry_wall:perl:5.4.4 + + CVE-1999-1386 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:23.913-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980308 another /tmp race: `perl -e' opens temp file not safely + + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#perl + + + XF + perl-e-tmp-symlink(7243) + + Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp2 + + CVE-1999-1387 + 1997-04-02T00:00:00.000-05:00 + 2008-09-05T16:19:24.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19970407 DUMP of NT system crash + + + BUGTRAQ + 19970403 Fatal bug in NT 4.0 server (more comments) + + + BUGTRAQ + 19970402 Fatal bug in NT 4.0 server + + Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25. + + + + + + + + + cpe:/o:sun:sunos:4.1 + + CVE-1999-1388 + 1994-05-13T00:00:00.000-04:00 + 2008-09-05T16:19:24.197-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX + + + BUGTRAQ + 19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994 + + + BUGTRAQ + 19941218 Sun Patch Id #102060-01 + + passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument. + + + + + + + + + cpe:/h:3com:total_control_netserver_card:3.7.24 + + CVE-1999-1389 + 1998-05-11T00:00:00.000-04:00 + 2008-09-05T16:19:24.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 99 + + + BUGTRAQ + 19980511 3Com/USR Total Control Chassis dialup port access filters + + US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt. + + + + + + + + + cpe:/o:debian:debian_linux:2.0 + + CVE-1999-1390 + 1998-04-28T00:00:00.000-04:00 + 2008-09-05T16:19:24.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980428 [Debian 2.0] /usr/bin/suidexec gives root access + + + BID + 94 + + suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line. + + + + + + + + + + cpe:/a:next:next:1.0a + cpe:/a:next:next:1.0 + + CVE-1999-1391 + 1990-10-03T00:00:00.000-04:00 + 2008-09-05T16:19:24.600-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1990-06 + + + CIAC + B-01 + + + BID + 10 + + + XF + nextstep-npd-root-access(7143) + + Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions. + + + + + + + + + + cpe:/a:next:nex:1.0a + cpe:/a:next:next:1.0 + + CVE-1999-1392 + 1990-10-03T00:00:00.000-04:00 + 2008-09-05T16:19:24.740-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1990-06 + + + BID + 9 + + + CIAC + B-01 + + + XF + nextstep-restore09-root-access(7144) + + Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges. + + + + + + + + + + cpe:/o:apple:mac_os:8.6 + cpe:/o:apple:mac_os:8.5 + + CVE-1999-1393 + 1999-05-21T00:00:00.000-04:00 + 2008-09-05T16:19:24.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 532 + + + MISC + http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html + + Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible. + + + + + + + + + cpe:/o:bsd:bsd:4.4 + + CVE-1999-1394 + 1999-07-02T00:00:00.000-04:00 + 2008-09-05T16:19:25.023-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990702 BSD-fileflags + + + BID + 510 + + BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:dec:dec_openvms:5.3 + cpe:/a:dec:dec_openvms:5.2 + cpe:/a:dec:dec_openvms:5.4 + cpe:/a:dec:dec_openvms:5.4.2 + cpe:/a:dec:dec_openvms:5.2.1 + cpe:/a:dec:dec_openvms:5.4.1 + cpe:/a:dec:dec_openvms:5.1.2 + cpe:/a:dec:dec_openvms:5.1.1 + cpe:/a:dec:dec_openvms:5.1 + cpe:/a:dec:dec_openvms:5.0 + cpe:/a:dec:dec_openvms:5.1b + cpe:/a:dec:dec_openvms:5.3.1 + cpe:/a:dec:dec_openvms:5.3.2 + cpe:/a:dec:dec_openvms:5.0.1 + cpe:/a:dec:dec_openvms:5.0.2 + + CVE-1999-1395 + 1992-11-17T00:00:00.000-05:00 + 2009-10-31T00:02:35.750-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-92.16 + + + CERT + CA-1992-18 + + + BID + 51 + + + XF + vms-monitor-gain-privileges(7136) + + + OSVDB + 59332 + + Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges. + + + + + + + + + + + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1396 + 1992-07-21T00:00:00.000-04:00 + 2008-09-05T16:19:25.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-15 + + + BID + 49 + + + XF + sun-integer-multiplication-access(7150) + + Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash). + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-1999-1397 + 1999-03-23T00:00:00.000-05:00 + 2008-09-10T15:01:51.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19990323 Index Server 2.0 and the Registry + + + BID + 476 + + + XF + iis-indexserver-reveal-path(7559) + + + NTBUGTRAQ + 19990323 Index Server 2.0 and the Registry + + Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-1398 + 1997-05-07T00:00:00.000-04:00 + 2008-09-05T16:19:25.617-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 472 + + + MISC + http://www.insecure.org/sploits/irix.xfsdump.html + + + BUGTRAQ + 19970507 Irix: misc + + Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-1999-1399 + 1997-08-20T00:00:00.000-04:00 + 2008-09-05T16:19:25.787-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 471 + + + BUGTRAQ + 19970820 SpaceWare 7.3 v1.0 + + spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed. + + + + + + + + + cpe:/a:the_economist:the_economist_1999_screen_saver + + CVE-1999-1400 + 1999-06-03T00:00:00.000-04:00 + 2008-09-05T16:19:25.930-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 466 + + + NTBUGTRAQ + 19990603 Re: Huge Exploit in NT 4.0 SP5 Screensaver with Password Protecti on Enabled. + + + NTBUGTRAQ + 19990603 Huge Exploit in NT 4.0 SP5 Screensaver with Password Protection Enabled + + + NTBUGTRAQ + 19990604 Official response from The Economist re: 1999 Screen Saver + + The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked. + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-1401 + 1996-12-05T00:00:00.000-05:00 + 2008-09-05T16:19:26.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 463 + + + SGI + 19961201-01-PX + + + XF + irix-searchbook-permissions(7575) + + + OSVDB + 8563 + + Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook). + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:sunos:4.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:2.2.8 + + CVE-1999-1402 + 1997-05-17T00:00:00.000-04:00 + 2008-09-05T16:19:26.227-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 456 + + + BUGTRAQ + 19971003 Solaris 2.6 and sockets + + + BUGTRAQ + 19970517 UNIX domain socket (Solarisx86 2.5) + + + XF + sun-domain-socket-permissions(7172) + + The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket. + + + + + + + + + + + cpe:/a:ibm:tivoli_opc_tracker_agent:3.0x + cpe:/a:ibm:tivoli_opc_tracker_agent:2.0x + cpe:/a:ibm:tivoli_opc_tracker_agent:1.0x + + CVE-1999-1403 + 1998-10-02T00:00:00.000-04:00 + 2008-09-10T15:01:52.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 382 + + + BUGTRAQ + 19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt + + IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files. + + + + + + + + + + + cpe:/a:ibm:tivoli_opc_tracker_agent:3.0x + cpe:/a:ibm:tivoli_opc_tracker_agent:2.0x + cpe:/a:ibm:tivoli_opc_tracker_agent:1.0x + + CVE-1999-1404 + 1998-10-02T00:00:00.000-04:00 + 2008-09-10T15:01:52.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 382 + + + BUGTRAQ + 19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt + + IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly. + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-1405 + 1999-02-17T00:00:00.000-05:00 + 2008-09-05T16:19:26.693-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 375 + + + BUGTRAQ + 19990220 Re: snap utility for AIX. + + + BUGTRAQ + 19990217 snap utility for AIX. + + snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a. + + + + + + + + + cpe:/o:redhat:linux:5.1 + + CVE-1999-1406 + 1998-07-29T00:00:00.000-04:00 + 2008-09-10T15:01:52.993-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980729 Crash a redhat 5.1 linux box + + + BID + 372 + + + BUGTRAQ + 19980730 FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box) + + dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel. + + + + + + + + + cpe:/o:redhat:linux:5.0 + + CVE-1999-1407 + 1998-03-09T00:00:00.000-05:00 + 2008-09-05T16:19:26.977-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts + + + BUGTRAQ + 19980309 *sigh* another RH5 /tmp problem + + + BID + 368 + + + XF + initscripts-ifdhcpdone-dhcplog-symlink(7294) + + ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file. + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.1.5 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:ibm:aix:4.1 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-1408 + 1997-03-05T00:00:00.000-05:00 + 2008-09-05T16:19:27.117-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 352 + + + BUGTRAQ + 19970305 Bug in connect() for aix 4.1.4 ? + + Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:sgi:irix:6.4 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:sgi:irix:6.2 + + CVE-1999-1409 + 1998-07-03T00:00:00.000-04:00 + 2008-09-10T15:01:53.663-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980703 more about 'at' + + + BID + 331 + + + XF + at-f-read-files(7577) + + + BUGTRAQ + 19980805 irix-6.2 "at -f" vulnerability + + + NETBSD + NetBSD-SA1998-004 + + The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail. + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-1410 + 1997-05-09T00:00:00.000-04:00 + 2008-09-05T16:19:27.443-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 330 + + + MISC + ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX + + + BUGTRAQ + 19970509 Re: Irix: misc + + addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file. + + + + + + + + + cpe:/o:debian:debian_linux:2.0 + + CVE-1999-1411 + 1998-11-26T00:00:00.000-05:00 + 2008-09-05T16:19:27.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 316 + + + BUGTRAQ + 19981128 Debian: Security flaw in FSP + + + XF + fsp-anon-ftp-access(7574) + + + BUGTRAQ + 19990217 Debian GNU/Linux 2.0r5 released (fwd) + + + BUGTRAQ + 19981130 Debian: Security flaw in FSP + + + DEBIAN + 19981126 new version of fsp fixes security flaw + + The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp. + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.0 + cpe:/a:apache:http_server + + CVE-1999-1412 + 1999-06-03T00:00:00.000-04:00 + 2008-09-05T16:19:27.740-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990603 MacOS X system panic with CGI + + + BID + 306 + + A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.4::x86 + + CVE-1999-1413 + 1996-08-03T00:00:00.000-04:00 + 2008-09-05T16:19:27.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 296 + + + BUGTRAQ + 19960803 Exploiting Zolaris 2.4 ?? :) + + Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg. + + + + + + + + + cpe:/a:ibm:netfinity_remote_control + + CVE-1999-1414 + 1999-05-25T00:00:00.000-04:00 + 2008-09-05T16:19:28.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NTBUGTRAQ + 19990609 IBM's response to "Security Leak with IBM Netfinity Remote Control Software + + + NTBUGTRAQ + 19990525 Security Leak with IBM Netfinity Remote Control Software + + + BID + 284 + + IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges. + + + + + + + + + cpe:/o:digital:ultrix:4.2 + + CVE-1999-1415 + 1991-08-23T00:00:00.000-04:00 + 2008-09-05T16:19:28.163-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-91.13 + + + BID + 27 + + Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges. + + + + + + + + + cpe:/a:inso:dwhttpd:3.1a4 + + CVE-1999-1416 + 1998-08-23T00:00:00.000-04:00 + 2008-09-10T15:01:54.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 253 + + + BUGTRAQ + 19980823 Solaris ab2 web server is junk + + AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length. + + + + + + + + + cpe:/a:inso:answerbook2 + + CVE-1999-1417 + 1998-08-23T00:00:00.000-04:00 + 2008-09-10T15:01:54.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 253 + + + BUGTRAQ + 19980823 Solaris ab2 web server is junk + + Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged. + + + + + + + + + cpe:/a:mirabilis:icq_web_front + + CVE-1999-1418 + 1999-05-01T00:00:00.000-04:00 + 2008-09-05T16:19:28.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990501 Update: security hole in the ICQ-Webserver + + + BID + 246 + + ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found"). + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.4::x86 + + CVE-1999-1419 + 1997-07-30T00:00:00.000-04:00 + 2008-09-05T16:19:28.740-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 219 + + + SUN + 00148 + + + XF + sun-nisplus-bo(7535) + + Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges. + + + + + + + + + + + + + cpe:/h:n-base:nh2048:1.33 + cpe:/h:n-base:nh3012:2.1 + cpe:/h:n-base:nh2012r:2.53 + cpe:/h:n-base:nh2012:2.53 + cpe:/h:n-base:nh2015:2.51 + + CVE-1999-1420 + 1998-07-20T00:00:00.000-04:00 + 2008-09-10T15:01:54.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 212 + + + BUGTRAQ + 19980722 N-Base Vulnerability Advisory Followup + + + BUGTRAQ + 19980720 N-Base Vulnerability Advisory + + NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration. + + + + + + + + + + cpe:/h:n-base:nh215 + cpe:/h:n-base:nh208 + + CVE-1999-1421 + 1998-07-20T00:00:00.000-04:00 + 2008-09-10T15:01:55.273-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 212 + + + BUGTRAQ + 19980722 N-Base Vulnerability Advisory Followup + + + BUGTRAQ + 19980720 N-Base Vulnerability Advisory + + NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names. + + + + + + + + + + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:slackware:slackware_linux:2.0.35 + + CVE-1999-1422 + 1999-01-02T00:00:00.000-05:00 + 2008-09-05T16:19:29.180-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990102 PATH variable in zip-slackware 2.0.35 + + The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1423 + 1997-06-26T00:00:00.000-04:00 + 2008-09-05T16:19:29.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 209 + + + SUN + 00146 + + + BUGTRAQ + 19971005 Solaris Ping Bug and other [bc] oddities + + + BUGTRAQ + 19970627 SUMMARY: Solaris Ping bug (DoS) + + + BUGTRAQ + 19970626 Solaris Ping bug (DoS) + + + XF + ping-multicast-loopback-dos(7492) + + + BUGTRAQ + 19970627 Solaris Ping bug(inetsvc) + + ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i. + + + + + + + + + + + + cpe:/a:sun:solstice_adminsuite:2.1::x86 + cpe:/a:sun:solstice_adminsuite:2.2::x86 + cpe:/a:sun:solstice_adminsuite:2.2 + cpe:/a:sun:solstice_adminsuite:2.1 + + CVE-1999-1424 + 1997-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:29.477-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 208 + + + SUN + 00145 + + Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries. + + + + + + + + + + + + cpe:/a:sun:solstice_adminsuite:2.1::x86 + cpe:/a:sun:solstice_adminsuite:2.2::x86 + cpe:/a:sun:solstice_adminsuite:2.2 + cpe:/a:sun:solstice_adminsuite:2.1 + + CVE-1999-1425 + 1997-11-10T00:00:00.000-05:00 + 2011-03-07T21:02:06.110-05:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 208 + + + SUN + 00145 + + Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd. + + + + + + + + + + + + cpe:/a:sun:solstice_adminsuite:2.1::x86 + cpe:/a:sun:solstice_adminsuite:2.2::x86 + cpe:/a:sun:solstice_adminsuite:2.2 + cpe:/a:sun:solstice_adminsuite:2.1 + + CVE-1999-1426 + 1997-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:29.773-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 208 + + + SUN + 00145 + + Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files. + + + + + + + + + + + + cpe:/a:sun:solstice_adminsuite:2.1::x86 + cpe:/a:sun:solstice_adminsuite:2.2::x86 + cpe:/a:sun:solstice_adminsuite:2.2 + cpe:/a:sun:solstice_adminsuite:2.1 + + CVE-1999-1427 + 1997-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:29.913-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 208 + + + SUN + 00145 + + Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges. + + + + + + + + + + + + cpe:/a:sun:solstice_adminsuite:2.1::x86 + cpe:/a:sun:solstice_adminsuite:2.2::x86 + cpe:/a:sun:solstice_adminsuite:2.2 + cpe:/a:sun:solstice_adminsuite:2.1 + + CVE-1999-1428 + 1997-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:30.070-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 208 + + + SUN + 00145 + + Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges. + + + + + + + + + cpe:/a:dit:transferpro + + CVE-1999-1429 + 1998-01-05T00:00:00.000-05:00 + 2008-09-05T16:19:30.210-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 204 + + + BUGTRAQ + 19980105 Security flaw in either DIT TransferPro or Solaris + + DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver. + + + + + + + + + cpe:/a:royal:davinci:1.0 + + CVE-1999-1430 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:19:30.350-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 185 + + + BUGTRAQ + 19990102 security problem with Royal daVinci + + PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access. + + + + + + + + + cpe:/a:microsoft:zero_administration_kit:1.0 + + CVE-1999-1431 + 2005-01-07T00:00:00.000-05:00 + 2008-09-05T16:19:30.490-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 181 + + + NTBUGTRAQ + 19990109 WinNT, ZAK and Office 97 + + + NTBUGTRAQ + 19990107 WinNT, ZAK and Office 97 + + ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-1999-1432 + 1998-07-16T00:00:00.000-04:00 + 2008-09-10T15:01:56.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980716 Security risk with powermanagemnet on Solaris 2.6 + + + BID + 160 + + Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges. + + + + + + + + + cpe:/a:hp:jetadmin:rev._d.01.09 + + CVE-1999-1433 + 1998-07-15T00:00:00.000-04:00 + 2008-09-10T15:01:56.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980722 Re: JetAdmin software + + + BUGTRAQ + 19980715 JetAdmin software + + + BID + 157 + + HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file. + + + + + + + + + + + + + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:slackware:slackware_linux:3.5 + cpe:/o:slackware:slackware_linux:3.2 + cpe:/o:slackware:slackware_linux:3.3 + cpe:/o:slackware:slackware_linux:3.1 + + CVE-1999-1434 + 1998-07-13T00:00:00.000-04:00 + 2008-09-10T15:01:56.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980713 Slackware Shadow Insecurity + + + BID + 155 + + login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server. + + + + + + + + + cpe:/a:nec:socks_5:1.0r5 + + CVE-1999-1435 + 1998-07-10T00:00:00.000-04:00 + 2008-09-10T15:01:56.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19980710 socks5 1.0r5 buffer overflow.. + + + BID + 154 + + Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables. + + + + + + + + + cpe:/a:ray_chan:www_authorization_gateway:0.1 + + CVE-1999-1436 + 1998-07-08T00:00:00.000-04:00 + 2008-09-10T15:01:56.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980708 WWW Authorization Gateway + + + BID + 152 + + Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter. + + + + + + + + + cpe:/a:ralf_s._engelschall:eperl:2.2.12 + + CVE-1999-1437 + 1998-07-07T00:00:00.000-04:00 + 2008-09-10T15:01:56.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980710 ePerl Security Update Available + + + BUGTRAQ + 19980707 ePerl: bad handling of ISINDEX queries + + + BID + 151 + + ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml. + + + + + + + + + + + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1438 + 1991-02-22T00:00:00.000-05:00 + 2008-09-05T16:19:31.490-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-01 + + + SUN + 00105 + + + BID + 15 + + Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments. + + + + + + + + + cpe:/a:gcc:gcc:2.7.2 + + CVE-1999-1439 + 1998-01-02T00:00:00.000-05:00 + 2008-09-05T16:19:31.633-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 146 + + + BUGTRAQ + 19980108 GCC Exploit + + + BUGTRAQ + 19980115 GCC 2.7.? /tmp files + + + BUGTRAQ + 19980102 Symlink bug with GCC 2.7.2 + + gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files. + + + + + + + + + cpe:/a:mirabilis:icq_98a:1.30 + + CVE-1999-1440 + 1999-01-01T00:00:00.000-05:00 + 2008-09-05T16:19:31.773-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 132 + + + BUGTRAQ + 19990101 Win32 ICQ 98a flaw + + Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client. + + + + + + + + + cpe:/o:linux:linux_kernel:2.0.34 + + CVE-1999-1441 + 1998-06-30T00:00:00.000-04:00 + 2008-09-05T16:19:31.913-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980630 Serious Linux 2.0.34 security problem + + + BID + 111 + + Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.1.132 + cpe:/o:linux:linux_kernel:2.0.39 + + CVE-1999-1442 + 1998-06-22T00:00:00.000-04:00 + 2008-09-05T16:19:32.053-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 105 + + + MISC + http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html + + + MISC + http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html + + Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments. + + + + + + + + + cpe:/a:micah_software:full_armor + + CVE-1999-1443 + 1998-06-02T00:00:00.000-04:00 + 2008-09-05T16:19:32.193-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 103 + + + BUGTRAQ + 19980602 Full Armor.... Fool Proof etc... bugs + + + BUGTRAQ + 19980609 Full Armor + + Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using <CTRL><ALT><DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting. + + + + + + + + + cpe:/a:computer_software_manufaktur:alibaba:2.0 + + CVE-1999-1444 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:01:57.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://catless.ncl.ac.uk/Risks/20.41.html#subj4 + + genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. + + + + + + + + + + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:slackware:slackware_linux:3.3 + + CVE-1999-1445 + 1998-02-02T00:00:00.000-05:00 + 2008-09-05T16:19:32.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980202 imapd/ipop3d coredump in slackware 3.4 + + Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords. + + + + + + + + + cpe:/a:microsoft:ie:3.0 + + CVE-1999-1446 + 1997-08-05T00:00:00.000-04:00 + 2008-09-05T16:19:32.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19970806 Re: Strange behavior regarding directory + + + NTBUGTRAQ + 19970805 Re: Strange behavior regarding directory + + Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays. + + + + + + + + + cpe:/a:microsoft:ie:4.0 + + CVE-1999-1447 + 1998-07-28T00:00:00.000-04:00 + 2008-09-05T16:19:32.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980728 Object tag crashes Internet Explorer 4.0 + + + BUGTRAQ + 19980730 Re: Object tag crashes Internet Explorer 4.0 + + Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. + + + + + + + + + + cpe:/a:qualcomm:eudora_light:3.05 + cpe:/a:qualcomm:eudora:3.05 + + CVE-1999-1448 + 1998-07-29T00:00:00.000-04:00 + 2008-09-05T16:19:32.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19980729 Eudora exploit (was Microsoft Security Bulletin (MS98-008)) + + Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault. + + + + + + + + + cpe:/o:sun:sunos:4.1.4 + + CVE-1999-1449 + 1997-05-19T00:00:00.000-04:00 + 2008-09-05T16:19:33.037-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html + + + BUGTRAQ + 19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's + + SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device. + + + + + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:unixware:2.1.3 + + CVE-1999-1450 + 1999-01-27T00:00:00.000-05:00 + 2008-09-10T15:01:58.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SCO + SSE020 + + + SCO + SB-99.06b + + + SCO + SB-99.03b + + Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-1451 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:33.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-samples-winmsdp(3271) + + + MS + MS99-013 + + + MSKB + Q231368 + + The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1452 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:33.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 198 + + + MSKB + Q214802 + + + NTBUGTRAQ + 19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS + + + BUGTRAQ + 19990129 ole objects in a "secured" environment? + + + XF + nt-gina-clipboard(1975) + + + NTBUGTRAQ + 19990129 ole objects in a "secured" environment? + + GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. + + + + + + + + + cpe:/a:microsoft:ie:4.0 + + CVE-1999-1453 + 1999-02-02T00:00:00.000-05:00 + 2008-09-05T16:19:33.617-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 215 + + + NTBUGTRAQ + 19990222 New IE4 vulnerability : the clipboard again. + + Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. + + + + + + + + + cpe:/a:macromedia:matrix_screen_saver + + CVE-1999-1454 + 1999-10-04T00:00:00.000-04:00 + 2008-09-05T16:19:33.757-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991004 Weakness In "The Matrix" Screensaver For Windows + + Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1455 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:33.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q158320 + + + XF + nt-rshsvc-ale-bypass(7422) + + RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host. + + + + + + + + + cpe:/a:thttpd:thttpd_http_server:2.03 + + CVE-1999-1456 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:34.037-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + thttpd-file-read(1809) + + + BUGTRAQ + 19980819 thttpd 2.04 released (fwd) + + + CONFIRM + http://www.acme.com/software/thttpd/thttpd.html#releasenotes + + thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename. + + + + + + + + + + + cpe:/a:thttpd:thttpd_http_server:2.04 + cpe:/a:thttpd:thttpd_http_server:1.90a + cpe:/a:thttpd:thttpd_http_server:2.04.31 + + CVE-1999-1457 + 1999-11-16T00:00:00.000-05:00 + 2008-09-10T15:01:58.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SUSE + 19991116 thttpd + + Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function. + + + + + + + + + + + + + + cpe:/o:digital:unix:4.0e + cpe:/o:digital:unix:4.0d + cpe:/o:digital:unix:4.0c + cpe:/o:digital:unix:4.0b + cpe:/o:digital:unix:4.0a + cpe:/o:digital:unix:4.0 + + CVE-1999-1458 + 1999-01-25T00:00:00.000-05:00 + 2008-09-05T16:19:34.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + du-at(3138) + + + BUGTRAQ + 19990125 Digital Unix 4.0 exploitable buffer overflows + + + SCO + SSRT0583U + + Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument. + + + + + + + + + + cpe:/a:bmc:patrol_agent:3.2 + cpe:/a:bmc:patrol_agent:3.2.3 + + CVE-1999-1459 + 1998-11-02T00:00:00.000-05:00 + 2008-09-05T16:19:34.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bmc-patrol-file-create(1388) + + + ISS + 19981102 BMC PATROL File Creation Vulnerability + + + BID + 534 + + BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file. + + + + + + + + + + + + cpe:/a:bmc:patrol_agent:3.2.7 + cpe:/a:bmc:patrol_agent:3.2 + cpe:/a:bmc:patrol_agent:3.2.5 + cpe:/a:bmc:patrol_agent:3.2.3 + + CVE-1999-1460 + 1999-07-13T00:00:00.000-04:00 + 2008-09-05T16:19:34.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 525 + + + BUGTRAQ + 19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?) + + + BUGTRAQ + 19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?) + + BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program. + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + + CVE-1999-1461 + 1997-05-07T00:00:00.000-04:00 + 2008-09-10T15:01:59.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 381 + + + SGI + 20001101-01-I + + + BUGTRAQ + 19970507 Irix: misc + + inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program. + + + + + + + + + + cpe:/a:sean_macguire:big_brother:1.09c + cpe:/a:sean_macguire:big_brother:1.09b + + CVE-1999-1462 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:34.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-bigbrother-bbhist(3755) + + + BID + 142 + + + BUGTRAQ + 19990426 FW: Security Notice: Big Brother 1.09b/c + + + CONFIRM + http://bb4.com/README.CHANGES + + Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attacker to read portions of arbitrary files. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + + CVE-1999-1463 + 1997-07-10T00:00:00.000-04:00 + 2008-09-05T16:19:35.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-frag(528) + + + BUGTRAQ + 19970710 A New Fragmentation Attack + + Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. + + + + + + + + + + cpe:/o:cisco:ios:11.1cc + cpe:/o:cisco:ios:11.1ct + + CVE-1999-1464 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:35.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-acl-leakage(1401) + + + CISCO + 19981105 Cisco IOS DFS Access List Leakage + + + CIAC + J-016 + + Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564. + + + + + + + + + cpe:/o:cisco:ios:11.3 + + CVE-1999-1465 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:35.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-acl-leakage(1401) + + + CISCO + 19981105 Cisco IOS DFS Access List Leakage + + + CIAC + J-016 + + Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862. + + + + + + + + + + + + cpe:/o:cisco:ios:9.1 + cpe:/o:cisco:ios:9.0 + cpe:/o:cisco:ios:8.3 + cpe:/o:cisco:ios:8.2 + + CVE-1999-1466 + 1992-12-10T00:00:00.000-05:00 + 2008-09-05T16:19:35.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1992-20 + + + BID + 53 + + Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword. + + + + + + + + + + + + + cpe:/o:sun:sunos:4.0.1 + cpe:/o:sun:sunos:4.0.2 + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.0.3c + cpe:/o:sun:sunos:4.0 + + CVE-1999-1467 + 1989-10-26T00:00:00.000-04:00 + 2008-09-05T16:19:35.630-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1989-07 + + + XF + sun-rcp(3165) + + + BID + 5 + + Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1psr_a + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sgi:irix:3.3.3 + cpe:/o:sun:sunos:4.1 + cpe:/o:sun:sunos:4.0.3c + cpe:/o:cray:unicos:6.0e + cpe:/o:sgi:irix:4.0 + cpe:/o:sgi:irix:3.3.2 + cpe:/o:sgi:irix:3.3.1 + cpe:/a:next:next:2.0 + cpe:/a:next:next:2.1 + cpe:/o:sun:sunos:4.0.3 + cpe:/o:cray:unicos:6.1 + cpe:/o:cray:unicos:6.0 + cpe:/o:sgi:irix:3.3 + + CVE-1999-1468 + 1991-10-22T00:00:00.000-04:00 + 2008-09-10T15:01:59.960-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-91.20 + + + BID + 31 + + + MISC + http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html + + + OSVDB + 8106 + + + XF + rdist-popen-gain-privileges(7160) + + rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable. + + + + + + + + + cpe:/a:hughes_technologies:w3-auth + + CVE-1999-1469 + 1999-09-30T00:00:00.000-04:00 + 2008-09-05T16:19:35.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19990930 mini-sql Buffer Overflow + + Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header. + + + + + + + + + cpe:/a:eastman_software:work_management:3.2.1 + + CVE-1999-1470 + 1999-06-24T00:00:00.000-04:00 + 2008-09-05T16:19:36.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eastman-cleartext-passwords(2303) + + + BID + 485 + + + NTBUGTRAQ + 19990624 Eastman Software Work Management 3.21 + + Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges. + + + + + + + + + + cpe:/o:bsd:bsd:4.2 + cpe:/o:bsd:bsd:4.3 + + CVE-1999-1471 + 1989-01-01T00:00:00.000-05:00 + 2008-09-05T16:19:36.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1989-01 + + + BID + 4 + + + XF + bsd-passwd-bo(7152) + + Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field. + + + + + + + + + cpe:/a:microsoft:ie:4.0 + + CVE-1999-1472 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:36.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-ie-spy(587) + + + MISC + http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html + + + MSKB + Q176794 + + + MSKB + Q176697 + + + CONFIRM + http://www.microsoft.com/Windows/ie/security/freiburg.asp + + + OSVDB + 7819 + + + BUGTRAQ + 19971017 Security Hole in Explorer 4.0 + + Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. + + + + + + + + + + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + + CVE-1999-1473 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:36.537-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q176697 + + + OSVDB + 7818 + + + XF + ie-page-redirect(7426) + + When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue." + + + + + + + + + + cpe:/a:microsoft:powerpoint:97 + cpe:/a:microsoft:powerpoint:95 + + CVE-1999-1474 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:36.677-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-ppt-patch(179) + + + CONFIRM + http://www.microsoft.com/windows/ie/security/powerpoint.asp + + PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer. + + + + + + + + + cpe:/a:proftpd_project:proftpd:1.2 + + CVE-1999-1475 + 1999-11-19T00:00:00.000-05:00 + 2008-09-05T16:19:36.820-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 812 + + + BUGTRAQ + 19991119 ProFTPd - mod_sqlpw.c + + ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command. + + + + + + + + + + cpe:/h:intel:pentium:::mmx + cpe:/h:intel:pentuim:::overdrive + + CVE-1999-1476 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:36.960-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pentium-crash(704) + + + MSKB + Q163852 + + A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem. + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:gnome:gnome_libs:1.0.8 + + CVE-1999-1477 + 1999-09-23T00:00:00.000-04:00 + 2008-09-05T16:19:37.100-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + gnome-espeaker-local-bo(3349) + + + BID + 663 + + + BUGTRAQ + 19990923 Linux GNOME exploit + + Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1478 + 1999-07-06T00:00:00.000-04:00 + 2008-09-05T16:19:37.240-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sun-hotspot-vm(2348) + + + NTBUGTRAQ + 19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver + + + NTBUGTRAQ + 19990706 Bug in SUN's Hotspot VM + + + BID + 522 + + The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. + + + + + + + + + cpe:/a:matt_wright:textcounter:1.2 + + CVE-1999-1479 + 1998-06-24T00:00:00.000-04:00 + 2008-09-05T16:19:37.397-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-textcounter(2052) + + + BUGTRAQ + 19980624 textcounter.pl SECURITY HOLE + + + BID + 2265 + + The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/o:ibm:aix:4.3 + + CVE-1999-1480 + 1998-06-11T00:00:00.000-04:00 + 2008-09-05T16:19:37.537-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 429 + + (1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack. + + + + + + + + + + + + + cpe:/a:national_science_foundation:squid_web_proxy:2.2 + cpe:/a:national_science_foundation:squid_web_proxy:2.1 + cpe:/a:national_science_foundation:squid_web_proxy:1.0 + cpe:/a:national_science_foundation:squid_web_proxy:1.1 + cpe:/a:national_science_foundation:squid_web_proxy:1.0novm + + CVE-1999-1481 + 1999-12-31T00:00:00.000-05:00 + 2011-03-07T21:02:13.767-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + squid-proxy-auth-access(3433) + + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.2/bugs/ + + + BID + 741 + + + BUGTRAQ + 19991025 [squid] exploit for external authentication problem + + Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair. + + + + + + + + + cpe:/a:svgalib:zgv:3.0.7 + + CVE-1999-1482 + 1999-02-19T00:00:00.000-05:00 + 2008-09-05T16:19:37.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990219 Security hole: "zgv" + + SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes. + + + + + + + + + cpe:/a:svgalib:svgalib:1.2.10 + + CVE-1999-1483 + 1997-06-19T00:00:00.000-04:00 + 2008-09-05T16:19:37.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 19970619 svgalib/zgv + + Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable. + + + + + + + + + cpe:/a:microsoft:msn_setup_bulletin_board_services:4.71.0.10 + + CVE-1999-1484 + 1999-09-24T00:00:00.000-04:00 + 2008-09-05T16:19:38.100-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + msn-setup-bbs-activex-bo(3310) + + + BID + 668 + + + BUGTRAQ + 19990924 Several ActiveX Buffer Overruns + + Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.2 + + CVE-1999-1485 + 1999-05-31T00:00:00.000-04:00 + 2008-09-10T15:02:03.477-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sgi-nsd-create(2247) + + + XF + sgi-nsd-view(2246) + + + BID + 412 + + + OSVDB + 8564 + + + BUGTRAQ + 19990531 IRIX 6.5 nsd virtual filesystem vulnerability + + nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system. + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-1486 + 1998-02-25T00:00:00.000-05:00 + 2008-09-10T15:02:03.790-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 408 + + + CONFIRM + http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info + + + XF + aix-sadc-timex(7675) + + + AIXAPAR + IX76853 + + + AIXAPAR + IX76330 + + + AIXAPAR + IX75554 + + sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:4.1.3 + + CVE-1999-1487 + 1998-01-21T00:00:00.000-05:00 + 2008-09-05T16:19:38.553-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 405 + + + XF + aix-digest(7477) + + + AIXAPAR + IX74599 + + Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system. + + + + + + + + + cpe:/a:ibm:system_data_repository:sp_2.0 + + CVE-1999-1488 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:38.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 371 + + + CIAC + I-079A + + + XF + ibm-sdr-read-files(7217) + + sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication. + + + + + + + + + cpe:/o:slackware:slackware_linux:3.1 + + CVE-1999-1489 + 1997-03-04T00:00:00.000-05:00 + 2008-09-05T16:19:38.850-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 364 + + + BUGTRAQ + 19970304 Linux SuperProbe exploit + + Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument. + + + + + + + + + cpe:/o:redhat:linux:5.1 + + CVE-1999-1490 + 1998-05-28T00:00:00.000-04:00 + 2008-09-05T16:19:38.990-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 362 + + + BUGTRAQ + 19980528 ALERT: Tiresome security hole in "xosview", RedHat5.1? + + + XF + linux-xosview-bo(8787) + + + BUGTRAQ + 19980529 Re: Tiresome security hole in "xosview" (xosexp.c) + + xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable. + + + + + + + + + cpe:/o:redhat:linux:2.1 + + CVE-1999-1491 + 1996-02-02T00:00:00.000-05:00 + 2008-09-05T16:19:39.130-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 354 + + + BUGTRAQ + 19960202 abuse Red Hat 2.1 security hole + + abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program. + + + + + + + + + cpe:/o:sgi:irix:6.4 + + CVE-1999-1492 + 1998-05-27T00:00:00.000-04:00 + 2008-09-05T16:19:39.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sgi-diskalign(2104) + + + XF + sgi-diskperf(2103) + + + BID + 348 + + + SGI + 19980502-01-P3030 + + Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges. + + + + + + + + + cpe:/o:hp:apollo_domain_os:sr10.3 + + CVE-1999-1493 + 1991-12-18T00:00:00.000-05:00 + 2008-09-05T16:19:39.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1991-23 + + + XF + apollo-crp-root-access(7158) + + + BID + 34 + + Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk(). + + + + + + + + + + + + + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:5.1.1 + + CVE-1999-1494 + 1994-08-09T00:00:00.000-04:00 + 2008-09-05T16:19:39.553-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sgi-colorview(2112) + + + BUGTRAQ + 19950307 sigh. another Irix 5.2 hole. + + + BID + 336 + + + SGI + 19950209-00-P + + + BUGTRAQ + 19940809 Re: IRIX 5.2 Security Advisory + + colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument. + + + + + + + + + cpe:/o:suse:suse_linux:6.0 + + CVE-1999-1495 + 1999-02-18T00:00:00.000-05:00 + 2008-09-05T16:19:39.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xtvscreen-overwrite(1792) + + + BID + 325 + + + BUGTRAQ + 19990218 xtvscreen and suse 6 + + xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file. + + + + + + + + + + + + + + + cpe:/a:todd_miller:sudo:1.5 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:redhat:linux:6.0 + + CVE-1999-1496 + 1999-06-08T00:00:00.000-04:00 + 2008-09-05T16:19:39.850-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sudo-file-exists(2277) + + + BID + 321 + + + BUGTRAQ + 19990608 unneeded information in sudo + + Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist. + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:5.0.8 + cpe:/a:ipswitch:imail:5.0 + cpe:/a:ipswitch:imail:5.0.5 + cpe:/a:ipswitch:imail:6.0 + cpe:/a:ipswitch:imail:5.0.6 + cpe:/a:ipswitch:imail:5.0.7 + + CVE-1999-1497 + 1999-12-21T00:00:00.000-05:00 + 2008-09-05T16:19:39.990-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 880 + + + BUGTRAQ + 19991221 [w00giving '99 #11] IMail's password encryption scheme + + Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts. + + + + + + + + + cpe:/o:slackware:slackware_linux:3.4 + + CVE-1999-1498 + 1998-04-06T00:00:00.000-04:00 + 2008-09-05T16:19:40.147-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 82 + + Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file. + + + + + + + + + + cpe:/a:isc:bind:4.9 + cpe:/a:isc:bind:8.1 + + CVE-1999-1499 + 1998-04-10T00:00:00.000-04:00 + 2008-09-05T16:19:40.287-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 80 + + + BUGTRAQ + 19980410 BIND 4.9.7 named follows symlinks, clobbers anything + + named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used. + + + + + + + + + cpe:/a:true_north:internet_anywhere_mail_server:2.3 + + CVE-1999-1500 + 1999-10-01T00:00:00.000-04:00 + 2008-09-05T16:19:40.427-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 733 + + + NTBUGTRAQ + 19991001 Vulnerabilities in the Internet Anywhere Mail Server + + Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments. + + + + + + + + + cpe:/o:sgi:irix:6.3 + + CVE-1999-1501 + 1998-04-08T00:00:00.000-04:00 + 2008-09-10T15:02:04.993-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 71 + + + BID + 70 + + + BUGTRAQ + 19980408 SGI O2 ipx security issue + + (1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands. + + + + + + + + + cpe:/a:id_software:quake:1.9 + + CVE-1999-1502 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:19:40.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 69 + + + BID + 68 + + + BUGTRAQ + 19980408 QuakeI client: serious holes. + + Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command. + + + + + + + + + + cpe:/a:nfr:nfr:1.5 + cpe:/a:nfr:nfr:1.6 + + CVE-1999-1503 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:19:40.850-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 63 + + Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field. + + + + + + + + + cpe:/a:stalker:stalker_internet_mail_server:1.6 + + CVE-1999-1504 + 1998-04-08T00:00:00.000-04:00 + 2008-09-05T16:19:40.990-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 62 + + + BUGTRAQ + 19980408 Re: AppleShare IP Mail Server + + Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command. + + + + + + + + + cpe:/a:id_software:quakeworld:2.10 + + CVE-1999-1505 + 1998-04-07T00:00:00.000-04:00 + 2008-09-05T16:19:41.130-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 60 + + + BUGTRAQ + 19980407 QW vulnerability + + Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet. + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.0.1 + cpe:/o:sun:sunos:3.5 + cpe:/o:sun:sunos:4.0.2 + cpe:/o:sun:sunos:4.0.3 + cpe:/o:sun:sunos:4.0.3c + cpe:/o:sun:sunos:4.0 + + CVE-1999-1506 + 1990-01-29T00:00:00.000-05:00 + 2008-09-05T16:19:41.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1990-01 + + + BID + 6 + + Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin. + + + + + + + + + + + + + + + cpe:/o:sun:sunos:4.1psr_a + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:sunos:4.1.2 + cpe:/o:sun:sunos:4.1 + + CVE-1999-1507 + 1993-02-03T00:00:00.000-05:00 + 2008-09-05T16:19:41.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1993-03 + + + BID + 59 + + + XF + sun-dir(521) + + Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash. + + + + + + + + + + + + + cpe:/h:tek:phaser_network_printer_740 + cpe:/h:tek:phaser_network_printer_750dp + cpe:/h:tek:phaser_network_printer_930 + cpe:/h:tek:phaser_network_printer_750 + cpe:/h:tek:phaser_network_printer_840 + + CVE-1999-1508 + 1999-11-16T00:00:00.000-05:00 + 2008-09-05T16:19:41.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 806 + + + BUGTRAQ + 19991116 [Fwd: Printer Vulnerability: Tektronix PhaserLink Webserver gives Administrator Password] + + Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html. + + + + + + + + + cpe:/a:etype:eserv:2.50 + + CVE-1999-1509 + 1999-11-04T00:00:00.000-05:00 + 2008-09-05T16:19:41.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 773 + + + BUGTRAQ + 19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability + + + NTBUGTRAQ + 19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability + + Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL. + + + + + + + + + cpe:/a:bisonware:bisonware_ftp_server:4.1 + + CVE-1999-1510 + 1999-05-17T00:00:00.000-04:00 + 2008-09-05T16:19:41.850-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bisonware-command-bo(3234) + + + NTBUGTRAQ + 19990517 Vulnerabilities in BisonWare FTP Server 3.5 + + Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands. + + + + + + + + + cpe:/a:artisoft:xtramail:1.11 + + CVE-1999-1511 + 1999-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:41.990-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xtramail-pass-dos(3488) + + + BID + 791 + + + BUGTRAQ + 19991110 Multiples Remotes DoS Attacks in Artisoft XtraMail v1.11 Vulnerability + + Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service. + + + + + + + + + cpe:/a:amavis:virus_scanner:0.2_pre4 + + CVE-1999-1512 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:42.130-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + amavis-command-execute(2349) + + + BID + 527 + + + CONFIRM + http://www.amavis.org/ChangeLog.txt + + + BUGTRAQ + 19990716 AMaViS virus scanner for Linux - root exploit + + The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field. + + + + + + + + + cpe:/h:3com:superstack_ii_hub:2.10 + + CVE-1999-1513 + 1999-08-30T00:00:00.000-04:00 + 2008-09-05T16:19:42.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990830 One more 3Com SNMP vulnerability + + Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities. + + + + + + + + + cpe:/a:celtech_software:expressfs:2.6 + + CVE-1999-1514 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:19:42.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + expressfs-command-bo(3401) + + + BID + 749 + + + BUGTRAQ + 19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability + + + NTBUGTRAQ + 19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability + + Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command. + + + + + + + + + cpe:/a:tenfour:tfs_gateway:4.0 + + CVE-1999-1515 + 1999-08-31T00:00:00.000-04:00 + 2008-09-05T16:19:42.553-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tfs-gateway-dos(3290) + + + BID + 613 + + A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds. + + + + + + + + + cpe:/a:tenfour:tfs_gateway_smtp:3.2 + + CVE-1999-1516 + 1999-09-02T00:00:00.000-04:00 + 2008-09-05T16:19:42.693-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990902 [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow + + A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string. + + + + + + + + + cpe:/o:freebsd:freebsd:3.3 + + CVE-1999-1517 + 1999-11-01T00:00:00.000-05:00 + 2008-09-05T16:19:42.850-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 750 + + + BUGTRAQ + 19991101 Amanda multiple vendor local root compromises + + runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:netbsd:netbsd:1.4::x86 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + + CVE-1999-1518 + 1999-07-15T00:00:00.000-04:00 + 2008-09-05T16:19:42.990-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-shared-memory-dos(2351) + + + BID + 526 + + + BUGTRAQ + 19990715 Shared memory DoS's + + Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults. + + + + + + + + + cpe:/a:gene6:g6_ftp_server:2.0 + + CVE-1999-1519 + 1999-11-17T00:00:00.000-05:00 + 2008-09-05T16:19:43.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + g6ftp-username-dos(3513) + + + BID + 805 + + + BUGTRAQ + 19991117 Remote D.o.S Attack in G6 FTP Server v2.0 (beta 4/5) Vulnerability + + Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password. + + + + + + + + + cpe:/a:microsoft:site_server:3.0 + + CVE-1999-1520 + 1999-05-11T00:00:00.000-04:00 + 2008-09-05T16:19:43.317-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + siteserver-site-csc(2270) + + + BID + 256 + + + BUGTRAQ + 19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs + + A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. + + + + + + + + + + cpe:/a:computalynx:cmail:2.4 + cpe:/a:computalynx:cmail:2.3sp2 + + CVE-1999-1521 + 1999-09-12T00:00:00.000-04:00 + 2008-09-05T16:19:43.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cmail-command-bo(2240) + + + BID + 633 + + + BUGTRAQ + 19990729 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer + + + BUGTRAQ + 19990912 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug + + Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server. + + + + + + + + + cpe:/a:roxen:roxen_web_server:1.3.11 + + CVE-1999-1522 + 1999-10-07T00:00:00.000-04:00 + 2008-09-05T16:19:43.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991007 Roxen security alert + + Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML. + + + + + + + + + + cpe:/a:sambar:sambar_server:4.2.1 + cpe:/a:sambar:sambar_server + + CVE-1999-1523 + 1999-10-04T00:00:00.000-04:00 + 2008-09-05T16:19:43.740-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sambar-logging-bo(1672) + + + BUGTRAQ + 19991006 Re: Sample DOS against the Sambar HTTP-Server + + + BUGTRAQ + 19991004 + + Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request. + + + + + + + + + cpe:/h:flowpoint:flowpoint_dsl_router:3.0.8 + + CVE-1999-1524 + 1999-08-07T00:00:00.000-04:00 + 2008-09-05T16:19:43.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990807 Re: FlowPoint DSL router vulnerability + + FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port. + + + + + + + + + cpe:/a:macromedia:shockwave_flash_plugin:6.0 + + CVE-1999-1525 + 1997-03-14T00:00:00.000-05:00 + 2008-09-05T16:19:44.023-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + http-ns-shockwave(460) + + + XF + shockwave-file-read-vuln(1586) + + + XF + shockwave-internal-access(1585) + + + BUGTRAQ + 19970314 Shockwave Security Alert + + Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie. + + + + + + + + + cpe:/a:macromedia:shockwave_flash_plugin:7.0 + + CVE-1999-1526 + 1999-03-11T00:00:00.000-05:00 + 2008-09-05T16:19:44.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + shockwave-updater(1931) + + + BUGTRAQ + 19990311 [Fwd: Shockwave 7 Security Hole] + + Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia. + + + + + + + + + + cpe:/a:sun:forte:community_1.0_beta + cpe:/a:sun:netbeans_developer:3.0_beta + + CVE-1999-1527 + 1999-11-23T00:00:00.000-05:00 + 2008-09-05T16:19:44.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 816 + + + BUGTRAQ + 19991123 NetBeans/ Forte' Java IDE HTTP vulnerability + + Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server. + + + + + + + + + cpe:/a:prosoft_engineering:netware_client:5.12 + + CVE-1999-1528 + 1999-11-14T00:00:00.000-05:00 + 2008-09-05T16:19:44.460-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 794 + + + BUGTRAQ + 19991114 MacOS 9 and the MacOS Netware Client + + ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.3 + cpe:/a:trend_micro:interscan_viruswall:3.23 + + CVE-1999-1529 + 1999-11-07T00:00:00.000-05:00 + 2008-09-05T16:19:44.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + viruswall-helo-bo(3465) + + + BID + 787 + + + NTBUGTRAQ + 19991108 Patch for VirusWall 3.23. + + + BUGTRAQ + 20000417 New DOS on Interscan NT/3.32 + + + BUGTRAQ + 19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow + + + NTBUGTRAQ + 19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow. + + + BUGTRAQ + 19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow. + + + BUGTRAQ + 19991108 Patch for VirusWall 3.23. + + A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code. + + + + + + + + + + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-1999-1530 + 1999-11-08T00:00:00.000-05:00 + 2008-09-05T16:19:44.740-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 777 + + + BUGTRAQ + 19991109 [Cobalt] Security Advisory - cgiwrap + + + BUGTRAQ + 19991108 Security flaw in Cobalt RaQ2 cgiwrap + + + OSVDB + 35 + + + XF + cobalt-cgiwrap-incorrect-permissions(7764) + + cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system. + + + + + + + + + cpe:/a:ibm:homepageprint:1.0.7 + + CVE-1999-1531 + 1999-11-02T00:00:00.000-05:00 + 2008-09-05T16:19:44.880-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 763 + + + BUGTRAQ + 19991102 Some holes for Win/UNIX softwares + + + XF + ibm-homepageprint-bo(7767) + + Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag. + + + + + + + + + + + cpe:/a:netscape:messaging_server:3.55 + cpe:/a:netscape:messaging_server:3.6 + cpe:/a:netscape:messaging_server:3.54 + + CVE-1999-1532 + 1999-10-29T00:00:00.000-04:00 + 2008-09-05T16:19:45.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 748 + + + BUGTRAQ + 19991029 message:Netscape Messaging Server RCPT TO vul. + + Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.3 + cpe:/a:trend_micro:interscan_viruswall:3.2.3 + + CVE-1999-1533 + 1999-11-07T00:00:00.000-05:00 + 2008-09-10T15:02:08.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + diva-lan-isdn-dos(3317) + + + BID + 665 + + + BUGTRAQ + 19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem + + Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service. + + + + + + + + + cpe:/a:knox_software:arkeia:4.0 + + CVE-1999-1534 + 1999-09-23T00:00:00.000-04:00 + 2008-09-05T16:19:45.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 661 + + + BUGTRAQ + 19990923 Multiple vendor Knox Arkiea local root/remote DoS + + Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable. + + + + + + + + + cpe:/a:persits:aspupload:1.4.0.2 + + CVE-1999-1535 + 1999-07-20T00:00:00.000-04:00 + 2008-09-05T16:19:45.443-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-aspupload-bo(3291) + + + NTBUGTRAQ + 19990818 AspUpload Buffer Overflow Fixed + + + BID + 592 + + + NTBUGTRAQ + 19990720 Buffer overflow in AspUpload 1.4 + + Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request. + + + + + + + + + cpe:/a:acushop:salesbuilder:2.6 + + CVE-1999-1536 + 1999-07-30T00:00:00.000-04:00 + 2008-09-05T16:19:45.600-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990730 World writable root owned script in SalesBuilder (RedHat 6.0) + + + BID + 560 + + + OSVDB + 13557 + + .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1537 + 1999-07-07T00:00:00.000-04:00 + 2008-09-05T16:19:45.740-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 521 + + + XF + ssl-iis-dos(2352) + + + NTBUGTRAQ + 19990707 SSL and IIS. + + IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1538 + 1999-01-14T00:00:00.000-05:00 + 2008-09-05T16:19:45.880-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19990114 MS IIS 4.0 Security Advisory + + + BUGTRAQ + 19990114 MS IIS 4.0 Security Advisory + + + BID + 189 + + When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. + + + + + + + + + + + cpe:/a:qpc_software:qvt_term_plus:4.2d + cpe:/a:qpc_software:qvt_net:4.3 + cpe:/a:qpc_software:qvt_term_plus:4.3 + + CVE-1999-1539 + 1999-11-10T00:00:00.000-05:00 + 2008-09-05T16:19:46.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qvtterm-login-dos(3491) + + + BID + 796 + + + NTBUGTRAQ + 19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability + + + BUGTRAQ + 19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability + + Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password. + + + + + + + + + cpe:/a:cactus_software:shell-lock + + CVE-1999-1540 + 1999-10-04T00:00:00.000-04:00 + 2008-09-05T16:19:46.163-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cactus-shell-lock-retrieve-shell-code(3356) + + + L0PHT + 19991004 + + + BUGTRAQ + 19991005 Cactus Software's shell-lock + + shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code. + + + + + + + + + cpe:/a:cactus_software:shell-lock + + CVE-1999-1541 + 1999-10-04T00:00:00.000-04:00 + 2008-09-05T16:19:46.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cactus-shell-lock-root-privs(3358) + + + L0PHT + 19991004 + + + BUGTRAQ + 19991005 Cactus Software's shell-lock + + shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-1999-1542 + 1999-10-04T00:00:00.000-04:00 + 2008-09-05T16:19:46.443-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-rh-rpmmail(3353) + + + BUGTRAQ + 19991006 Fwd: [Re: RH6.0 local/remote command execution] + + + BUGTRAQ + 19991004 RH6.0 local/remote command execution + + RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command. + + + + + + + + + + + + + + + cpe:/o:apple:mac_os:7.6 + cpe:/o:apple:mac_os:7.6.1 + cpe:/o:apple:mac_os:7.5.3 + cpe:/o:apple:mac_os:8.6 + cpe:/o:apple:mac_os:8.5 + cpe:/o:apple:mac_os:8.1 + cpe:/o:apple:mac_os:8.0 + + CVE-1999-1543 + 1999-07-10T00:00:00.000-04:00 + 2008-09-05T16:19:46.583-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 519 + + + BUGTRAQ + 19990914 MacOS system encryption algorithm 3 + + + BUGTRAQ + 19990710 MacOS system encryption algorithm + + MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-1999-1544 + 1999-01-24T00:00:00.000-05:00 + 2008-09-05T16:19:46.740-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990124 Advisory: IIS FTP Exploit/DoS Attack + + Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. + + + + + + + + + cpe:/a:joes_own_editor:joe:2.8 + + CVE-1999-1545 + 1999-07-14T00:00:00.000-04:00 + 2008-09-05T16:19:46.880-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990717 joe 2.8 makes world-readable DEADJOE + + + BUGTRAQ + 19990714 + + Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users. + + + + + + + + + cpe:/a:ibm:navio_nc_browser:1.1.0.1 + + CVE-1999-1546 + 1999-01-29T00:00:00.000-05:00 + 2008-09-05T16:19:47.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + navionc-config-script(1724) + + + BUGTRAQ + 19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1 + + netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable. + + + + + + + + + cpe:/a:oracle:web_listener:2.1 + + CVE-1999-1547 + 1999-11-25T00:00:00.000-05:00 + 2008-09-05T16:19:47.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 841 + + + NTBUGTRAQ + 19991125 Oracle Web Listener + + + BUGTRAQ + 19991125 Oracle Web Listener + + Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent. + + + + + + + + + cpe:/h:cabletron:smartswitch_router_8000_firmware:2.0 + + CVE-1999-1548 + 1999-11-24T00:00:00.000-05:00 + 2008-09-05T16:19:47.303-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BINDVIEW + 19991124 Cabletron SmartSwitch Router 8000 Firmware v2.x + + + BID + 821 + + Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit. + + + + + + + + + + cpe:/a:university_of_kansas:lynx:2.7 + cpe:/a:university_of_kansas:lynx:2.8 + + CVE-1999-1549 + 1999-11-16T00:00:00.000-05:00 + 2008-09-05T16:19:47.443-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 804 + + + BUGTRAQ + 19991116 lynx 2.8.x - 'special URLs' anti-spoofing protection is weak + + Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands. + + + + + + + + + cpe:/a:f5:big-ip:2.0 + + CVE-1999-1550 + 1999-11-08T00:00:00.000-05:00 + 2008-09-05T16:19:47.583-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991109 + + + BID + 778 + + + BUGTRAQ + 19991109 Re: BigIP - bigconf.cgi holes + + + BUGTRAQ + 19991108 BigIP - bigconf.cgi holes + + + XF + bigip-bigconf-view-files(7771) + + bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter. + + + + + + + + + + cpe:/a:ipswitch:imail:5.0 + cpe:/a:ipswitch:imail:6.0 + + CVE-1999-1551 + 1999-03-02T00:00:00.000-05:00 + 2008-09-05T16:19:47.723-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 505 + + + XF + imail-websvc-overflow(1898) + + + BUGTRAQ + 19990302 Multiple IMail Vulnerabilites + + Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL. + + + + + + + + + + + + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-1552 + 1994-07-20T00:00:00.000-04:00 + 2008-09-10T15:02:10.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 358 + + + BUGTRAQ + 19940720 xnews and XDM + + dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges. + + + + + + + + + cpe:/a:xcmail:xcmail:0.99.6 + + CVE-1999-1553 + 1999-05-01T00:00:00.000-04:00 + 2008-09-05T16:19:48.020-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xcmail-reply-overflow(1859) + + + BID + 311 + + + BUGTRAQ + 19990301 [0z0n3] XCmail remotely exploitable vulnerability + + Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line. + + + + + + + + + + cpe:/o:sgi:irix:3.3.1 + cpe:/o:sgi:irix:3.3 + + CVE-1999-1554 + 1990-10-31T00:00:00.000-05:00 + 2008-09-05T16:19:48.163-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-1990-08 + + + BID + 13 + + + XF + sgi-irix-reset(3164) + + /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users. + + + + + + + + + cpe:/a:cheyenne:inoculan_anti-virus_server:4.0 + + CVE-1999-1555 + 1998-06-11T00:00:00.000-04:00 + 2008-09-05T16:19:48.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + inoculan-bad-permissions(1536) + + + BUGTRAQ + 19980611 Cheyenne Inoculan vulnerability on NT + + Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll. + + + + + + + + + cpe:/a:microsoft:sql_server:6.5 + + CVE-1999-1556 + 1998-06-29T00:00:00.000-04:00 + 2008-09-05T16:19:48.443-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + mssql-sqlexecutivecmdexec-password(7354) + + + BID + 109 + + + NTBUGTRAQ + 19980629 MS SQL Server 6.5 stores password in unprotected registry keys + + Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value. + + + + + + + + + cpe:/a:ipswitch:imail:5.0 + + CVE-1999-1557 + 2005-05-02T00:00:00.000-04:00 + 2008-09-05T16:19:48.583-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + imail-imap-overflow(1895) + + + BUGTRAQ + 19990301 Multiple IMail Vulnerabilites + + Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password. + + + + + + + + + + cpe:/a:digital:digital_openvms:7.1 + cpe:/a:digital:digital_openvms_axp:7.1 + + CVE-1999-1558 + 1998-07-16T00:00:00.000-04:00 + 2008-09-05T16:19:48.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 161 + + + CIAC + I-071A + + + XF + openvms-loginout-unauth-access(7151) + + Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled. + + + + + + + + + cpe:/h:alcatel:omniswitch:3.2.4 + + CVE-1999-1559 + 1999-03-31T00:00:00.000-05:00 + 2008-09-05T16:19:48.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xylan-omniswitch-login(2064) + + + BUGTRAQ + 19990331 Xylan OmniSwitch "features" + + Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time. + + + + + + + + + cpe:/a:tamu:tiger + + CVE-1999-1560 + 1999-07-20T00:00:00.000-04:00 + 2008-09-05T16:19:49.020-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + tiger-script-execute(2369) + + + BUGTRAQ + 19990720 tiger vulnerability + + Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root. + + + + + + + + + cpe:/a:nullsoft:shoutcast_server:1.9.7::win32 + + CVE-1999-1561 + 1999-08-20T00:00:00.000-04:00 + 2008-09-05T16:19:49.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990820 Winamp SHOUTcast server: Gain Administrator Password + + Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server. + + + + + + + + + + cpe:/a:gftp:ftp_client:2.0.0 + cpe:/a:gftp:ftp_client:1.13 + + CVE-1999-1562 + 1999-09-05T00:00:00.000-04:00 + 2008-09-05T16:19:49.303-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 19990905 gftp + + + BID + 3446 + + + DEBIAN + DSA-084 + + gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file. + + + + + + + + + + cpe:/h:nachuatec:d435 + cpe:/h:nachuatec:d445 + + CVE-1999-1563 + 2000-10-14T00:00:00.000-04:00 + 2008-09-05T16:19:49.443-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19991116 NEUROCOM: Nashuatec D445/435 vulnerabilities updated + + + BUGTRAQ + 19991014 NEUROCOM: Nashuatec printer, 3 vulnerabilities found + + Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm. + + + + + + + + + cpe:/o:freebsd:freebsd:3.2 + + CVE-1999-1564 + 1999-09-02T00:00:00.000-04:00 + 2008-09-05T16:19:49.583-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990902 [ Kernel panic with FreeBSD-3.2-19990830-STABLE ] + + FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes. + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + cpe:/a:earl_hood:man2html:2.1 + + CVE-1999-1565 + 1999-08-20T00:00:00.000-04:00 + 2008-09-05T16:19:49.723-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990820 [SECURITY] New versions of man2html fixes postinst glitch + + + OSVDB + 6291 + + Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:intel:iparty:1.2 + + CVE-1999-1566 + 1999-05-08T00:00:00.000-04:00 + 2008-09-05T16:19:49.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990508 iParty Daemon Vulnerability w/ Exploit Code (worse than thought?) + + Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters. + + + + + + + + + cpe:/a:seapine_software:testtrack + + CVE-1999-1567 + 1999-03-08T00:00:00.000-05:00 + 2008-09-05T16:19:50.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + testtrack-dos(1948) + + Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data. + + + + + + + + + cpe:/a:ncftpd:ncftpd_ftp_server:2.4.0 + + CVE-1999-1568 + 1999-01-01T00:00:00.000-05:00 + 2008-09-10T15:02:11.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BUGTRAQ + 19990223 NcFTPd remote buffer overflow + + + XF + ncftpd-port-bo(1833) + + + BUGTRAQ + 19990223 Comments on NcFTPd "theoretical root compromise" + + Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. + + + + + + + + + cpe:/a:id_software:quake:1.9 + + CVE-1999-1569 + 2001-07-17T00:00:00.000-04:00 + 2008-09-05T16:19:50.303-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + quake-spoofed-client-dos(6871) + + + BID + 3051 + + + BUGTRAQ + 20010716 Quake client and server denial-of-service + + + BUGTRAQ + 19981101 Quake problem? + + + BUGTRAQ + 19980502 NetQuake Protocol problem resulting in smurf like effect. + + Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit. + + + + + + + + + cpe:/a:caldera:openserver:5.0.5 + + CVE-1999-1570 + 2002-05-01T00:00:00.000-04:00 + 2008-09-05T16:19:50.443-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4089 + + + XF + openserver-sar-bo(8989) + + + CALDERA + CSSA-2002-SCO.17 + + + BUGTRAQ + 19990909 19 SCO 5.0.5+Skunware98 buffer overflows + + + VULN-DEV + 20020509 Sar -o exploitation process info. + + Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter. + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.0 + + CVE-1999-1571 + 1999-11-04T00:00:00.000-05:00 + 2008-09-10T15:02:12.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://online.securityfocus.com/advisories/1843 + + + XF + openserver-sar-bo(8989) + + + BUGTRAQ + 19990909 19 SCO 5.0.5+Skunware98 buffer overflows + + + BUGTRAQ + 19990917 Re: recent SCO 5.0.x vulnerabilities + + + CONFIRM + ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr + + + SCO + SB-99.17c + + + BID + 643 + + + VULN-DEV + 20020509 Sar -o exploitation process info. + + + BUGTRAQ + 19991105 SCO Security Bulletin 99.17 + + + BUGTRAQ + 19991020 Re: recent SCO 5.0.x vulnerabilities + + Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570. + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:enterprise_linux:4.0::advanced_server + cpe:/o:mandrakesoft:mandrake_linux:10.0 + cpe:/o:mandrakesoft:mandrake_linux:10.1 + cpe:/o:mandrakesoft:mandrake_linux:cs3.0 + cpe:/o:redhat:enterprise_linux_desktop:4.0 + cpe:/o:ubuntu:ubuntu_linux:4.10 + cpe:/o:redhat:enterprise_linux:4.0::enterprise_server + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:mandrakesoft:mandrake_linux:cs2.1 + cpe:/o:debian:debian_linux:3.0 + cpe:/o:mandrakesoft:mandrake_linux:9.2 + cpe:/o:redhat:enterprise_linux:4.0::workstation + + CVE-1999-1572 + 1996-07-16T00:00:00.000-04:00 + 2010-08-21T00:02:40.937-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + cpio-o-archive-insecure-permissions(19167) + + + TRUSTIX + 2005-0003 + + + REDHAT + RHSA-2005:080 + + + REDHAT + RHSA-2005:073 + + + MISC + http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391 + + + DEBIAN + DSA-664 + + + REDHAT + RHSA-2005:806 + + + MANDRAKE + MDKSA-2005:032 + + + CONFIRM + http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf + + + BUGTRAQ + 20050204 [USN-75-1] cpio vulnerability + + + + + cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.30 + + CVE-1999-1573 + 1999-12-28T00:00:00.000-05:00 + 2009-03-04T00:03:12.593-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#13217 + + + HP + HPSBUX9812-090 + + + CIAC + J-022 + + + AUSCERT + ESB-98.186 + + + XF + hp-rcmnds-gain-privileges(7860) + + + + + Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files. + + + + + + + + + cpe:/o:ibm:aix:4.3.0 + + CVE-1999-1574 + 1998-07-06T00:00:00.000-04:00 + 2008-09-05T16:19:51.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#182777 + + + XF + aix-nslookup-lex-bo(7867) + + + AIXAPAR + IX79909 + + Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings." + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1575 + 1999-09-10T00:00:00.000-04:00 + 2008-09-05T16:19:51.177-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#9162 + + + CERT-VN + VU#41408 + + + CERT-VN + VU#26924 + + + CERT-VN + VU#24839 + + + CERT-VN + VU#23412 + + + XF + wang-kodak-activex-control(7097) + + + BUGTRAQ + 19990924 Several ActiveX Buffer Overruns + + + MS + MS99-037 + + The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands. + + + + + + + + + cpe:/a:adobe:acrobat_reader:4.0 + + CVE-1999-1576 + 1999-09-27T00:00:00.000-04:00 + 2008-09-05T16:19:51.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#25919 + + + XF + adobe-acrobat-pdf-bo(3318) + + + BID + 666 + + + BUGTRAQ + 19990924 Several ActiveX Buffer Overruns + + Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1577 + 1999-10-31T00:00:00.000-04:00 + 2008-09-05T16:19:51.473-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#29795 + + + XF + ie-hhopen-bo(3314) + + + BID + 669 + + + BUGTRAQ + 19990924 Several ActiveX Buffer Overruns + + Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0.1 + + CVE-1999-1578 + 1999-09-24T00:00:00.000-04:00 + 2008-09-05T16:19:51.617-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#37556 + + + BID + 671 + + + XF + ie-registration-wiz-bo(3311) + + + BUGTRAQ + 19990924 Several ActiveX Buffer Overruns + + Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1579 + 2000-12-14T00:00:00.000-05:00 + 2008-09-10T15:02:15.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#3062 + + + XF + winnt-xenroll-dos(7107) + + + BID + 6827 + + + MSKB + Q242366 + + The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:5.59 + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.4jl + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.4 + cpe:/a:sendmail:sendmail:5.61 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.3u1 + cpe:/o:sun:sunos:4.1.2 + cpe:/a:sendmail:sendmail:5.65 + + CVE-1999-1580 + 1995-08-23T00:00:00.000-04:00 + 2008-09-05T16:19:51.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1995-11 + + + CERT-VN + VU#3278 + + + BID + 7829 + + + AUSCERT + AA-95.09 + + + MISC + http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html + + SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-1999-1581 + 1997-12-23T00:00:00.000-05:00 + 2008-09-05T16:19:52.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#4923 + + + XF + winnt-snmp-oid-memory-leak(8231) + + + MSKB + Q178381 + + Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded. + + + + + + + + + cpe:/a:cisco:pix_firewall + + CVE-1999-1582 + 1998-07-15T00:00:00.000-04:00 + 2008-09-05T16:19:52.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#6733 + + + XF + cisco-pix-established-bypass(8052) + + + CISCO + 19980715 PIX Firewall "established" Command + + By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality. + + + + + + + + + cpe:/o:ibm:aix:4.3 + + CVE-1999-1583 + 1999-09-30T00:00:00.000-04:00 + 2008-09-05T16:19:52.350-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#872443 + + + AIXAPAR + IY02120 + + + XF + aix-nslookup-hostname-bo(8031) + + Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument. + + + + + + + + + + + + + + + + + cpe:/a:sun:openwindows:3.0 + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + + CVE-1999-1584 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:52.490-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-10-04T08:47:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-93.18 + + + SUN + 00124 + + Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586. + + + + + + + + + cpe:/o:sun:solaris:2.0 + + CVE-1999-1585 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:52.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-10-04T08:57:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + SUN + 00124 + + The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges. + + + + + + + + + + + + cpe:/o:sun:sunos:4.1.3c + cpe:/o:sun:sunos:4.1.3 + cpe:/o:sun:sunos:4.1.1 + cpe:/o:sun:sunos:4.1.2 + + CVE-1999-1586 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:52.787-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-10-04T09:01:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-95.12 + + + XF + sun-loadmodule(498) + + + CIAC + G-02 + + loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584. + + + + + + + + + + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:9.0::sparc + + CVE-1999-1587 + 1996-08-30T00:00:00.000-04:00 + 1999-12-31T00:00:00.000-05:00 + 2011-03-07T21:02:28.127-05:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-05-01T16:39:00.000-04:00 + + + + + XF + solaris-ps-information-disclosure(25460) + + + SUNALERT + 102215 + + + SECTRACK + 1015833 + + + VUPEN + ADV-2006-1123 + + + MISC + http://www.sunmanagers.org/archives/1996/1383.html + + + BID + 19662 + + + OSVDB + 24200 + + + + + /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option. + + + + + + + + + + + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-1999-1588 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:53.067-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-05-01T16:40:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c + + + BID + 2319 + + + MISC + http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c + + + MISC + http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server + + Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766. + + + + + + + + + + + + + cpe:/o:ibm:aix:1.2.1 + cpe:/o:ibm:aix:2.2.1 + cpe:/o:ibm:aix:1.3 + cpe:/o:ibm:aix:3.1 + cpe:/o:ibm:aix:3.2 + + CVE-1999-1589 + 1992-05-05T00:00:00.000-04:00 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-06-15T16:27:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-1992-10 + + + BID + 357 + + Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors. + + + + + + + + + cpe:/a:wwwcount:wwwcount:2.3 + + CVE-1999-1590 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:53.367-04:00 + + + 3.5 + NETWORK + MEDIUM + SINGLE_INSTANCE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-12-06T16:23:00.000-05:00 + + + + BUGTRAQ + 19971010 Security flaw in Count.cgi (wwwcount) + + Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerability than CVE-1999-0021. + + + + + + + + + + cpe:/a:microsoft:visual_interdev:6.0 + cpe:/a:microsoft:internet_information_server:4.0:sp4 + + CVE-1999-1591 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:53.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-08-01T10:10:00.000-04:00 + + + + BID + 190 + + + NTBUGTRAQ + 19990119 Re: IIS4.0 and Visual Interdev + + + NTBUGTRAQ + 19990118 IIS4.0 and Visual Interdev + + Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0. + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:5 + + CVE-1999-1592 + 1999-12-31T00:00:00.000-05:00 + 2008-09-05T16:19:53.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-08-01T10:20:00.000-04:00 + + + + BID + 243 + + + SUN + 00159 + + Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129. + + + + + + CVE-1999-1593 + 2009-01-14T20:30:00.407-05:00 + 2009-01-15T00:00:00.000-05:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2009-01-15T11:54:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + MISC + https://www2.sans.org/reading_room/whitepapers/win2k/185.php + + + BID + 2221 + + + BUGTRAQ + 20010119 Re: Invalid WINS entries + + + BUGTRAQ + 20010118 Re: Invalid WINS entries + + + BUGTRAQ + 20010117 Re: Invalid WINS entries + + + BUGTRAQ + 20010117 Re: Invalid WINS entries + + + BUGTRAQ + 20010118 Re: Invalid WINS entries + + + BUGTRAQ + 20010117 Re: Invalid WINS entries + + + BUGTRAQ + 20010117 Invalid WINS entries + + + NTBUGTRAQ + 19990302 NT Domain DoS and Security Exploit with SAMBA Server + + Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable. + + + + + + + + + cpe:/a:realnetworks:realserver:5.0 + + CVE-2000-0001 + 1999-12-23T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 888 + + RealMedia server allows remote attackers to cause a denial of service via a long ramgen request. + + + + + + + + + cpe:/a:zbsoft:zbserver:1.5 + + CVE-2000-0002 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:17.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000128 ZBServer 1.50-r1x exploit (WinNT) + + + BID + 889 + + + NTBUGTRAQ + 19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT + + + BUGTRAQ + 19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT + + Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request. + + + + + + + + + cpe:/o:sco:unixware + + CVE-2000-0003 + 1999-12-30T00:00:00.000-05:00 + 2008-09-10T15:02:17.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000127 New SCO patches... + + Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable. + + + + + + + + + cpe:/a:zbsoft:zbserver:1.5 + + CVE-2000-0004 + 1999-12-01T00:00:00.000-05:00 + 2008-09-10T15:02:17.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT + + + BUGTRAQ + 19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT + + ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:hp-ux:9.10 + cpe:/o:hp:hp-ux:8.04 + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:8.05 + cpe:/o:hp:hp-ux:8.06 + cpe:/o:hp:hp-ux:8.07 + cpe:/h:hp:9000:7_800 + cpe:/o:hp:hp-ux:9.03 + cpe:/o:hp:hp-ux:8.08 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:8.09 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:hp:hp-ux:9.08 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:9.06 + cpe:/o:hp:hp-ux:10.16 + cpe:/o:hp:hp-ux:8.00 + cpe:/a:hp:aserver + cpe:/o:hp:hp-ux:8.01 + cpe:/o:hp:hp-ux:9.09 + cpe:/o:hp:hp-ux:8.02 + cpe:/o:hp:hp-ux:7.02 + cpe:/o:hp:hp-ux:7.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:7.06 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:hp:hp-ux:7.04 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:hp:hp-ux:7.08 + cpe:/o:hp:hp-ux:10.09 + cpe:/o:hp:hp-ux:10.08 + + CVE-2000-0005 + 1999-01-02T00:00:00.000-05:00 + 2009-03-04T00:03:30.420-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + HP-UX aserver program allows local users to gain privileges via a symlink attack. + + + + + + + + + + + + + + cpe:/a:paul_kranenburg:strace + cpe:/o:linux:linux_kernel:2.3.20 + + CVE-2000-0006 + 1999-12-25T00:00:00.000-05:00 + 2008-09-10T15:02:18.023-04:00 + + + 2.6 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-strace(4554) + + + BUGTRAQ + 19991225 strace can lie + + strace allows local users to read arbitrary files via memory mapped file names. + + + + + + + + + cpe:/a:trend_micro:pc-cillin:6.0 + + CVE-2000-0007 + 1999-12-29T00:00:00.000-05:00 + 2008-09-10T15:02:18.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pccillin-proxy-remote-dos(4491) + + + BID + 1740 + + Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service. + + + + + + + + + cpe:/a:1st_choice_software:ftppro:7.5 + + CVE-2000-0008 + 1999-12-26T00:00:00.000-05:00 + 2008-09-10T15:02:18.147-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + FTPPro allows local users to read sensitive information, which is stored in plain text. + + + + + + + + + cpe:/a:nortel:optivity_net_architect:2.0 + + CVE-2000-0009 + 1999-12-29T00:00:00.000-05:00 + 2008-09-10T15:02:18.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 907 + + The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands. + + + + + + + + + cpe:/a:tony_greenwood:webwho%2b:1.1 + + CVE-2000-0010 + 1999-12-26T00:00:00.000-05:00 + 2008-09-10T15:02:18.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter. + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.0.1 + + CVE-2000-0011 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:02:18.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.analogx.com/contents/download/network/sswww.htm + + + BID + 906 + + + OSVDB + 1184 + + Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. + + + + + + + + + cpe:/a:hughes:msql:2.0.11 + + CVE-2000-0012 + 1999-12-27T00:00:00.000-05:00 + 2008-09-10T15:02:18.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 898 + + Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-2000-0013 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:02:18.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 909 + + IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program. + + + + + + + + + cpe:/a:michael_lamont:savant_webserver:2.0 + + CVE-2000-0014 + 1999-12-28T00:00:00.000-05:00 + 2008-09-10T15:02:19.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 897 + + Denial of service in Savant web server via a null character in the requested URL. + + + + + + + + + cpe:/a:ascend:cascadeview_ux:1.0 + + CVE-2000-0015 + 1999-12-31T00:00:00.000-05:00 + 2008-09-10T15:02:19.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 910 + + CascadeView TFTP server allows local users to gain privileges via a symlink attack. + + + + + + + + + + cpe:/a:true_north:internet_anywhere_mail_server:2.3.1 + cpe:/a:true_north:internet_anywhere_mail_server:2.3 + + CVE-2000-0016 + 1999-10-01T00:00:00.000-04:00 + 2008-09-10T15:02:19.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 730 + + Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username. + + + + + + + + + cpe:/o:redhat:linux + + CVE-2000-0017 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:19.227-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter. + + + + + + + + + cpe:/a:windowmaker:wmmon:1.0b2 + + CVE-2000-0018 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:19.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 885 + + + OSVDB + 1169 + + wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file. + + + + + + + + + cpe:/a:ipswitch:imail:2006 + + CVE-2000-0019 + 1999-03-04T00:00:00.000-05:00 + 2008-09-10T15:02:19.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IMail POP3 daemon uses weak encryption, which allows local users to read files. + + + + + + + + + cpe:/a:man_and_mice:dns_pro:5.7 + + CVE-2000-0020 + 1999-12-20T00:00:00.000-05:00 + 2008-09-10T15:02:19.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + DNS PRO allows remote attackers to conduct a denial of service via a large number of connections. + + + + + + + + + cpe:/a:lotus:domino_server:4.6 + + CVE-2000-0021 + 1999-12-01T00:00:00.000-05:00 + 2008-09-10T15:02:19.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 881 + + Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin. + + + + + + + + + + cpe:/a:lotus:domino_server:4.6.x + cpe:/a:lotus:domino_server:4.6 + + CVE-2000-0022 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:19.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 881 + + Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory. + + + + + + + + + + cpe:/a:lotus:domino_server:4.6.x + cpe:/a:lotus:domino_server:4.6 + + CVE-2000-0023 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:19.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 881 + + + OSVDB + 51 + + Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-2000-0024 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:20.557-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q246401 + + + MS + MS99-061 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt + + IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0 + + CVE-2000-0025 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:20.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q238606 + + + OSVDB + 8098 + + + MS + MS99-058 + + IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. + + + + + + + + + + + + + + cpe:/a:windowmaker:wmmon:1.0b2 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0026 + 1999-12-21T00:00:00.000-05:00 + 2008-09-10T15:02:20.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 876 + + + OSVDB + 6310 + + + BUGTRAQ + 19991223 FYI, SCO Security patches available. + + Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. + + + + + + + + + cpe:/a:ibm:network_station_manager:2.0r1 + + CVE-2000-0027 + 1999-12-27T00:00:00.000-05:00 + 2008-09-10T15:02:20.773-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 900 + + + BUGTRAQ + 19991227 IBM NetStation/UnixWare local root exploit + + + XF + ibm-netstat-race-condition(5381) + + IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack. + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.1 + cpe:/a:microsoft:ie:4.0:a_mac_os + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + cpe:/a:microsoft:ie:4.0.1:sp2 + cpe:/a:microsoft:ie:4.5 + cpe:/a:microsoft:ie:3.1 + cpe:/a:microsoft:ie:3.2 + + CVE-2000-0028 + 1999-12-23T00:00:00.000-05:00 + 2008-09-10T15:02:20.853-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. + + + + + + + + + cpe:/o:sco:unixware:7.1 + + CVE-2000-0029 + 1999-12-27T00:00:00.000-05:00 + 2008-09-10T15:02:23.460-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 901 + + + BUGTRAQ + 20000113 Info on some security holes reported against SCO Unixware. + + UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack. + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + + CVE-2000-0030 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:23.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 878 + + Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database. + + + + + + + + + + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + + CVE-2000-0031 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:02:23.697-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack. + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + + CVE-2000-0032 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:23.757-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 878 + + + OSVDB + 7582 + + Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2000-0033 + 1999-12-27T00:00:00.000-05:00 + 2008-09-10T15:02:23.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 899 + + InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments. + + + + + + + + + cpe:/a:netscape:communicator:4.7 + + CVE-2000-0034 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:23.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords." + + + + + + + + + cpe:/a:great_circle_associates:majordomo:1.94.4 + + CVE-2000-0035 + 1999-12-28T00:00:00.000-05:00 + 2008-09-10T15:02:24.040-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 902 + + + BUGTRAQ + 20000113 Info on some security holes reported against SCO Unixware. + + resend command in Majordomo allows local users to gain privileges via shell metacharacters. + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0::macos + cpe:/a:microsoft:ie:4.5::macintosh + + CVE-2000-0036 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:24.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-060 + + + MSKB + Q249082 + + Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. + + + + + + + + + + cpe:/a:great_circle_associates:majordomo:1.94.5 + cpe:/a:great_circle_associates:majordomo:1.94.4 + + CVE-2000-0037 + 1999-12-28T00:00:00.000-05:00 + 2008-09-10T15:02:24.507-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 903 + + + REDHAT + RHSA-2000:005 + + + BUGTRAQ + 20000113 Info on some security holes reported against SCO Unixware. + + Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file. + + + + + + + + + cpe:/a:glftpd:glftpd:1.17.2 + + CVE-2000-0038 + 1999-12-23T00:00:00.000-05:00 + 2008-09-10T15:02:24.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + glFtpD includes a default glftpd user account with a default password and a UID of 0. + + + + + + + + + + cpe:/a:altavista:search_intranet:2.0b + cpe:/a:altavista:search_intranet:2.3a + + CVE-2000-0039 + 1999-12-29T00:00:00.000-05:00 + 2008-09-10T15:02:24.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 896 + + + OSVDB + 15 + + AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program. + + + + + + + + + cpe:/a:glftpd:glftpd:1.17.2 + + CVE-2000-0040 + 1999-12-23T00:00:00.000-05:00 + 2008-09-10T15:02:24.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. + + + + + + + + + cpe:/o:apple:mac_os:9.0 + + CVE-2000-0041 + 1999-12-28T00:00:00.000-05:00 + 2008-09-10T15:02:24.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 890 + + Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack. + + + + + + + + + + + + + + + + cpe:/a:csm:mail_server:2000-01a + cpe:/a:csm:mail_server:1999-07i + cpe:/a:csm:mail_server:1999-07h + cpe:/a:csm:mail_server:1999-07g + cpe:/a:csm:mail_server:1999-07f + cpe:/a:csm:mail_server:2000.8.a + cpe:/a:csm:mail_server:1999-07b + cpe:/a:csm:mail_server:1999-07m + + CVE-2000-0042 + 1999-12-29T00:00:00.000-05:00 + 2008-09-10T15:02:24.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 895 + + Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command. + + + + + + + + + cpe:/a:camshot:webcam_http_server:2.5 + + CVE-2000-0043 + 1999-12-30T00:00:00.000-05:00 + 2008-09-10T15:02:24.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 905 + + Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request. + + + + + + + + + + cpe:/a:jgaa:warftpd:1.67b2 + cpe:/a:jgaa:warftpd:1.70b + + CVE-2000-0044 + 2000-01-06T00:00:00.000-05:00 + 2008-09-10T15:02:25.023-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 919 + + Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands. + + + + + + + + + + + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.23.8 + + CVE-2000-0045 + 2000-01-11T00:00:00.000-05:00 + 2008-09-10T15:02:25.087-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 926 + + MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. + + + + + + + + + cpe:/a:mirabilis:icq:0.99b_1.1.1.1 + + CVE-2000-0046 + 2000-01-10T00:00:00.000-05:00 + 2008-09-10T15:02:25.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 929 + + Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message. + + + + + + + + + cpe:/a:yahoo:pager:733 + + CVE-2000-0047 + 1999-10-01T00:00:00.000-04:00 + 2008-09-10T15:02:25.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message. + + + + + + + + + cpe:/o:corel:linux:1.0 + + CVE-2000-0048 + 2000-01-12T00:00:00.000-05:00 + 2008-09-10T15:02:25.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://linux.corel.com/support/clos_patch1.htm + + + BID + 928 + + get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program. + + + + + + + + + + cpe:/a:nullsoft:winamp:2.0 + cpe:/a:nullsoft:winamp:2.10 + + CVE-2000-0049 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:25.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 925 + + + OSVDB + 12022 + + Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file. + + + + + + + + + cpe:/a:allaire:spectra:1.0 + + CVE-2000-0050 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:26.133-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ALLAIRE + ASB00-01 + + + BID + 915 + + The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs. + + + + + + + + + cpe:/a:allaire:spectra:1.0 + + CVE-2000-0051 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:26.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB00-02 + + + BID + 916 + + The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL. + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:turbolinux:turbolinux:3.5b2 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0052 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:40.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-pam-userhelper + + + BID + 913 + + + REDHAT + RHSA-2000:001 + + + L0PHT + 20000104 PamSlam + + Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack. + + + + + + + + + + cpe:/a:microsoft:commercial_internet_system:2.5 + cpe:/a:microsoft:commercial_internet_system:2.0 + + CVE-2000-0053 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:41.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS00-001 + + + MSKB + Q246731 + + + BID + 912 + + Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request. + + + + + + + + + cpe:/a:solution_scripts:home_free:1.0 + + CVE-2000-0054 + 1999-01-03T00:00:00.000-05:00 + 2008-09-10T15:02:41.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 921 + + search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.6:hw5 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:2.6:hw5:x86 + cpe:/o:sun:solaris:2.6:hw3:x86 + cpe:/o:sun:solaris:2.5.1::x86 + + CVE-2000-0055 + 2000-01-06T00:00:00.000-05:00 + 2008-09-10T15:02:41.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 918 + + Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option. + + + + + + + + + + + cpe:/a:ipswitch:imail:5.0.8 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:6.0 + + CVE-2000-0056 + 2000-01-05T00:00:00.000-05:00 + 2008-09-10T15:02:41.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 914 + + IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi. + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:4.0.1 + + CVE-2000-0057 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:41.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ALLAIRE + ASB00-03 + + + BID + 917 + + Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information. + + + + + + + + + cpe:/a:handspring:visor_network_hotsync:1.0 + + CVE-2000-0058 + 2000-01-05T00:00:00.000-05:00 + 2008-09-10T15:02:41.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 920 + + + BUGTRAQ + 20000105 Handspring Visor Network HotSync Security Hole + + Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2000-0059 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:41.507-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 911 + + PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. + + + + + + + + + cpe:/a:avirt:rover:1.1 + + CVE-2000-0060 + 1999-12-27T00:00:00.000-05:00 + 2008-09-10T15:02:41.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 894 + + + XF + avirt-rover-pop3-dos(3765) + + + NTBUGTRAQ + 19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt + + + BUGTRAQ + 19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt + + Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name. + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5:preview + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0061 + 2000-01-07T00:00:00.000-05:00 + 2008-09-10T15:02:41.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 923 + + Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading. + + + + + + + + + + cpe:/a:zope:zope:1.10.3 + cpe:/a:zope:zope:2.1.1 + + CVE-2000-0062 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:41.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT] + + + BID + 922 + + The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities. + + + + + + + + + cpe:/h:nortel:contivity:1.0 + + CVE-2000-0063 + 2000-01-17T00:00:00.000-05:00 + 2008-09-10T15:02:41.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 938 + + cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script. + + + + + + + + + cpe:/h:nortel:contivity:1.0 + + CVE-2000-0064 + 2000-01-17T00:00:00.000-05:00 + 2008-09-10T15:02:41.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 938 + + + OSVDB + 7583 + + cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters. + + + + + + + + + cpe:/a:avtronics:inetserv:3.0 + + CVE-2000-0065 + 2000-01-17T00:00:00.000-05:00 + 2008-09-10T15:02:42.057-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. + + + + + + + + + + cpe:/a:oreilly:website_professional:2.3.18 + cpe:/a:oreilly:website_professional:2.4.9 + + CVE-2000-0066 + 2000-01-13T00:00:00.000-05:00 + 2008-09-10T15:02:42.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. + + + + + + + + + cpe:/a:cybercash:merchant_connection_kit:3.2.0.4 + + CVE-2000-0067 + 2000-01-11T00:00:00.000-05:00 + 2008-09-10T15:02:42.197-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack. + + + + + + + + + cpe:/a:intel:inbusiness_email_station:1.04 + + CVE-2000-0068 + 1999-12-14T00:00:00.000-05:00 + 2008-09-10T15:02:42.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000104 [rootshell] Security Bulletin #27 + + daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail. + + + + + + + + + cpe:/a:sun:solstice_backup:5.1 + + CVE-2000-0069 + 2000-01-01T00:00:00.000-05:00 + 2008-09-10T15:02:42.337-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The recover program in Solstice Backup allows local users to restore sensitive files. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0070 + 2000-01-12T00:00:00.000-05:00 + 2008-09-10T15:02:42.633-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BINDVIEW + 20000113 Local Promotion Vulnerability in Windows NT 4 + + + MSKB + Q247869 + + + XF + nt-spoofed-lpc-port + + + BID + 934 + + + MS + MS00-003 + + NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request." + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0071 + 2000-01-11T00:00:00.000-05:00 + 2008-09-10T15:02:42.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000113 SV: IIS still revealing paths for web directories + + + BUGTRAQ + 20000111 IIS still revealing paths for web directories + + IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. + + + + + + + + + + cpe:/a:computer_power_solutions:visual_casel:3.5 + cpe:/a:computer_power_solutions:visual_casel:3.0 + + CVE-2000-0072 + 2000-01-17T00:00:00.000-05:00 + 2008-09-10T15:02:42.773-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 937 + + + XF + vcasel-filename-trusting(3867) + + + BUGTRAQ + 20000118 Warning: VCasel security hole. + + Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0073 + 1999-11-17T00:00:00.000-05:00 + 2008-09-10T15:02:42.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-005 + + + MSKB + Q249973 + + + XF + win-malformed-rtf-control-word + + Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. + + + + + + + + + cpe:/a:powerscripts:plusmail + + CVE-2000-0074 + 2000-01-11T00:00:00.000-05:00 + 2008-09-10T15:02:42.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. + + + + + + + + + cpe:/a:nosque:msgcore:1.9 + + CVE-2000-0075 + 2000-01-13T00:00:00.000-05:00 + 2008-09-10T15:02:42.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 930 + + Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session. + + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + cpe:/o:berkeley:nvi:1.7x + + CVE-2000-0076 + 1999-12-30T00:00:00.000-05:00 + 2008-09-10T15:02:43.057-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1439 + + + BUGTRAQ + 19991230 vibackup.sh + + nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + + CVE-2000-0077 + 2000-01-02T00:00:00.000-05:00 + 2009-03-04T00:03:52.920-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + + CVE-2000-0078 + 2000-01-02T00:00:00.000-05:00 + 2009-03-04T00:03:53.030-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. + + + + + + + + + cpe:/a:w3c:cern_httpd:3.0 + + CVE-2000-0079 + 2000-01-18T00:00:00.000-05:00 + 2008-09-10T15:02:51.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 936 + + The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. + + + + + + + + + cpe:/o:ibm:aix:4.3.2 + + CVE-2000-0080 + 2000-01-10T00:00:00.000-05:00 + 2008-09-10T15:02:51.523-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 931 + + + BUGTRAQ + 20000110 2nd attempt: AIX techlibss follows links + + AIX techlibss allows local users to overwrite files via a symlink attack. + + + + + + + + + cpe:/a:microsoft:hotmail + + CVE-2000-0081 + 2000-01-10T00:00:00.000-05:00 + 2008-09-05T16:20:05.707-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&#x41;vascript. + + + + + + + + + cpe:/a:microsoft:webtv + + CVE-2000-0082 + 2000-01-02T00:00:00.000-05:00 + 2008-09-05T16:20:05.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.wired.com/news/technology/0,1282,33420,00.html + + + MISC + http://net4tv.com/voice/story.cfm?StoryID=1823 + + WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + + CVE-2000-0083 + 2000-04-18T00:00:00.000-04:00 + 2008-09-10T15:02:52.897-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBUX0001-109 + + + + + HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges. + + + + + + + + + cpe:/a:globalscape:cuteftp:2.x + + CVE-2000-0084 + 2000-01-06T00:00:00.000-05:00 + 2008-09-10T15:02:52.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + CuteFTP uses weak encryption to store password information in its tree.dat file. + + + + + + + + + cpe:/a:microsoft:hotmail + + CVE-2000-0085 + 2000-01-04T00:00:00.000-05:00 + 2008-09-10T15:02:53.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. + + + + + + + + + + cpe:/a:netopia:timbuktu_pro:2.0 + cpe:/a:netopia:timbuktu_pro:3.0 + + CVE-2000-0086 + 2000-01-18T00:00:00.000-05:00 + 2008-09-10T15:02:53.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 935 + + Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing. + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:navigator + + CVE-2000-0087 + 2000-01-12T00:00:00.000-05:00 + 2008-09-10T15:02:53.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-mail-notify-plaintext(4385) + + + BUGTRAQ + 20000113 Misleading sense of security in Netscape + + Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:office:97:::korean + cpe:/a:microsoft:powerpoint:2000:::korean + cpe:/a:microsoft:powerpoint:97:::chinese + cpe:/a:microsoft:word:2000:::japanese + cpe:/a:microsoft:office:2000:::korean + cpe:/a:microsoft:office:2000:::japanese + cpe:/a:microsoft:word:2000:::korean + cpe:/a:microsoft:word:2000:::chinese + cpe:/a:microsoft:powerpoint:97:::japanese + cpe:/a:microsoft:word:97:::korean + cpe:/a:microsoft:word:98:::korean + cpe:/a:microsoft:powerpoint:2000:::japanese + cpe:/a:microsoft:word:97:::japanese + cpe:/a:microsoft:powerpoint:97:::korean + cpe:/a:microsoft:office:2000:::chinese + cpe:/a:microsoft:word:98:::japanese + cpe:/a:microsoft:office:97:::chinese + cpe:/a:microsoft:word:98:::chinese + cpe:/a:microsoft:word:97:::chinese + cpe:/a:microsoft:office_converter_pack:2000.0 + cpe:/a:microsoft:office:97:::japanese + cpe:/a:microsoft:powerpoint:2000:::chinese + + CVE-2000-0088 + 2000-01-20T00:00:00.000-05:00 + 2008-09-10T15:02:53.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 946 + + + MS + MS00-002 + + Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0089 + 2000-02-04T00:00:00.000-05:00 + 2008-09-10T15:02:53.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q249108 + + + BID + 947 + + + MS + MS00-004 + + The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. + + + + + + + + + + + + + cpe:/a:vmware:workstation:1.0.2 + cpe:/a:vmware:workstation:1.0.1 + cpe:/a:vmware:workstation:1.1.2 + cpe:/a:vmware:workstation:1.1.1 + cpe:/a:vmware:workstation:1.1 + + CVE-2000-0090 + 2000-01-17T00:00:00.000-05:00 + 2008-09-10T15:02:53.447-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 943 + + + OSVDB + 1205 + + VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. + + + + + + + + + + + + + + + + + + cpe:/a:inter7:vpopmail:vchkpw_3.4.9 + cpe:/a:inter7:vpopmail:vchkpw_3.4.8 + cpe:/a:inter7:vpopmail:vchkpw_3.4.7 + cpe:/a:inter7:vpopmail:vchkpw_3.4.6 + cpe:/a:inter7:vpopmail:vchkpw_3.4.5 + cpe:/a:inter7:vpopmail:vchkpw_3.4.4 + cpe:/a:inter7:vpopmail:vchkpw_3.4.3 + cpe:/a:inter7:vpopmail:vchkpw_3.4.2 + cpe:/a:inter7:vpopmail:vchkpw_3.4.11 + cpe:/a:inter7:vpopmail:vchkpw_3.4.1 + + CVE-2000-0091 + 2000-01-21T00:00:00.000-05:00 + 2008-09-10T15:02:53.897-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.inter7.com/vpopmail/ChangeLog + + + MISC + http://www.inter7.com/vpopmail/ + + + BID + 942 + + Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1::x86 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:freebsd:freebsd:3.4 + + CVE-2000-0092 + 2000-01-19T00:00:00.000-05:00 + 2011-03-07T21:02:37.860-05:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-00:01 + + + BID + 939 + + The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. + + + + + + + + + cpe:/o:redhat:linux:6.1 + + CVE-2000-0093 + 2000-01-21T00:00:00.000-05:00 + 2008-09-10T15:02:54.040-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5. + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1 + + CVE-2000-0094 + 2000-02-16T00:00:00.000-05:00 + 2008-09-10T15:02:54.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + netbsd-procfs(3995) + + + BID + 940 + + + OSVDB + 20760 + + + NETBSD + NetBSD-SA2000-001 + + procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr. + + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.30 + + CVE-2000-0095 + 2000-01-24T00:00:00.000-05:00 + 2008-09-10T15:02:54.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX0001-110 + + + BID + 944 + + The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:qualcomm:qpopper:3.0beta27 + cpe:/a:qualcomm:qpopper:3.0beta28 + cpe:/a:qualcomm:qpopper:3.0beta25 + cpe:/a:qualcomm:qpopper:3.0beta26 + cpe:/a:qualcomm:qpopper:3.0beta29 + cpe:/a:qualcomm:qpopper:3.0beta20 + cpe:/a:qualcomm:qpopper:3.0beta23 + cpe:/a:qualcomm:qpopper:3.0beta24 + cpe:/a:qualcomm:qpopper:3.0beta21 + cpe:/a:qualcomm:qpopper:3.0beta22 + cpe:/a:qualcomm:qpopper:3.0beta4 + cpe:/a:qualcomm:qpopper:3.0beta3 + cpe:/a:qualcomm:qpopper:3.0beta2 + cpe:/a:qualcomm:qpopper:3.0beta1 + cpe:/a:qualcomm:qpopper:3.0beta14 + cpe:/a:qualcomm:qpopper:3.0beta15 + cpe:/a:qualcomm:qpopper:3.0beta16 + cpe:/a:qualcomm:qpopper:3.0beta17 + cpe:/a:qualcomm:qpopper:3.0beta18 + cpe:/a:qualcomm:qpopper:3.0beta19 + cpe:/a:qualcomm:qpopper:3.0beta9 + cpe:/a:qualcomm:qpopper:3.0 + cpe:/a:qualcomm:qpopper:3.0beta5 + cpe:/a:qualcomm:qpopper:3.0beta10 + cpe:/a:qualcomm:qpopper:3.0beta6 + cpe:/a:qualcomm:qpopper:3.0beta11 + cpe:/a:qualcomm:qpopper:3.0beta7 + cpe:/a:qualcomm:qpopper:3.0beta12 + cpe:/a:qualcomm:qpopper:3.0beta8 + cpe:/a:qualcomm:qpopper:3.0beta13 + + CVE-2000-0096 + 2000-01-26T00:00:00.000-05:00 + 2008-09-10T15:02:54.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 948 + + Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command. + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-2000-0097 + 2000-01-26T00:00:00.000-05:00 + 2008-09-10T15:02:54.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-006 + + + BID + 950 + + + OSVDB + 1210 + + The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-2000-0098 + 2000-01-26T00:00:00.000-05:00 + 2008-09-10T15:02:54.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-006 + + Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. + + + + + + + + + + + cpe:/o:sco:unixware:7.1.0 + cpe:/o:sco:unixware:7.0.0 + cpe:/o:sco:unixware:7.0.1 + + CVE-2000-0099 + 2000-01-18T00:00:00.000-05:00 + 2008-09-10T15:02:54.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000119 Unixware ppptalk + + Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument. + + + + + + + + + cpe:/a:microsoft:systems_management_server:2.0 + + CVE-2000-0100 + 1999-12-29T00:00:00.000-05:00 + 2008-09-10T15:02:54.540-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS00-012 + + + NTBUGTRAQ + 20000115 Security Vulnerability with SMS 2.0 Remote Control + + The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program. + + + + + + + + + cpe:/a:make-a-store:orderpage + + CVE-2000-0101 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:salescart:salescart + + CVE-2000-0102 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:netsmart:smartcart + + CVE-2000-0103 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:web_express:shoptron:1.2 + + CVE-2000-0104 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + + CVE-2000-0105 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 962 + + Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. + + + + + + + + + cpe:/a:easycart:easycart + + CVE-2000-0106 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:54.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + + CVE-2000-0107 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:55.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 958 + + + DEBIAN + 20000201 + + Linux apcd program allows local attackers to modify arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:intelligent_vending_systems:intellivend + + CVE-2000-0108 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:55.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:comstock:multicsp:4.2 + + CVE-2000-0109 + 2000-01-31T00:00:00.000-05:00 + 2008-09-10T15:02:55.147-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords. + + + + + + + + + cpe:/a:baron_consulting_group:websitetool + + CVE-2000-0110 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:55.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:avt:rightfax:5.2 + + CVE-2000-0111 + 2000-01-29T00:00:00.000-05:00 + 2008-09-10T15:02:55.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 953 + + The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions. + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::pre_potato + cpe:/o:debian:debian_linux:2.0:r5 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-0112 + 2000-02-02T00:00:00.000-05:00 + 2008-09-10T15:02:55.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 960 + + + BUGTRAQ + 20000202 vulnerability in Linux Debian default boot configuration + + The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation. + + + + + + + + + + cpe:/a:sybergen:sygate:3.11 + cpe:/a:sybergen:sygate:2.0 + + CVE-2000-0113 + 2000-01-27T00:00:00.000-05:00 + 2008-09-10T15:02:55.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.sybergen.com/support/fix.htm + + + BID + 952 + + + BUGTRAQ + 20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole + + + BUGTRAQ + 20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole + + + BUGTRAQ + 20000128 SyGate 3.11 Port 7323 / Remote Admin hole + + The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0114 + 2000-02-02T00:00:00.000-05:00 + 2008-09-10T15:02:56.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. + + + + + + + + + cpe:/a:microsoft:internet_information_server + + CVE-2000-0115 + 2000-01-21T00:00:00.000-05:00 + 2008-09-10T15:02:56.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. + + + + + + + + + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0116 + 2000-01-29T00:00:00.000-05:00 + 2008-09-10T15:02:56.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 954 + + + OSVDB + 1212 + + Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag. + + + + + + + + + + + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + cpe:/a:sun:cobalt_raq:1.0 + + CVE-2000-0117 + 2000-01-30T00:00:00.000-05:00 + 2008-09-10T15:02:56.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 951 + + The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:::x86 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:sun:solaris:1.2 + cpe:/o:sun:solaris:1.1.2 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:sun:solaris:1.1.4 + cpe:/o:sun:solaris:1.1 + cpe:/o:sun:solaris:1.1.3 + cpe:/o:redhat:linux:5.2::sparc + cpe:/o:redhat:linux:6.1::i386 + cpe:/o:sun:solaris:2.3 + cpe:/o:redhat:linux:2.1 + cpe:/o:sun:solaris:2.4 + cpe:/o:redhat:linux:5.2::alpha + cpe:/o:redhat:linux:2.0 + cpe:/o:sun:solaris:2.5 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:sun:solaris:1.1.4::jl + cpe:/o:redhat:linux:3.0.3 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:1.1.3:u1 + cpe:/o:sun:solaris:2.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:sun:solaris:1.1.1a + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + + CVE-2000-0118 + 1999-06-09T00:00:00.000-04:00 + 2008-09-10T15:02:56.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000130 RedHat 6.1 /and others/ PAM + + The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing. + + + + + + + + + + cpe:/a:symantec:norton_antivirus + cpe:/a:mcafee:virusscan + + CVE-2000-0119 + 1999-12-22T00:00:00.000-05:00 + 2008-09-10T15:02:56.367-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000130 Bypass Virus Checking + + The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection. + + + + + + + + + cpe:/a:allaire:spectra:1.0 + + CVE-2000-0120 + 2000-01-01T00:00:00.000-05:00 + 2008-09-10T15:02:56.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + allaire-spectra-ras-access(4025) + + + BID + 955 + + The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0121 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:56.507-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MSKB + Q248399 + + + BID + 963 + + + MS + MS00-007 + + The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability. + + + + + + + + + + cpe:/a:microsoft:frontpage:98 + cpe:/a:microsoft:frontpage:2000 + + CVE-2000-0122 + 2000-02-03T00:00:00.000-05:00 + 2008-09-10T15:02:56.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 964 + + + XF + frontpage-cern-information-disclosure(34719) + + + BUGTRAQ + 20070603 CERN &#304;mage Map Dispatcher + + Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. + + + + + + + + + cpe:/a:filemaker:filemaker:::pro + + CVE-2000-0123 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:02:56.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:surfcontrol:superscout:2.6.1.6 + + CVE-2000-0124 + 2000-02-03T00:00:00.000-05:00 + 2008-09-10T15:02:56.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 965 + + surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. + + + + + + + + + cpe:/a:wired_community_software:wwwthreads + + CVE-2000-0125 + 2000-02-03T00:00:00.000-05:00 + 2008-09-10T15:02:56.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000203 RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory) + + + BID + 967 + + wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0126 + 2000-01-26T00:00:00.000-05:00 + 2008-09-10T15:02:56.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:progress:webspeed:3.0 + + CVE-2000-0127 + 2000-02-03T00:00:00.000-05:00 + 2008-09-10T15:02:57.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 969 + + + CONFIRM + http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&keywords=security%20Webspeed + + The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll. + + + + + + + + + + + + cpe:/a:daniel_beckham:the_finger_server:0.83_beta + cpe:/a:daniel_beckham:the_finger_server:0.80_beta + cpe:/a:daniel_beckham:the_finger_server:0.82_beta + cpe:/a:daniel_beckham:the_finger_server:0.81_beta + + CVE-2000-0128 + 2000-02-04T00:00:00.000-05:00 + 2008-09-10T15:02:58.023-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.glazed.org/finger/changelog.txt + + + OSVDB + 7610 + + The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0129 + 2000-02-04T00:00:00.000-05:00 + 2008-09-10T15:03:04.977-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. + + + + + + + + + + + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0130 + 2000-01-27T00:00:00.000-05:00 + 2008-09-10T15:03:05.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000127 New SCO patches... + + + SCO + SB-00.02a + + Buffer overflow in SCO scohelp program allows remote attackers to execute commands. + + + + + + + + + + cpe:/a:jgaa:warftpd:1.66x4s + cpe:/a:jgaa:warftpd:1.67.3 + + CVE-2000-0131 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 966 + + + OSVDB + 4677 + + + BUGTRAQ + 20000201 war-ftpd 1.6x DoS + + Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3000 + cpe:/a:microsoft:virtual_machine:2000 + + CVE-2000-0132 + 2000-01-31T00:00:00.000-05:00 + 2008-09-10T15:03:05.290-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 957 + + Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. + + + + + + + + + cpe:/a:h._nomura:tiny_ftpdaemon:0.52 + + CVE-2000-0133 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.413-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 961 + + Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands. + + + + + + + + + cpe:/a:adgrafix_corporation:check_it_out + + CVE-2000-0134 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:atretail:atretail + + CVE-2000-0135 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:mcmurtrey_whitaker_and_associates:cart32 + + CVE-2000-0136 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:cartit:cartit + + CVE-2000-0137 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:05.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. + + + CVE-2000-0138 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:03:05.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20000502 "mstream" Distributed Denial of Service Tool + + + BUGTRAQ + 20000501 Re: Source code to mstream, a DDoS tool + + + BUGTRAQ + 20000429 Source code to mstream, a DDoS tool + + A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft. + + + + + + + + + cpe:/a:true_north:internet_anywhere_mail_server:3.1.3 + + CVE-2000-0139 + 1999-12-03T00:00:00.000-05:00 + 2008-09-10T15:03:05.867-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 982 + + + BUGTRAQ + 20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3 + + Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command. + + + + + + + + + cpe:/a:true_north:internet_anywhere_mail_server:3.1.3 + + CVE-2000-0140 + 2000-02-10T00:00:00.000-05:00 + 2008-09-10T15:03:05.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 980 + + + BUGTRAQ + 20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3 + + Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections. + + + + + + + + + cpe:/a:infopop:ultimate_bulletin_board:5.43 + + CVE-2000-0141 + 2000-02-11T00:00:00.000-05:00 + 2008-09-10T15:03:06.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.ultimatebb.com/home/versions.shtml + + + BUGTRAQ + 20000211 perl-cgi hole in UltimateBB by Infopop Corp. + + + BUGTRAQ + 20000225 FW: Important UBB News For Licensed Users + + + BID + 991 + + Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field. + + + + + + + + + + cpe:/a:netopia:timbuktu_pro:2.0 + cpe:/a:netopia:timbuktu_pro:5.2.1 + + CVE-2000-0142 + 2000-02-11T00:00:00.000-05:00 + 2008-09-10T15:03:06.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.3 + cpe:/a:ssh:ssh:1.2.4 + cpe:/a:ssh:ssh:1.2.1 + cpe:/a:ssh:ssh:1.2.2 + cpe:/a:ssh:ssh:1.2.7 + cpe:/a:ssh:ssh:1.2.8 + cpe:/a:ssh:ssh:1.2.5 + cpe:/a:ssh:ssh:1.2.19 + cpe:/a:ssh:ssh:1.2.6 + cpe:/a:ssh:ssh:1.2.18 + cpe:/a:ssh:ssh:1.2.0 + cpe:/a:openbsd:openssh:1.2 + cpe:/a:ssh:ssh:1.2.16 + cpe:/a:ssh:ssh:1.2.17 + cpe:/a:ssh:ssh:1.2.14 + cpe:/a:ssh:ssh:1.2.9 + cpe:/a:ssh:ssh:1.2.15 + cpe:/a:ssh:ssh:1.2.12 + cpe:/a:ssh:ssh:1.2.13 + cpe:/a:ssh:ssh:1.2.10 + cpe:/a:ssh:ssh:1.2.11 + cpe:/a:openbsd:openssh:1.2.1 + cpe:/a:ssh:ssh:1.2.20 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.21 + cpe:/a:ssh:ssh:1.2.22 + cpe:/a:ssh:ssh:1.2.23 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2000-0143 + 2000-02-11T00:00:00.000-05:00 + 2008-09-10T15:03:06.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP. + + + + + + + + + + + + + + cpe:/h:axis:700_network_document_server:1.13 + cpe:/h:axis:700_network_document_server:1.12 + cpe:/h:axis:700_network_document_server:1.14 + cpe:/h:axis:700_network_document_server:1.11 + cpe:/h:axis:700_network_document_server:1.10 + cpe:/h:axis:700_network_document_server:1.0 + + CVE-2000-0144 + 2000-02-07T00:00:00.000-05:00 + 2008-09-10T15:03:06.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 971 + + + BUGTRAQ + 20000207 Infosec.20000207.axis700.a + + Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack. + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + + CVE-2000-0145 + 2000-02-05T00:00:00.000-05:00 + 2008-09-10T15:03:06.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions. + + + + + + + + + cpe:/a:novell:groupwise:5.5::enhancement_pack + + CVE-2000-0146 + 2000-02-07T00:00:00.000-05:00 + 2008-09-10T15:03:06.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 972 + + + BUGTRAQ + 20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e + + The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet. + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + + CVE-2000-0147 + 2000-02-08T00:00:00.000-05:00 + 2008-09-05T16:20:15.737-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NAI + 20000207 SNMPD default writable community string + + + SCO + SB-00.04a + + + BID + 973 + + snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration. + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.22.30 + + CVE-2000-0148 + 2000-02-08T00:00:00.000-05:00 + 2008-09-10T15:03:06.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 975 + + + BUGTRAQ + 20000208 Remote access vulnerability in all MySQL server versions + + MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:zeus_technologies:zeus_web_server:3.3.1 + cpe:/a:zeus_technologies:zeus_web_server:3.3.5 + cpe:/a:zeus_technologies:zeus_web_server:3.3.4 + cpe:/a:zeus_technologies:zeus_web_server:3.3.3 + cpe:/a:zeus_technologies:zeus_web_server:3.3.2 + cpe:/a:zeus_technologies:zeus_web_server:3.1.6 + cpe:/a:zeus_technologies:zeus_web_server:3.1.7 + cpe:/a:zeus_technologies:zeus_web_server:3.1.4 + cpe:/a:zeus_technologies:zeus_web_server:3.1.5 + cpe:/a:zeus_technologies:zeus_web_server:3.1.8 + cpe:/a:zeus_technologies:zeus_web_server:3.1.9 + cpe:/a:zeus_technologies:zeus_web_server:3.3 + cpe:/a:zeus_technologies:zeus_web_server:3.1.2 + cpe:/a:zeus_technologies:zeus_web_server:3.1.3 + cpe:/a:zeus_technologies:zeus_web_server:3.1.1 + + CVE-2000-0149 + 2000-02-08T00:00:00.000-05:00 + 2008-09-10T15:03:06.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + zeus-server-null-string(3982) + + + BID + 977 + + + OSVDB + 254 + + + BUGTRAQ + 20000208 Zeus Web Server: Null Terminated Strings + + Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL. + + + + + + + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/o:cisco:pix_firewall:4.4%284%29 + cpe:/o:cisco:pix_firewall:4.2%282%29 + cpe:/o:cisco:pix_firewall:4.2%281%29 + cpe:/o:cisco:pix_firewall:5.0 + cpe:/o:cisco:pix_firewall:4.1%286b%29 + cpe:/o:cisco:pix_firewall:4.1%286%29 + cpe:/a:checkpoint:firewall-1:3.0 + cpe:/o:cisco:pix_firewall:4.3 + + CVE-2000-0150 + 2000-02-12T00:00:00.000-05:00 + 2008-09-10T15:03:06.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#328867 + + + BID + 979 + + + OSVDB + 4417 + + Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt. + + + + + + + + + cpe:/a:gnu:make:3.77.44 + + CVE-2000-0151 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:07.007-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 981 + + GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands. + + + + + + + + + + cpe:/a:novell:bordermanager:3.5 + cpe:/a:novell:bordermanager:3.0 + + CVE-2000-0152 + 2000-03-30T00:00:00.000-05:00 + 2008-09-10T15:03:07.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 976 + + + OSVDB + 7468 + + Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000. + + + + + + + + + + cpe:/a:microsoft:personal_web_server:4.0 + cpe:/a:microsoft:frontpage + + CVE-2000-0153 + 1999-03-26T00:00:00.000-05:00 + 2008-09-10T15:03:07.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000216 Doubledot bug in FrontPage FrontPage Personal Web Server. + + + BID + 989 + + FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack. + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0154 + 2000-02-16T00:00:00.000-05:00 + 2008-09-10T15:03:07.397-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 988 + + + MISC + http://www.sco.com/security/ + + + NAI + 20000215 ARCserve symlink vulnerability + + The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0155 + 2000-02-18T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 993 + + + BUGTRAQ + 20000218 AUTORUN.INF Vulnerability + + Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0156 + 2000-02-16T00:00:00.000-05:00 + 2008-09-10T15:03:07.557-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ie-image-source-redirect(3996) + + + OSVDB + 7827 + + + MS + MS00-009 + + Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1 + + CVE-2000-0157 + 2000-02-01T00:00:00.000-05:00 + 2008-09-10T15:03:07.633-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 992 + + + NETBSD + 1999-012 + + NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process. + + + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + + CVE-2000-0158 + 2000-02-16T00:00:00.000-05:00 + 2008-09-10T15:03:07.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + NAI + 20000215 Remote Vulnerability in the MMDF SMTP Daemon + + + SCO + SB-00.06a + + + BID + 997 + + + BUGTRAQ + 20000218 MMDF + + Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0159 + 2000-02-17T00:00:00.000-05:00 + 2008-09-10T15:03:07.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBUX0002-111 + + HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges. + + + + + + + + + + + cpe:/a:microsoft:outlook + cpe:/a:microsoft:ie:5 + cpe:/a:microsoft:ie:4.x + + CVE-2000-0160 + 2000-02-21T00:00:00.000-05:00 + 2008-09-10T15:03:07.867-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000221 Microsoft signed software can be install software without prompting users + + The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft. + + + + + + + + + cpe:/a:microsoft:site_server:3.0 + + CVE-2000-0161 + 2000-02-18T00:00:00.000-05:00 + 2008-09-10T15:03:07.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 994 + + + MS + MS00-010 + + Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands. + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:4.1::windows_nt_4.0 + cpe:/a:microsoft:ie:4.0::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5::windows_nt_4.0 + cpe:/a:microsoft:visual_studio:6.0 + cpe:/a:microsoft:ie:4.0::windows_nt + cpe:/a:microsoft:ie:4.1::windows_95 + + CVE-2000-0162 + 2000-02-18T00:00:00.000-05:00 + 2008-09-10T15:03:08.103-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS00-011 + + The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + + CVE-2000-0163 + 2000-02-21T00:00:00.000-05:00 + 2008-09-10T15:03:08.197-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + FREEBSD + FreeBSD-SA-00:03 + + + BID + 996 + + asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file. + + + + + + + + + cpe:/a:sun:solaris_isp_server:2.0 + + CVE-2000-0164 + 2000-02-20T00:00:00.000-05:00 + 2008-09-10T15:03:08.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1004 + + + BUGTRAQ + 20000220 Sun Internet Mail Server + + The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords. + + + + + + + + + + cpe:/a:etl:delegate:5.9 + cpe:/a:etl:delegate:6.0 + + CVE-2000-0165 + 1999-11-13T00:00:00.000-05:00 + 2008-09-10T15:03:08.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + FREEBSD + FreeBSD-SA-00:04 + + + CIAC + K-023 + + The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands. + + + + + + + + + cpe:/a:interaccess:interaccess_telnetd_server:4.0 + + CVE-2000-0166 + 2000-02-21T00:00:00.000-05:00 + 2008-09-10T15:03:08.397-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT + + + BID + 995 + + Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0167 + 2000-02-15T00:00:00.000-05:00 + 2008-09-10T15:03:08.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000215 Crashing Inetinfo.exe by using a longfilename in the \mailroot\pickup directory + + IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + + CVE-2000-0168 + 2000-03-04T00:00:00.000-05:00 + 2008-09-10T15:03:08.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000306 con\con is a old thing (anyway is cool) + + + MS + MS00-017 + + + BID + 1043 + + Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. + + + + + + + + + cpe:/a:oracle:application_server:4.0 + + CVE-2000-0169 + 2000-03-15T00:00:00.000-05:00 + 2008-09-10T15:03:08.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1053 + + + NTBUGTRAQ + 20000314 Oracle Web Listener 4.0.x + + Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'. + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:4.1 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:redhat:linux:5.0 + cpe:/o:redhat:linux:4.2 + cpe:/o:turbolinux:turbolinux:3.5b2 + + CVE-2000-0170 + 2000-02-26T00:00:00.000-05:00 + 2008-09-10T15:03:08.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1011 + + Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable. + + + + + + + + + cpe:/a:at_computing:atsar_linux:1.4 + + CVE-2000-0171 + 2000-03-11T00:00:00.000-05:00 + 2008-09-10T15:03:08.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1048 + + + BUGTRAQ + 20000311 TESO advisory -- atsadc + + atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges. + + + + + + + + + + + + + + + + + + cpe:/a:matt_kimball_and_roger_wolff:mtr:0.41 + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:turbolinux:turbolinux:3.5b2 + cpe:/a:matt_kimball_and_roger_wolff:mtr:0.28 + cpe:/o:turbolinux:turbolinux:6.0.2 + + CVE-2000-0172 + 2000-03-03T00:00:00.000-05:00 + 2008-09-10T15:03:08.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1038 + + The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges. + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0173 + 2000-03-10T00:00:00.000-05:00 + 2008-09-10T15:03:08.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SCO + SB-00.08a + + Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service. + + + + + + + + + cpe:/a:sun:staroffice:5.1 + + CVE-2000-0174 + 2000-03-09T00:00:00.000-05:00 + 2008-09-10T15:03:09.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1040 + + + BUGTRAQ + 20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities + + StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:sun:staroffice:5.1 + + CVE-2000-0175 + 2000-03-09T00:00:00.000-05:00 + 2008-09-10T15:03:09.087-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1039 + + + BUGTRAQ + 20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities + + Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command. + + + + + + + + + + + + + + cpe:/a:cat_soft:serv-u:2.5a + cpe:/a:cat_soft:serv-u:2.5c + cpe:/a:cat_soft:serv-u:2.5b + cpe:/a:cat_soft:serv-u:2.5d + cpe:/a:cat_soft:serv-u:2.4 + cpe:/a:cat_soft:serv-u:2.5 + + CVE-2000-0176 + 2000-02-29T00:00:00.000-05:00 + 2008-09-10T15:03:09.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1016 + + + BUGTRAQ + 20000228 Serv-U FTP-Server v2.4a showing real path + + The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist. + + + + + + + + + cpe:/a:dnstools_software:dnstools:1.0.8 + + CVE-2000-0177 + 2000-03-02T00:00:00.000-05:00 + 2008-09-10T15:03:09.257-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1028 + + + BUGTRAQ + 20000302 DNSTools v1.08 has no input validation + + DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + cpe:/a:foundrynet:serveriron:6.0 + cpe:/a:foundrynet:serveriron:5.1.10t12 + + CVE-2000-0178 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:09.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.foundrynet.com/bugTraq.html + + + BID + 1017 + + ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions. + + + + + + + + + + + cpe:/a:hp:openview_omniback_ii:3.1 + cpe:/a:hp:openview_omniback_ii:3.0 + cpe:/a:hp:openview_omniback_ii:2.55 + + CVE-2000-0179 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:14.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1015 + + + HP + HPSBUX0006-115 + + + BUGTRAQ + 20000228 HP Omniback remote DoS + + HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555. + + + + + + + + + cpe:/a:generation_terrorists_designs_and_concepts:sojourn:2.0 + + CVE-2000-0180 + 2000-03-14T00:00:00.000-05:00 + 2008-09-05T16:20:20.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1052 + + + NTBUGTRAQ + 20000313 SOJOURN Search engine exposes files + + + XF + sojourn-file-read(4197) + + Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0181 + 2000-03-11T00:00:00.000-05:00 + 2008-09-10T15:03:15.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1054 + + + OSVDB + 1256 + + + BUGTRAQ + 20000311 Our old friend Firewall-1 + + Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1_enterprise + + CVE-2000-0182 + 2000-02-23T00:00:00.000-05:00 + 2008-09-10T15:03:15.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic. + + + + + + + + + cpe:/a:michael_sandrof:ircii:4.4.7 + + CVE-2000-0183 + 2000-03-10T00:00:00.000-05:00 + 2008-09-10T15:03:15.570-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1046 + + + REDHAT + RHSA-2000:008 + + + BUGTRAQ + 20000310 Fwd: ircii-4.4 buffer overflow + + Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability. + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0184 + 2000-03-09T00:00:00.000-05:00 + 2008-09-10T15:03:15.647-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1037 + + + BUGTRAQ + 20000309 + + Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords. + + + + + + + + + + + cpe:/a:realnetworks:realserver:5.0 + cpe:/a:realnetworks:realserver_g2:1.0 + cpe:/a:realnetworks:realserver:7.0 + + CVE-2000-0185 + 2000-03-08T00:00:00.000-05:00 + 2008-09-10T15:03:15.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1049 + + + BUGTRAQ + 20000308 RealServer exposes internal IP addresses + + RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private. + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:redhat:linux:5.1 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0186 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:15.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1020 + + + REDHAT + RHSA-2000:100 + + Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument. + + + + + + + + + cpe:/a:alex_heiphetz_group:ezshopper:3.0 + + CVE-2000-0187 + 2000-02-27T00:00:00.000-05:00 + 2008-09-10T15:03:15.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1014 + + + BUGTRAQ + 20000227 EZ Shopper 3.0 shopping cart CGI remote command execution + + EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. + + + + + + + + + cpe:/a:alex_heiphetz_group:ezshopper:3.0 + + CVE-2000-0188 + 2000-02-27T00:00:00.000-05:00 + 2008-09-10T15:03:15.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1014 + + + BUGTRAQ + 20000227 EZ Shopper 3.0 shopping cart CGI remote command execution + + EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:4.0.1 + cpe:/a:allaire:coldfusion_server:4.5 + + CVE-2000-0189 + 2000-03-01T00:00:00.000-05:00 + 2008-09-10T15:03:16.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1021 + + ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files. + + + + + + + + + cpe:/a:aol:instant_messenger:3.5 + + CVE-2000-0190 + 2000-03-02T00:00:00.000-05:00 + 2008-09-10T15:03:16.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000303 Aol Instant Messenger DoS vulnerability + + AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value. + + + + + + + + + cpe:/h:axis:storpoint_cd + + CVE-2000-0191 + 2000-02-29T00:00:00.000-05:00 + 2008-09-10T15:03:16.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000229 Infosec.20000229.axisstorpointcd.a + + + BID + 1025 + + + OSVDB + 19 + + Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack. + + + + + + + + + cpe:/o:caldera:openlinux:2.3 + + CVE-2000-0192 + 2000-03-05T00:00:00.000-05:00 + 2008-09-10T15:03:16.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1036 + + + BUGTRAQ + 20000304 OpenLinux 2.3: rpm_query + + The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system. + + + + + + + + + cpe:/o:corel:linux:1.0 + + CVE-2000-0193 + 2000-03-02T00:00:00.000-05:00 + 2008-09-10T15:03:16.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1030 + + + BUGTRAQ + 20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln + + The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges. + + + + + + + + + cpe:/o:corel:linux:1.0 + + CVE-2000-0194 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:16.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1007 + + + BUGTRAQ + 20000224 Corel Linux 1.0 local root compromise + + buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters. + + + + + + + + + cpe:/o:corel:linux:1.0 + + CVE-2000-0195 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:16.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1008 + + + BUGTRAQ + 20000224 Corel Linux 1.0 local root compromise + + setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::alpha + cpe:/o:redhat:linux:5.2::i386 + cpe:/a:nmh:nmh:1.0.2 + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:turbolinux:turbolinux:3.5b2 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:5.2::sparc + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0196 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:16.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1018 + + + REDHAT + RHSA-2000:006 + + Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0197 + 2000-02-14T00:00:00.000-05:00 + 2008-09-10T15:03:16.820-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1050 + + + NTBUGTRAQ + 20000313 AT Jobs - Denial of serice/Privilege Elevation + + The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file. + + + + + + + + + + + cpe:/a:atrium_software:mercur_mailserver:3.2 + cpe:/a:atrium_software:mercur_pop3_server:3.20.01 + cpe:/a:atrium_software:mercur_imap4_server:3.20.01 + + CVE-2000-0198 + 2000-03-15T00:00:00.000-05:00 + 2008-09-10T15:03:16.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1051 + + + NTBUGTRAQ + 20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability + + + BUGTRAQ + 20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability + + Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service. + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + + CVE-2000-0199 + 2000-03-14T00:00:00.000-05:00 + 2008-09-10T15:03:16.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1055 + + When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password. + + + + + + + + + + + cpe:/a:microsoft:home_publishing:2000 + cpe:/a:microsoft:greetings:2000 + cpe:/a:microsoft:clip_art:1.0 + + CVE-2000-0200 + 2000-03-06T00:00:00.000-05:00 + 2008-09-10T15:03:17.040-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1034 + + + MS + MS00-015 + + Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0201 + 2000-03-01T00:00:00.000-05:00 + 2008-09-10T15:03:17.117-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1033 + + The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking. + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-0202 + 2000-03-08T00:00:00.000-05:00 + 2008-09-10T15:03:17.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1041 + + + MS + MS00-014 + + Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query. + + + + + + + + + cpe:/a:trend_micro:officescan:3.5 + + CVE-2000-0203 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:17.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.antivirus.com/download/ofce_patch_35.htm + + + BUGTRAQ + 20000228 Re: TrendMicro OfficeScan tmlisten.exe DoS + + + BID + 1013 + + + BUGTRAQ + 20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies + + The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345. + + + + + + + + + cpe:/a:trend_micro:officescan:3.5 + + CVE-2000-0204 + 2000-02-28T00:00:00.000-05:00 + 2008-09-10T15:03:17.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies + + + BID + 1013 + + + BUGTRAQ + 20000226 DOS in Trendmicro OfficeScan + + + MISC + http://www.antivirus.com/download/ofce_patch_35.htm + + The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%. + + + + + + + + + cpe:/a:trend_micro:officescan:3.5 + + CVE-2000-0205 + 2000-03-03T00:00:00.000-05:00 + 2008-09-10T15:03:17.757-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.antivirus.com/download/ofce_patch_35.htm + + + BID + 1013 + + + BUGTRAQ + 20000303 TrendMicro OfficeScan, numerous security holes, remote files modification. + + + BUGTRAQ + 20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies + + Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.5 + + CVE-2000-0206 + 2000-03-05T00:00:00.000-05:00 + 2008-09-10T15:03:18.117-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1035 + + + BUGTRAQ + 20000305 Oracle installer problem + + The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges. + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/a:sgi:infosearch:1.0 + cpe:/o:sgi:irix:6.5.3f + + CVE-2000-0207 + 2000-03-01T00:00:00.000-05:00 + 2008-09-10T15:03:18.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1031 + + + SGI + 20000501-01-P + + SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. + + + + + + + + + + + + + cpe:/a:htdig:htdig:3.2.0b1 + cpe:/a:htdig:htdig:3.1.2 + cpe:/a:htdig:htdig:3.1.3 + cpe:/a:htdig:htdig:3.1.1 + cpe:/a:htdig:htdig:3.1.4 + + CVE-2000-0208 + 2000-02-29T00:00:00.000-05:00 + 2008-09-10T15:03:18.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1026 + + The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch. + + + + + + + + + + + cpe:/a:university_of_kansas:lynx:2.8.3_dev22 + cpe:/a:university_of_kansas:lynx:2.7 + cpe:/a:university_of_kansas:lynx:2.8 + + CVE-2000-0209 + 2000-02-27T00:00:00.000-05:00 + 2008-09-10T15:03:18.790-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1012 + + Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page. + + + + + + + + + cpe:/a:sun:workshop:5.0 + + CVE-2000-0210 + 2000-02-21T00:00:00.000-05:00 + 2008-09-10T15:03:18.853-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 998 + + The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files. + + + + + + + + + + cpe:/a:microsoft:windows_media_services:4.1 + cpe:/a:microsoft:windows_media_services:4.0 + + CVE-2000-0211 + 2000-02-23T00:00:00.000-05:00 + 2008-09-10T15:03:18.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1000 + + + MS + MS00-013 + + The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability. + + + + + + + + + cpe:/a:pragma_systems:interaccess_telnetd_server:4.0 + + CVE-2000-0212 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:19.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + interaccess-telnet-dos(4033) + + + BID + 1001 + + InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information. + + + + + + + + + cpe:/a:sambar:sambar_server:4.2:beta7 + + CVE-2000-0213 + 2000-02-23T00:00:00.000-05:00 + 2008-09-10T15:03:19.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1002 + + + BUGTRAQ + 20000223 Sambar Server alert! + + + CONFIRM + http://www.sambar.com/session/highlight?url=/syshelp/history.htm&words=security+&color=red + + The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters. + + + + + + + + + cpe:/a:ftpx:ftp_explorer:1.00.10 + + CVE-2000-0214 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:19.557-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000224 How the password could be recover using FTP Explorer's registry! + + + BID + 1003 + + FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites. + + + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.0 + cpe:/o:sco:unixware:7.0.1 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0215 + 2000-02-08T00:00:00.000-05:00 + 2008-09-10T15:03:19.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1019 + + Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges. + + + + + + + + + + + cpe:/a:microsoft:exchange_server + cpe:/a:microsoft:outlook + cpe:/a:microsoft:windows_messaging + + CVE-2000-0216 + 2000-02-29T00:00:00.000-05:00 + 2008-09-10T15:03:19.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000229 mailbombing DoS easily exploitable against mail systems using MS mail clients. + + Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.3 + cpe:/a:ssh:ssh:1.2.4 + cpe:/a:ssh:ssh:1.2.1 + cpe:/a:ssh:ssh:1.2.2 + cpe:/a:ssh:ssh:1.2.7 + cpe:/a:ssh:ssh:1.2.8 + cpe:/a:ssh:ssh:1.2.5 + cpe:/a:ssh:ssh:1.2.19 + cpe:/a:ssh:ssh:1.2.6 + cpe:/a:ssh:ssh:1.2.18 + cpe:/a:ssh:ssh2:2.0.9 + cpe:/a:ssh:ssh2:2.0.8 + cpe:/a:ssh:ssh:1.2.0 + cpe:/a:ssh:ssh2:2.0.1 + cpe:/a:ssh:ssh2:2.0.2 + cpe:/a:ssh:ssh2:2.0.3 + cpe:/a:ssh:ssh2:2.0.4 + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh2:2.0.5 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:openbsd:openssh:1.2 + cpe:/a:ssh:ssh2:2.0.6 + cpe:/a:ssh:ssh2:2.0.7 + cpe:/a:ssh:ssh:1.2.16 + cpe:/a:ssh:ssh:1.2.17 + cpe:/a:ssh:ssh:1.2.14 + cpe:/a:ssh:ssh:1.2.9 + cpe:/a:ssh:ssh:1.2.15 + cpe:/a:ssh:ssh:1.2.12 + cpe:/a:ssh:ssh:1.2.13 + cpe:/a:ssh:ssh:1.2.10 + cpe:/a:ssh:ssh:1.2.11 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh2:2.0 + cpe:/a:ssh:ssh:1.2.20 + cpe:/a:ssh:ssh2:2.0.12 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh2:2.0.11 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.21 + cpe:/a:ssh:ssh:1.2.22 + cpe:/a:ssh:ssh2:2.0.10 + cpe:/a:ssh:ssh:1.2.23 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2000-0217 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:19.790-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1006 + + The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program. + + + + + + + + + + cpe:/o:caldera:openlinux:2.3 + cpe:/o:suse:suse_linux + + CVE-2000-0218 + 2000-02-03T00:00:00.000-05:00 + 2008-09-10T15:03:19.853-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 7004 + + + OSVDB + 6980 + + + CALDERA + CSSA-2000-002.0 + + Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname. + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + + CVE-2000-0219 + 2000-02-23T00:00:00.000-05:00 + 2014-11-04T21:12:24.140-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1005 + + + CONFIRM + https://kc.mcafee.com/corporate/index?page=content&id=SB10053 + + + BUGTRAQ + 20000223 redhat 6.0: single user boot security hole + + Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt. + + + + + + + + + cpe:/a:zonelabs:zonealarm:2.0.26 + + CVE-2000-0220 + 2000-02-24T00:00:00.000-05:00 + 2008-09-10T15:03:20.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event. + + + + + + + + + cpe:/h:nortel:nautica_marlin + + CVE-2000-0221 + 2000-02-25T00:00:00.000-05:00 + 2008-09-10T15:03:20.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1009 + + The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_2000:::professional + + CVE-2000-0222 + 2000-02-15T00:00:00.000-05:00 + 2008-09-10T15:03:20.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000215 Windows 2000 installation process weakness + + + BID + 990 + + The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs. + + + + + + + + + cpe:/a:sam_hawker:wmcdplay:1.0_beta2 + + CVE-2000-0223 + 2000-03-10T00:00:00.000-05:00 + 2008-09-10T15:03:20.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1047 + + + BUGTRAQ + 20000311 TESO advisory -- wmcdplay + + Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter. + + + + + + + + + + cpe:/o:sco:unixware:7.1.1 + cpe:/o:sco:unixware:7.1 + + CVE-2000-0224 + 2000-02-15T00:00:00.000-05:00 + 2008-09-10T15:03:20.307-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NAI + 20000215 ARCserve symlink vulnerability + + ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack. + + + + + + + + + cpe:/a:deti_fliegl:poc32:2.05 + + CVE-2000-0225 + 2000-03-07T00:00:00.000-05:00 + 2008-09-10T15:03:20.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1032 + + + BUGTRAQ + 20000303 Pocsag remote access to client can't be disabled. + + + OSVDB + 259 + + The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0226 + 2000-03-20T00:00:00.000-05:00 + 2008-09-10T15:03:20.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-018 + + + BID + 1066 + + IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.3.99:pre2 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.14 + + CVE-2000-0227 + 2000-03-23T00:00:00.000-05:00 + 2008-09-10T15:03:20.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-domain-socket-dos(4186) + + + BID + 1072 + + + BUGTRAQ + 20000323 Local Denial-of-Service attack against Linux + + + BUGTRAQ + 20000328 Re: Local Denial-of-Service attack against Linux + + The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets. + + + + + + + + + + cpe:/a:microsoft:windows_media_rights_manager:4.0 + cpe:/a:microsoft:windows_media_rights_manager:4.1 + + CVE-2000-0228 + 2000-03-17T00:00:00.000-05:00 + 2008-09-10T15:03:20.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-016 + + + BID + 1058 + + Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:suse:suse_linux:5.3 + cpe:/o:debian:debian_linux:2.2::pre_potato + cpe:/o:alessandro_rubini:gpm:1.18.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:alessandro_rubini:gpm:1.19 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:suse:suse_linux:6.0 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0229 + 2000-03-22T00:00:00.000-05:00 + 2008-09-10T15:03:40.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1069 + + + REDHAT + RHSA-2000:045 + + + REDHAT + RHSA-2000:009 + + + SUSE + 20000405 Security hole in gpm < 1.18.1 + + + BUGTRAQ + 20000322 gpm-root + + gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root. + + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:halloween:halloween_linux:4.0 + + CVE-2000-0230 + 2000-03-13T00:00:00.000-05:00 + 2008-09-10T15:03:40.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1060 + + + REDHAT + RHSA-2000:016 + + + BUGTRAQ + 20000316 TESO & C-Skills development advisory -- imwheel + + Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable. + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:halloween:halloween_linux:4.0 + cpe:/o:suse:suse_linux:6.0 + + CVE-2000-0231 + 2000-03-16T00:00:00.000-05:00 + 2008-09-10T15:03:40.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1061 + + + BUGTRAQ + 20000316 "TESO & C-Skills development advisory -- kreatecd" at: + + Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges. + + + + + + + + + + + + + + + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0232 + 2000-03-30T00:00:00.000-05:00 + 2008-09-10T15:03:40.913-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-021 + + + BID + 1082 + + + BUGTRAQ + 20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability + + Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request. + + + + + + + + + cpe:/a:suse:suse_linux_imap_server:1.0 + + CVE-2000-0233 + 2000-03-15T00:00:00.000-05:00 + 2008-09-10T15:03:40.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUSE + 20000327 Security hole in SuSE Linux IMAP Server + + SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges. + + + + + + + + + + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2000-0234 + 2000-03-31T00:00:00.000-05:00 + 2008-09-10T15:03:41.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.securityfocus.com/templates/advisory.html?id=2150 + + + BUGTRAQ + 20000330 Cobalt apache configuration exposes .htaccess + + + BID + 1083 + + The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + + CVE-2000-0235 + 2000-03-27T00:00:00.000-05:00 + 2011-03-07T21:02:49.423-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-00:10 + + + BID + 1070 + + + OSVDB + 1263 + + Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges. + + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.0 + cpe:/a:netscape:enterprise_server:3.5.1 + cpe:/a:netscape:enterprise_server:3.6 + + CVE-2000-0236 + 2000-03-17T00:00:00.000-05:00 + 2008-09-10T15:03:41.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags + + + BID + 1063 + + Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump. + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.6 + cpe:/a:netscape:enterprise_server:3.5 + + CVE-2000-0237 + 2000-03-11T00:00:00.000-05:00 + 2008-09-10T15:03:41.647-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1075 + + + MISC + http://zsh.stupidphat.com/advisory.cgi?000311-1 + + Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories. + + + + + + + + + cpe:/a:symantec:norton_antivirus:1.0::internet_email_gateways + + CVE-2000-0238 + 2000-03-17T00:00:00.000-05:00 + 2008-09-10T15:03:42.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1064 + + + BUGTRAQ + 20000317 DoS with NAVIEG + + Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + cpe:/a:atrium_software:mercur_mailserver:3.2 + cpe:/a:atrium_software:mercur_pop3_server:3.20.01 + cpe:/a:atrium_software:mercur_imap4_server:3.20.01 + + CVE-2000-0239 + 2000-03-15T00:00:00.000-05:00 + 2008-09-10T15:03:42.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000315 Local / Remote DoS Attack in MERCUR WebView WebMail-Client 1.0 + + + BID + 1056 + + + BUGTRAQ + 20000315 Local / Remote DoS Attack in MERCUR WebView WebMail-Client 1.0 + + Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request. + + + + + + + + + cpe:/a:vqsoft:vqserver:1.9.9 + + CVE-2000-0240 + 2000-03-21T00:00:00.000-05:00 + 2008-09-10T15:03:43.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1067 + + + CONFIRM + http://www.vqsoft.com/vq/server/faqs/dotdotbug.html + + + BUGTRAQ + 20000321 vqserver /........../ + + + OSVDB + 270 + + vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack. + + + + + + + + + cpe:/a:vqsoft:vqserver:1.9.9 + + CVE-2000-0241 + 2000-03-21T00:00:00.000-05:00 + 2008-09-10T15:03:43.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000321 vqserver /........../ + + + BID + 1068 + + vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges. + + + + + + + + + cpe:/a:geocel:windmail:3.0 + + CVE-2000-0242 + 2000-03-25T00:00:00.000-05:00 + 2008-09-10T15:03:43.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1073 + + + BUGTRAQ + 20000325 Windmail allow web user get any file + + WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters. + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.0.3 + + CVE-2000-0243 + 2000-03-25T00:00:00.000-05:00 + 2008-09-10T15:03:44.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1076 + + + MISC + http://www.analogx.com/contents/download/network/sswww.htm + + + XF + simpleserver-exception-dos(4189) + + + BUGTRAQ + 20000324 AnalogX SimpleServer 1.03 Remote Crash" at: + + + OSVDB + 1265 + + AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. + + + + + + + + + + + + cpe:/a:citrix:metaframe:1.0::unix + cpe:/a:citrix:metaframe:1.8::windows_nt_4.0_tse + cpe:/a:citrix:winframe:3.5_1.8_for_windows_nt + cpe:/a:citrix:metaframe:1.8::windows_2000 + + CVE-2000-0244 + 2000-03-29T00:00:00.000-05:00 + 2008-09-10T15:03:44.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1077 + + + BUGTRAQ + 20000328 Citrix ICA Basic Encryption + + The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.1 + + CVE-2000-0245 + 2000-03-27T00:00:00.000-05:00 + 2008-09-10T15:03:45.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000328 Objectserver vulnerability + + + XF + irix-objectserver-create-accounts(4206) + + + BID + 1079 + + + OSVDB + 1267 + + + CIAC + K-030 + + + SGI + 20000303-01-PX + + Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:commercial_internet_system:2.5 + cpe:/a:microsoft:commercial_internet_system:2.0 + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0 + cpe:/a:microsoft:proxy_server:2.0 + + CVE-2000-0246 + 2000-03-30T00:00:00.000-05:00 + 2008-09-10T15:03:45.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-019 + + + BID + 1081 + + + MSKB + Q249599 + + IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. + + + + + + + + + + cpe:/a:gnqs:gnqs:3.50.6 + cpe:/a:gnqs:gnqs:3.50.7 + + CVE-2000-0247 + 2000-03-22T00:00:00.000-05:00 + 2008-09-05T16:20:30.973-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000322 Local root compromise in GNQS 3.50.6 and 3.50.7 + + + XF + generic-nqs-local-root(4306) + + + BID + 1842 + + + MISC + http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt + + + FREEBSD + FreeBSD-SA-00:13 + + Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges. + + + + + + + + + + + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + + CVE-2000-0248 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:03:45.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ISS + 20000424 Backdoor Password in Red Hat Linux Virtual Server Package + + The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands. + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + + CVE-2000-0249 + 2000-04-26T00:00:00.000-04:00 + 2008-09-10T15:03:45.930-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ISS + 20000426 Insecure file handling in IBM AIX frcactrl program + + + BID + 1152 + + The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program. + + + + + + + + + cpe:/a:qnx:qnx:4.25a + + CVE-2000-0250 + 2000-04-14T00:00:00.000-04:00 + 2008-09-10T15:03:45.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1114 + + + BUGTRAQ + 20000414 qnx crypt comprimised + + The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords. + + + + + + + + + + cpe:/o:hp:hp-ux:11.4 + cpe:/o:hp:vvos:3.50 + + CVE-2000-0251 + 2000-04-06T00:00:00.000-04:00 + 2008-09-10T15:03:46.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1090 + + + HP + HPSBUX0004-112 + + HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses. + + + + + + + + + cpe:/a:craig_dansie:dansie_shopping_cart:3.0.4 + + CVE-2000-0252 + 2000-04-11T00:00:00.000-04:00 + 2008-09-10T15:03:46.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1115 + + + BUGTRAQ + 20000411 Back Door in Commercial Shopping Cart + + + XF + dansie-shell-metacharacters + + The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable. + + + + + + + + + cpe:/a:craig_dansie:dansie_shopping_cart:3.0.4 + + CVE-2000-0253 + 2000-04-11T00:00:00.000-04:00 + 2008-09-10T15:03:46.210-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + shopping-cart-form-tampering + + + BID + 1115 + + The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields. + + + + + + + + + cpe:/a:craig_dansie:dansie_shopping_cart:3.0.4 + + CVE-2000-0254 + 2000-04-14T00:00:00.000-04:00 + 2008-09-10T15:03:46.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dansie-form-variables + + + BID + 1115 + + The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables. + + + + + + + + + cpe:/h:nbase-xyplex:edgeblaster:1.0 + + CVE-2000-0255 + 2000-04-05T00:00:00.000-04:00 + 2008-09-10T15:03:46.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1091 + + + BUGTRAQ + 20000405 SilverBack Security Advisory: Nbase-Xyplex DoS + + The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program. + + + + + + + + + + + cpe:/a:microsoft:personal_web_server:2.0 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/a:microsoft:frontpage + + CVE-2000-0256 + 2000-04-19T00:00:00.000-04:00 + 2008-09-10T15:03:46.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1117 + + + MS + MS00-028 + + + XF + frontpage-cern-bo(34720) + + + BUGTRAQ + 20070603 CERN &#304;mage Map Dispatcher + + Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability. + + + + + + + + + cpe:/o:novell:netware:5.1 + + CVE-2000-0257 + 2000-04-19T00:00:00.000-04:00 + 2008-09-10T15:03:46.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1118 + + + BUGTRAQ + 20000418 Novell Netware 5.1 (server 5.00h, Dec 11, 1999)... + + Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0258 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:03:46.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-023 + + + BID + 1101 + + IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. + + + + + + + + + + + + + + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0259 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:03:46.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1105 + + + MS + MS00-024 + + The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. + + + + + + + + + + cpe:/a:microsoft:visual_interdev:1.0 + cpe:/a:microsoft:frontpage + + CVE-2000-0260 + 2000-04-14T00:00:00.000-04:00 + 2008-09-10T15:03:46.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS00-025 + + + BID + 1109 + + + OSVDB + 282 + + Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability. + + + + + + + + + + cpe:/a:avm:ken:1.3.10 + cpe:/a:avm:ken:1.4.30 + + CVE-2000-0261 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:03:46.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000418 AVM's Statement + + + BID + 1103 + + + OSVDB + 1282 + + + BUGTRAQ + 20000415 (no subject) + + The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:avm:ken:1.3.10 + cpe:/a:avm:ken:1.4.30 + + CVE-2000-0262 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:03:46.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000418 AVM's Statement + + + BID + 1103 + + + BUGTRAQ + 20000415 (no subject) + + The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request. + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0263 + 2000-04-16T00:00:00.000-04:00 + 2008-09-10T15:03:47.007-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1111 + + + BUGTRAQ + 20000416 xfs + + The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request. + + + + + + + + + cpe:/a:panda:panda_security:3.0 + + CVE-2000-0264 + 2000-04-17T00:00:00.000-04:00 + 2008-09-10T15:03:47.587-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip + + + BUGTRAQ + 20000417 bugs in Panda Security 3.0 + + + BID + 1119 + + Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods. + + + + + + + + + cpe:/a:panda:panda_security:3.0 + + CVE-2000-0265 + 2000-04-17T00:00:00.000-04:00 + 2008-09-10T15:03:47.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000417 bugs in Panda Security 3.0 + + + BID + 1119 + + + CONFIRM + http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip + + Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet. + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0266 + 2000-04-18T00:00:00.000-04:00 + 2008-09-10T15:03:47.727-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1121 + + + BUGTRAQ + 20000418 IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy) + + Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. + + + + + + + + + cpe:/o:cisco:catos:5.4%281%29 + + CVE-2000-0267 + 2000-04-20T00:00:00.000-04:00 + 2008-09-10T15:03:47.807-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CISCO + 20000419 Cisco Catalyst Enable Password Bypass Vulnerability + + + BID + 1122 + + + OSVDB + 1288 + + Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:accesspath:vs-3 + cpe:/a:cisco:as5800 + cpe:/o:cisco:ios:12.0%284%29t + cpe:/h:cisco:3660_router + cpe:/o:cisco:ios:12.0%284%29s + cpe:/o:cisco:ios:12.0%287%29t + cpe:/a:cisco:as5300 + cpe:/o:cisco:ios:11.3aa + cpe:/h:cisco:7100_router + cpe:/o:cisco:ios:12.0%285%29 + cpe:/a:cisco:accesspath:ts-3 + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%282%29xg + cpe:/o:cisco:ios:12.0%282%29xf + cpe:/o:cisco:ios:12.0%282%29xc + cpe:/a:cisco:system_controller_3640 + cpe:/h:cisco:voice_gateway_as5800 + cpe:/o:cisco:ios:12.0%284%29 + cpe:/h:cisco:ubr7200 + cpe:/h:cisco:7500_router + cpe:/h:cisco:7200_router + cpe:/o:cisco:ios:12.0%282%29 + cpe:/a:cisco:accesspath:ls-3 + cpe:/a:cisco:as5200 + cpe:/o:cisco:ios:12.0%286%29 + cpe:/o:cisco:ios:12.0%283%29t2 + + CVE-2000-0268 + 2000-04-20T00:00:00.000-04:00 + 2008-09-10T15:03:47.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20000420 Cisco IOS Software TELNET Option Handling Vulnerability + + + BID + 1123 + + + OSVDB + 1289 + + Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot. + + + + + + + + + + + + + + + cpe:/a:gnu:emacs:20.0 + cpe:/a:gnu:emacs:20.4 + cpe:/a:gnu:emacs:20.3 + cpe:/a:gnu:emacs:20.2 + cpe:/a:gnu:emacs:20.1 + cpe:/a:gnu:emacs:20.6 + cpe:/a:gnu:emacs:20.5 + + CVE-2000-0269 + 2000-04-18T00:00:00.000-04:00 + 2008-09-10T15:03:47.930-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1125 + + + BUGTRAQ + 20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20 + + Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess. + + + + + + + + + + + + + + + cpe:/a:gnu:emacs:20.0 + cpe:/a:gnu:emacs:20.4 + cpe:/a:gnu:emacs:20.3 + cpe:/a:gnu:emacs:20.2 + cpe:/a:gnu:emacs:20.1 + cpe:/a:gnu:emacs:20.6 + cpe:/a:gnu:emacs:20.5 + + CVE-2000-0270 + 2000-04-18T00:00:00.000-04:00 + 2008-09-10T15:03:48.007-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1125 + + + BUGTRAQ + 20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20 + + The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack. + + + + + + + + + + + + + + + cpe:/a:gnu:emacs:20.0 + cpe:/a:gnu:emacs:20.4 + cpe:/a:gnu:emacs:20.3 + cpe:/a:gnu:emacs:20.2 + cpe:/a:gnu:emacs:20.1 + cpe:/a:gnu:emacs:20.6 + cpe:/a:gnu:emacs:20.5 + + CVE-2000-0271 + 2000-04-18T00:00:00.000-04:00 + 2008-09-10T15:03:48.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1125 + + + BUGTRAQ + 20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20 + + read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords. + + + + + + + + + + + + + + cpe:/a:realnetworks:realserver:plus + cpe:/a:realnetworks:realserver:intranet + cpe:/a:realnetworks:realserver:basic + cpe:/a:realnetworks:realserver:g2_1.0 + cpe:/a:realnetworks:realserver:pro + cpe:/a:realnetworks:realserver:7.0 + + CVE-2000-0272 + 2000-04-20T00:00:00.000-04:00 + 2008-09-10T15:03:48.147-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1128 + + + CONFIRM + http://service.real.com/help/faq/servg270.html + + + BUGTRAQ + 20000420 Remote DoS attack in Real Networks Real Server Vulnerability + + RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070. + + + + + + + + + + cpe:/a:symantec:pcanywhere:9.0 + cpe:/a:symantec:pcanywhere:8.0 + + CVE-2000-0273 + 2000-04-09T00:00:00.000-04:00 + 2008-09-10T15:03:48.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1095 + + + BUGTRAQ + 20000409 A funny way to DOS pcANYWHERE8.0 and 9.0 + + PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt. + + + + + + + + + cpe:/o:bray_systems:linux_trustees:1.5 + + CVE-2000-0274 + 2000-04-10T00:00:00.000-04:00 + 2008-09-10T15:03:48.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.braysystems.com/linux/trustees.html + + + BID + 1096 + + + BUGTRAQ + 20000410 linux trustees 1.5 long path name vulnerability + + The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name. + + + + + + + + + cpe:/a:cryptocard:cryptoadmin:4.1 + + CVE-2000-0275 + 2000-04-10T00:00:00.000-04:00 + 2008-09-10T15:03:54.663-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1097 + + + L0PHT + 20000410 CRYPTOCard PalmToken PIN Extraction + + + BUGTRAQ + 20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ion + + CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN. + + + + + + + + + + cpe:/o:be:beos:5.0 + cpe:/o:be:beos:4.5 + + CVE-2000-0276 + 2000-04-10T00:00:00.000-04:00 + 2008-09-10T15:03:54.727-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1098 + + + BUGTRAQ + 20000410 BeOS syscall bug + + BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37. + + + + + + + + + + cpe:/a:microsoft:excel:97 + cpe:/a:microsoft:excel:2000 + + CVE-2000-0277 + 2000-04-03T00:00:00.000-04:00 + 2008-09-10T15:03:54.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS00-022 + + + BID + 1087 + + + OSVDB + 1272 + + Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability. + + + + + + + + + cpe:/a:saleslogix:corporation_eviewer:1.0 + + CVE-2000-0278 + 2000-08-03T00:00:00.000-04:00 + 2008-09-10T15:03:54.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1089 + + + BUGTRAQ + 20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application + + The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user. + + + + + + + + + + + cpe:/o:be:beos:5.0 + cpe:/o:be:beos:4.5 + cpe:/o:be:beos:4.0 + + CVE-2000-0279 + 2000-04-07T00:00:00.000-04:00 + 2008-09-10T15:03:59.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1100 + + + MISC + http://bebugs.be.com/devbugs/detail.php3?oid=2505312 + + + BUGTRAQ + 20000407 BeOS Networking DOS + + BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers. + + + + + + + + + + cpe:/a:realnetworks:realplayer:7.0::win + cpe:/a:realnetworks:realplayer:6.0::win + + CVE-2000-0280 + 2000-04-03T00:00:00.000-04:00 + 2008-09-05T16:20:36.033-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1088 + + + BUGTRAQ + 20000403 Win32 RealPlayer 6/7 Buffer Overflow + + Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL. + + + + + + + + + cpe:/a:napster:napster_client:beta_5 + + CVE-2000-0281 + 2000-03-26T00:00:00.000-05:00 + 2008-09-05T16:20:36.177-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000330 Napster, Inc. response to Colten Edwards + + + BUGTRAQ + 20000326 neat little napster bug + + Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message. + + + + + + + + + cpe:/a:talentsoft:web%2b:4 + + CVE-2000-0282 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:03:59.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1102 + + + BUGTRAQ + 20000412 TalentSoft Web+ Input Validation Bug Vulnerability + + + CONFIRM + ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html + + TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.5.3f + + CVE-2000-0283 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:04:00.087-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1106 + + + BUGTRAQ + 20000412 Performance Copilot for IRIX 6.5 + + The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon. + + + + + + + + + cpe:/a:university_of_washington:imap:12.264 + + CVE-2000-0284 + 2000-04-16T00:00:00.000-04:00 + 2008-09-10T15:04:00.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1110 + + + BUGTRAQ + 20000416 imapd4r1 v12.264 + + + BUGTRAQ + 20000416 imapd4r1 v12.264 + + Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands. + + + + + + + + + + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:xfree86_project:x11r6:3.3.6 + + CVE-2000-0285 + 2000-04-16T00:00:00.000-04:00 + 2008-09-10T15:04:00.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000416 XFree86 server overflow + + + BID + 1306 + + Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter. + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0286 + 2000-04-16T00:00:00.000-04:00 + 2008-09-10T15:04:00.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1111 + + + BUGTRAQ + 20000416 xfs + + X fontserver xfs allows local users to cause a denial of service via malformed input to the server. + + + + + + + + + cpe:/a:cnc:technology_bizdb:1.0 + + CVE-2000-0287 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:04:00.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1104 + + + BUGTRAQ + 20000412 BizDB Search Script Enables Shell Command Execution at the Server + + The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter. + + + CVE-2000-0288 + 2000-04-12T00:00:00.000-04:00 + 2008-09-10T15:04:00.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000412 Infonautic's getdoc.cgi may allow unauthorized access to documents + + Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable. + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:debian:debian_linux:2.2::pre_potato + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0289 + 2000-03-27T00:00:00.000-05:00 + 2008-09-10T15:04:00.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1078 + + + BUGTRAQ + 20000327 Security Problems with Linux 2.2.x IP Masquerading + + + SUSE + 20000520 Security hole in kernel < 2.2.15 + + IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection. + + + + + + + + + cpe:/a:4d:webstar_http_server:4.0 + + CVE-2000-0290 + 2000-03-31T00:00:00.000-05:00 + 2008-09-10T15:04:00.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000331 Webstar 4.0 Buffer overflow vulnerability + + + XF + macos-webstar-get-bo(4792) + + + BID + 1822 + + Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request. + + + + + + + + + cpe:/a:sun:staroffice:5.1 + + CVE-2000-0291 + 2000-04-16T00:00:00.000-04:00 + 2008-09-10T15:04:00.697-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1112 + + + BUGTRAQ + 20000416 StarOffice 5.1 + + Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document. + + + + + + + + + cpe:/h:adtran:mx2800:m13 + + CVE-2000-0292 + 2000-04-19T00:00:00.000-04:00 + 2008-09-10T15:04:00.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000418 Adtran DoS + + + BID + 1129 + + The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash. + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.1:alpha + cpe:/o:suse:suse_linux:6.0 + + CVE-2000-0293 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:00.837-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1130 + + aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory. + + + + + + + + + + + cpe:/a:jim_housley:healthd:0.1 + cpe:/a:jim_housley:healthd:0.3 + cpe:/a:jim_housley:healthd:0.2 + + CVE-2000-0294 + 2000-04-10T00:00:00.000-04:00 + 2008-09-10T15:04:00.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-00:12 + + + BID + 1107 + + + OSVDB + 606 + + Buffer overflow in healthd for FreeBSD allows local users to gain root privileges. + + + + + + + + + cpe:/a:lcdproc:lcdproc:0.4 + + CVE-2000-0295 + 2000-04-21T00:00:00.000-04:00 + 2008-09-10T15:04:00.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000420 Remote vulnerability in LCDproc 0.4 + + + BID + 1131 + + + XF + lcdproc-remote-overflow(4315) + + + GENTOO + GLSA-200301-07 + + Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command. + + + + + + + + + cpe:/a:michael_a._gumienny:fcheck:2.7.45 + + CVE-2000-0296 + 2000-03-31T00:00:00.000-05:00 + 2008-09-10T15:04:01.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1086 + + + BUGTRAQ + 20000331 fcheck v.2.7.45 and insecure use of Perl's system() + + fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck. + + + + + + + + + cpe:/a:allaire:forums:2.0.5 + + CVE-2000-0297 + 2000-04-03T00:00:00.000-04:00 + 2008-09-10T15:04:02.557-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB00-06 + + + BID + 1085 + + + OSVDB + 1270 + + Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0298 + 2000-04-07T00:00:00.000-04:00 + 2008-09-10T15:04:02.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + win2k-unattended-install(4278) + + + BID + 1758 + + + NTBUGTRAQ + 20000407 All Users startup folder left open if unattended install and OEMP reinstall=1 + + The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. + + + + + + + + + cpe:/a:apple:webobjects:4.5 + + CVE-2000-0299 + 2000-04-04T00:00:00.000-04:00 + 2008-09-10T15:04:02.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000404 WebObjects DoS + + Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept. + + + + + + + + + cpe:/a:symantec:pcanywhere:9.0 + + CVE-2000-0300 + 2000-04-06T00:00:00.000-04:00 + 2008-09-10T15:04:02.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1093 + + + BUGTRAQ + 20000405 PcAnywhere weak password encryption + + The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts. + + + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:5.0.8 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:5.0 + cpe:/a:ipswitch:imail:5.0.5 + cpe:/a:ipswitch:imail:6.0 + cpe:/a:ipswitch:imail:5.0.6 + cpe:/a:ipswitch:imail:5.0.7 + + CVE-2000-0301 + 2000-04-06T00:00:00.000-04:00 + 2008-09-10T15:04:02.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1094 + + + CONFIRM + http://support.ipswitch.com/kb/IM-20000208-DM02.htm + + + BUGTRAQ + 20000405 Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm) + + Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command. + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-2000-0302 + 2000-03-31T00:00:00.000-05:00 + 2008-09-05T16:20:39.363-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-006 + + + BUGTRAQ + 20000331 Alert: MS Index Server (CISADV000330) + + + BID + 1084 + + + OSVDB + 271 + + Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. + + + + + + + + + cpe:/a:id_software:quake_3_arena:1.16n + + CVE-2000-0303 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:03.257-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.quake3arena.com/news/index.html + + + ISS + 20000503 Vulnerability in Quake3Arena Auto-Download Feature + + + BID + 1169 + + + OSVDB + 7531 + + Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0304 + 2000-05-10T00:00:00.000-04:00 + 2008-09-10T15:04:03.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20000511 Microsoft IIS Remote Denial of Service Attack + + + BID + 1191 + + + MS + MS00-031 + + Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability. + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/a:microsoft:terminal_server + cpe:/o:be:beos:5.0 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0305 + 2000-05-19T00:00:00.000-04:00 + 2008-09-10T15:04:03.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-029 + + + BINDVIEW + 20000519 jolt2 - Remote DoS against NT, W2K, 9x + + + BID + 1236 + + Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability. + + + + + + + + + cpe:/o:sco:openserver:5.04 + + CVE-2000-0306 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:40.017-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19981229 Local/remote exploit for SCO UNIX. + + + SCO + SB-99.02 + + Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message. + + + + + + + + + + + cpe:/o:sco:openserver:5.05 + cpe:/o:sco:open_desktop + cpe:/o:sco:unixware:2.1.3 + + CVE-2000-0307 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:40.160-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SCO + SB-99.07 + + Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024. + + + + + + + + + + + + + + + + + + cpe:/a:netscape:fasttrack_server:2.01 + cpe:/o:sco:unixware:7.0 + cpe:/a:netscape:fasttrack_server:2.0 + cpe:/a:netscape:enterprise_server:2.0 + cpe:/a:netscape:proxy_server:2.5 + cpe:/o:sco:unixware:2.1.3 + + CVE-2000-0308 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:40.317-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SCO + SB-99.08 + + Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges. + + + + + + + + + cpe:/o:openbsd:openbsd:2.4 + + CVE-2000-0309 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:04:03.757-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6126 + + + OPENBSD + 19990212 i386 trace-trap handling when DDB was configured could cause a system crash. + + The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service. + + + + + + + + + cpe:/o:openbsd:openbsd:2.4 + + CVE-2000-0310 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:04:03.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 7539 + + + OPENBSD + 19990217 IP fragment assembly can bog the machine excessively and cause problems. + + IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0311 + 2000-04-20T00:00:00.000-04:00 + 2008-09-10T15:04:03.897-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-026 + + + BID + 1145 + + The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability. + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + + CVE-2000-0312 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:40.910-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OPENBSD + 19990830 In cron(8), make sure argv[] is NULL terminated in the fake popen() and run sendmail as the user, not as root. + + cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function. + + + + + + + + + cpe:/o:openbsd:openbsd:2.6 + + CVE-2000-0313 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:04:04.040-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + OSVDB + 7540 + + + OPENBSD + 19991109 Any user can change interface media configurations. + + Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations. + + + + + + + + + + + + + cpe:/o:redhat:linux:2.0.34 + cpe:/o:debian:debian_linux:2.0.34 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:slackware:slackware_linux:2.0.34 + cpe:/o:digital:unix:4.0 + + CVE-2000-0314 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:41.207-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NETBSD + NetBSD-SA1999-004 + + + BUGTRAQ + 19990213 traceroute as a flooder + + + OSVDB + 7574 + + traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero. + + + + + + + + + + + + + cpe:/o:redhat:linux:2.0.34 + cpe:/o:debian:debian_linux:2.0.34 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:slackware:slackware_linux:2.0.34 + cpe:/o:digital:unix:4.0 + + CVE-2000-0315 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:41.363-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NETBSD + NetBSD-SA1999-004 + + + BUGTRAQ + 19990213 traceroute as a flooder + + + OSVDB + 7575 + + traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks. + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + + CVE-2000-0316 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:04.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1143 + + + BUGTRAQ + 20000424 Solaris 7 x86 lp exploit + + Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + + CVE-2000-0317 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:04.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1138 + + + BUGTRAQ + 20000424 Solaris 7 x86 lpset exploit. + + + BUGTRAQ + 20000424 Solaris 7 x86 lpset exploit. + + + BUGTRAQ + 20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !) + + Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option. + + + + + + + + + cpe:/a:atrium_software:mercur_mailserver:3.2 + + CVE-2000-0318 + 2000-04-21T00:00:00.000-04:00 + 2008-09-10T15:04:04.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1144 + + + NTBUGTRAQ + 20000413 Security problems with Atrium Mercur Mailserver 3.20 + + Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:eric_allman:sendmail:8.8.x + cpe:/a:eric_allman:sendmail:8.8.4 + cpe:/a:eric_allman:sendmail:8.8.5 + cpe:/a:eric_allman:sendmail:8.6.x + cpe:/a:eric_allman:sendmail:8.7.5 + cpe:/a:eric_allman:sendmail:8.9.1 + cpe:/a:eric_allman:sendmail:8.7.6 + cpe:/a:eric_allman:sendmail:8.8.2 + cpe:/a:eric_allman:sendmail:8.7.x + cpe:/a:eric_allman:sendmail:8.8.3 + cpe:/a:eric_allman:sendmail:8.8.1 + cpe:/a:eric_allman:sendmail:8.9.3 + cpe:/a:eric_allman:sendmail:8.7.4 + cpe:/a:eric_allman:sendmail:8.7.3 + cpe:/a:eric_allman:sendmail:8.7.2 + cpe:/a:eric_allman:sendmail:8.8 + cpe:/a:eric_allman:sendmail:8.7.1 + cpe:/a:eric_allman:sendmail:5.59 + cpe:/a:eric_allman:sendmail:5.58 + + CVE-2000-0319 + 2000-04-23T00:00:00.000-04:00 + 2008-09-10T15:04:04.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1146 + + + BUGTRAQ + 20000424 unsafe fgets() in sendmail's mail.local + + mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n. + + + + + + + + + + + + cpe:/a:qualcomm:qpopper:2.53 + cpe:/h:sun:cobalt_raq_2 + cpe:/a:qualcomm:qpopper:3.0 + cpe:/h:sun:cobalt_raq_3i + + CVE-2000-0320 + 2000-04-21T00:00:00.000-04:00 + 2008-09-10T15:04:04.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000421 unsafe fgets() in qpopper + + + BID + 1133 + + Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n. + + + + + + + + + cpe:/a:icradius:icradius:0.14 + + CVE-2000-0321 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:04.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1147 + + + BUGTRAQ + 20000424 Buffer Overflow in version .14 + + Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name. + + + + + + + + + + + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + + CVE-2000-0322 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:04.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1149 + + + BUGTRAQ + 20000424 piranha default password/exploit + + + REDHAT + RHSA-2000:014 + + The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execure arbitrary commands via shell metacharacters. + + + + + + + + + + + cpe:/a:microsoft:jet:4.0 + cpe:/a:microsoft:jet:3.5 + cpe:/a:microsoft:jet:3.51 + + CVE-2000-0323 + 1999-07-28T00:00:00.000-04:00 + 2008-09-10T15:04:04.727-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19990728 Alert : MS Office 97 Vulnerability + + + BID + 595 + + + MS + MS99-030 + + The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability. + + + + + + + + + + + + cpe:/a:symantec:pcanywhere:9.0 + cpe:/a:symantec:pcanywhere:8.0.2 + cpe:/a:symantec:pcanywhere:9.2 + cpe:/a:symantec:pcanywhere:8.0.1 + + CVE-2000-0324 + 2000-04-25T00:00:00.000-04:00 + 2008-09-10T15:04:05.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000425 Denial of Service Against pcAnywhere. + + + BID + 1150 + + + OSVDB + 1301 + + + XF + pcanywhere-tcpsyn-dos(4347) + + + BUGTRAQ + 20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow + + + BUGTRAQ + 20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow + + pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap. + + + + + + + + + + cpe:/a:microsoft:jet:3.5.1 + cpe:/a:microsoft:jet:3.5 + + CVE-2000-0325 + 1999-08-20T00:00:00.000-04:00 + 2008-09-10T15:04:05.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + jet-vba-shell(3155) + + + BID + 548 + + + MS + MS99-030 + + The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. + + + + + + + + + + + + + + cpe:/a:on_technology:meeting_maker:1.0 + cpe:/a:on_technology:meeting_maker:6.0 + cpe:/a:on_technology:meeting_maker:3.0 + cpe:/a:on_technology:meeting_maker:2.0 + cpe:/a:on_technology:meeting_maker:4.0 + cpe:/a:on_technology:meeting_maker:5.0 + + CVE-2000-0326 + 2000-04-25T00:00:00.000-04:00 + 2008-09-10T15:04:07.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1151 + + + CONFIRM + http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument + + Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts. + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3000 + cpe:/a:microsoft:virtual_machine:2000 + + CVE-2000-0327 + 1999-10-21T00:00:00.000-04:00 + 2008-09-10T15:04:07.773-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS99-045 + + + BUGTRAQ + 19991014 Another Microsoft Java Flaw Disovered + + Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0328 + 1999-08-24T00:00:00.000-04:00 + 2008-09-10T15:04:07.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS99-046 + + + BUGTRAQ + 19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4 + + + BID + 604 + + Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook_express:4.72.2106.4 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:ie:5.0::windows_2000 + cpe:/a:microsoft:ie:4.1::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0::windows_98 + cpe:/a:microsoft:ie:5::windows_nt_4.0 + cpe:/a:microsoft:ie:4.0::windows_nt + cpe:/a:microsoft:ie:4.1::windows_95 + cpe:/a:microsoft:ie:4.0.1::windows_98 + cpe:/a:microsoft:outlook_express:4.72.3120.0 + cpe:/a:microsoft:outlook_express:4.27.3110.1 + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:4.0.1::windows_nt + cpe:/a:microsoft:ie:4.0.1::windows_95 + cpe:/a:microsoft:ie:4.1::windows_nt_4.0 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:outlook_express:4.72.3612.1700 + + CVE-2000-0329 + 1999-11-11T00:00:00.000-05:00 + 2008-09-10T15:04:09.507-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS99-048 + + A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-2000-0330 + 1999-11-12T00:00:00.000-05:00 + 2008-09-10T15:04:09.617-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS99-049 + + The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability. + + + + + + + + + + + + + + + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0331 + 2000-04-20T00:00:00.000-04:00 + 2008-09-10T15:04:09.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1135 + + + MS + MS00-027 + + + BUGTRAQ + 20000421 CMD.EXE overflow (CISADV000420) + + Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability. + + + + + + + + + cpe:/a:ultrascripts:ultraboard:1.6 + + CVE-2000-0332 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:09.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1164 + + + BUGTRAQ + 20000502 Fun with UltraBoard V1.6X + + + OSVDB + 4065 + + + OSVDB + 1309 + + UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte. + + + + + + + + + + + + + cpe:/a:lbl:tcpdump:3.4 + cpe:/a:ethereal_group:ethereal:0.8.6 + cpe:/a:ethereal_group:ethereal:0.8.5 + cpe:/a:ethereal_group:ethereal:0.8.4 + cpe:/a:lbl:tcpdump:3.5a + + CVE-2000-0333 + 1999-05-31T00:00:00.000-04:00 + 2008-09-10T15:04:09.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1165 + + + BUGTRAQ + 20000502 Denial of service attack against tcpdump + + tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet. + + + + + + + + + + cpe:/a:allaire:spectra:1.0 + cpe:/a:allaire:spectra:1.0.1 + + CVE-2000-0334 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:09.993-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB00-10 + + + BID + 1181 + + The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule. + + + + + + + + + + + + + + + + cpe:/a:gnu:glibc:2.1 + cpe:/a:gnu:glibc:2.1.2 + cpe:/a:gnu:glibc:2.1.3 + cpe:/a:isc:bind:8.2.1 + cpe:/a:gnu:glibc:2.0 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.2 + cpe:/a:gnu:glibc:2.1.1 + + CVE-2000-0335 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:10.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1166 + + The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:openldap:openldap:1.2.9 + cpe:/a:openldap:openldap:1.2.8 + cpe:/a:openldap:openldap:1.2.7 + cpe:/a:openldap:openldap:1.2.10 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:turbolinux:turbolinux:4.4 + cpe:/o:turbolinux:turbolinux:4.2 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0336 + 2000-04-21T00:00:00.000-04:00 + 2008-09-10T15:04:10.133-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2000-009.0 + + + TURBO + TLSA2000010-1 + + + BID + 1232 + + + REDHAT + RHSA-2000:012 + + Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2000-0337 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:10.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1140 + + + BUGTRAQ + 20000424 Solaris x86 Xsun overflow. + + Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter. + + + + + + + + + cpe:/a:cvs:cvs:1.10.7 + + CVE-2000-0338 + 2000-04-23T00:00:00.000-04:00 + 2008-09-10T15:04:10.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1136 + + + BUGTRAQ + 20000423 CVS DoS + + Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user. + + + + + + + + + cpe:/a:zonelabs:zonealarm:2.2.10 + + CVE-2000-0339 + 2000-04-24T00:00:00.000-04:00 + 2008-09-10T15:04:10.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000420 ZoneAlarm + + + BID + 1137 + + + OSVDB + 1294 + + ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules. + + + + + + + + + + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-0340 + 2000-04-29T00:00:00.000-04:00 + 2008-09-10T15:04:10.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1155 + + + CONFIRM + http://www.suse.com/us/support/download/updates/axp_63.html + + + BUGTRAQ + 20000428 SuSE 6.3 Gnomelib buffer overflow + + Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable. + + + + + + + + + cpe:/a:atrium_software:cassandra_nntp_server:1.10 + + CVE-2000-0341 + 2000-05-01T00:00:00.000-04:00 + 2008-09-05T16:20:45.457-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1156 + + + NTBUGTRAQ + 20000501 Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM + + ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name. + + + + + + + + + + cpe:/a:qualcomm:eudora:4.3 + cpe:/a:qualcomm:eudora:4.2 + + CVE-2000-0342 + 2000-04-28T00:00:00.000-04:00 + 2008-09-10T15:04:11.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.peacefire.org/security/stealthattach/explanation.html + + + CONFIRM + http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077 + + + BID + 1157 + + Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment." + + + + + + + + + + cpe:/a:brecht_claerhout:sniffit:0.3.7beta + cpe:/a:brecht_claerhout:sniffit:0.3.6hip + + CVE-2000-0343 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:11.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1158 + + + BUGTRAQ + 20000502 spj-003-000 - S0ftPj Advisory + + Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header. + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.1 + cpe:/o:linux:linux_kernel:2.3.0 + + CVE-2000-0344 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:11.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000501 Linux knfsd DoS issue + + + BID + 1160 + + The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.0%284%29t + cpe:/o:cisco:ios:11.2%2810%29bc + cpe:/o:cisco:ios:12.0%284%29s + cpe:/h:cisco:router_2600 + cpe:/o:cisco:ios:12.0%287%29t + cpe:/h:cisco:router_7200 + cpe:/o:cisco:ios:11.1%2813%29 + cpe:/o:cisco:ios:12.0%285%29 + cpe:/o:cisco:ios:12.0%281%29xb + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%282%29xg + cpe:/o:cisco:ios:12.0%281%29w + cpe:/o:cisco:ios:12.0%282%29xf + cpe:/o:cisco:ios:11.2%2810%29 + cpe:/o:cisco:ios:12.0%281%29xe + cpe:/o:cisco:ios:12.0%282%29xc + cpe:/o:cisco:ios:11.2 + cpe:/h:cisco:router_7500 + cpe:/o:cisco:ios:11.1%2813%29aa + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.1%2815%29ca + cpe:/o:cisco:ios:11.1%2813%29ia + cpe:/o:cisco:ios:11.1%2817%29cc + cpe:/o:cisco:ios:12.0%282%29 + cpe:/h:cisco:router_4000 + cpe:/o:cisco:ios:12.0%283%29t2 + cpe:/o:cisco:ios:12.0%286%29 + cpe:/o:cisco:ios:12.0%289%29s + cpe:/o:cisco:ios:11.2%288%29sa1 + cpe:/o:cisco:ios:12.0%281%29xa3 + cpe:/o:cisco:ios:11.2%288%29sa5 + cpe:/o:cisco:ios:11.2%288%29sa3 + cpe:/o:cisco:ios:11.2%284%29f1 + cpe:/o:cisco:ios:11.1%2816%29ia + cpe:/o:cisco:ios:9.14 + cpe:/h:cisco:router_2500 + cpe:/o:cisco:ios:11.1%2817%29ct + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:11.2%289%29xa + cpe:/o:cisco:ios:11.1%2816%29 + cpe:/o:cisco:ios:12.0%285%29t1 + cpe:/o:cisco:ios:11.2p + cpe:/h:cisco:router_3600 + cpe:/o:cisco:ios:11.2%2817%29 + cpe:/o:cisco:ios:12.0%284%29 + cpe:/o:cisco:ios:11.2%288%29p + cpe:/o:cisco:ios:11.2%288%29 + cpe:/o:cisco:ios:11.1%2816%29aa + cpe:/o:cisco:ios:11.1%2813%29ca + cpe:/o:cisco:ios:11.2%289%29p + cpe:/o:cisco:ios:12.0%288%29 + + CVE-2000-0345 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:11.430-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1161 + + + BUGTRAQ + 20000502 Possible issue with Cisco on-line help? + + The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command. + + + + + + + + + + + cpe:/a:apple:appleshare:6.1:::jp + cpe:/a:apple:appleshare:6.3:::jp + cpe:/a:apple:appleshare:6.2:::jp + + CVE-2000-0346 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:11.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://asu.info.apple.com/swupdates.nsf/artnum/n11670 + + + BUGTRAQ + 20000502 INFO:AppleShare IP 6.3.2 squashes security bug + + + BID + 1162 + + AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-2000-0347 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:12.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1163 + + + NTBUGTRAQ + 20000501 el8.org advisory - Win 95/98 DoS (RFParalyze.c) + + Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. + + + + + + + + + cpe:/o:sco:unixware:7.1.0 + + CVE-2000-0348 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:46.643-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SCO + SB-99.10 + + A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges. + + + + + + + + + cpe:/o:sco:unixware:7.1.0 + + CVE-2000-0349 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:46.783-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SCO + SB-99.13 + + Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service. + + + + + + + + + cpe:/a:networkice:icecap_manager:2.0.23 + + CVE-2000-0350 + 2000-05-17T00:00:00.000-04:00 + 2008-09-10T15:04:12.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securityfocus.com/templates/advisory.html?id=2220 + + + CONFIRM + http://advice.networkice.com/advice/Support/KB/q000166/ + + + BID + 1216 + + + OSVDB + 312 + + A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events. + + + + + + + + + cpe:/o:sco:unixware:7.1.0 + + CVE-2000-0351 + 2001-03-12T00:00:00.000-05:00 + 2011-03-07T21:03:05.687-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SCO + SB-99.09 + + Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages. + + + + + + + + + + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.20 + + CVE-2000-0352 + 1999-11-18T00:00:00.000-05:00 + 2008-09-10T15:04:12.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 19991117 Pine: expanding env vars in URLs (seems to be fixed as of 4.21) + + + BID + 810 + + + SUSE + 19991227 Security hole in Pine < 4.21 + + + CALDERA + CSSA-1999-036.0 + + Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL. + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.10 + cpe:/a:university_of_washington:pine:3.98 + cpe:/a:university_of_washington:pine:4.0 + cpe:/a:university_of_washington:pine:4.2 + + CVE-2000-0353 + 1999-06-28T00:00:00.000-04:00 + 2008-09-10T15:04:12.820-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html + + + BID + 1247 + + + SUSE + 19990628 Execution of commands in Pine 4.x + + + SUSE + 19990911 Update for Pine (fixed IMAP support) + + Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine. + + + + + + + + + cpe:/a:lee_mcloughlin:mirror:2.9 + + CVE-2000-0354 + 2000-09-28T00:00:00.000-04:00 + 2008-09-10T15:04:12.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 19990928 mirror 2.9 hole + + + BID + 681 + + + SUSE + 19991001 Security hole in mirror + + + DEBIAN + 19991018 Incorrect directory name handling in mirror + + mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory. + + + + + + + + + + + cpe:/o:suse:suse_linux:6.2 + cpe:/o:redhat:linux:6.0 + cpe:/o:bent_bagger:pbpg:1.1 + + CVE-2000-0355 + 1999-08-21T00:00:00.000-04:00 + 2008-09-10T15:04:12.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SUSE + 19990920 Security hole in pbpg + + pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files. + + + + + + + + + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0356 + 1999-10-13T00:00:00.000-04:00 + 2008-09-10T15:04:13.023-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-1999:040 + + + BID + 697 + + Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts. + + + + + + + + + cpe:/o:redhat:linux:6.1 + + CVE-2000-0357 + 1999-12-03T00:00:00.000-05:00 + 2008-09-10T15:04:13.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-1999:058-01 + + ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys. + + + + + + + + + cpe:/o:redhat:linux:6.1 + + CVE-2000-0358 + 1999-12-03T00:00:00.000-05:00 + 2008-09-10T15:04:13.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-1999:058-01 + + ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program. + + + + + + + + + + + + + + + cpe:/a:acme_labs:thttpd:2.0 + cpe:/a:acme_labs:thttpd:2.0.1 + cpe:/a:acme_labs:thttpd:1.90a + cpe:/a:acme_labs:thttpd:2.0.2 + cpe:/a:acme_labs:thttpd:1.95 + cpe:/a:acme_labs:thttpd:2.0.3 + cpe:/a:acme_labs:thttpd:2.0.4 + + CVE-2000-0359 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:04:13.243-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1248 + + + SUSE + 19991116 Security hole in thttpd 1.90a - 2.04 + + + BUGTRAQ + 19991113 thttpd 2.04 stack overflow (VD#6) + + Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. + + + + + + + + + + + + + + + + + + + + cpe:/a:isc:inn:2.2.1 + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:1.4sec2 + cpe:/a:isc:inn:1.5.1 + cpe:/a:isc:inn:1.7 + cpe:/a:isc:inn:2.0 + cpe:/a:isc:inn:2.1 + cpe:/a:isc:inn:1.7.2 + cpe:/a:isc:inn:1.4unoff3 + cpe:/a:isc:inn:1.4sec + cpe:/a:isc:inn:1.5 + cpe:/a:isc:inn:1.4unoff4 + + CVE-2000-0360 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:04:13.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-1999-038.0 + + + BID + 1249 + + + SUSE + 19991124 Security hole in inn <= 2.2.1 + + Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article. + + + + + + + + + cpe:/o:suse:suse_linux + + CVE-2000-0361 + 1999-12-14T00:00:00.000-05:00 + 2008-09-10T15:04:13.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUSE + 19991214 Security hole in wvdial <= 1.4 + + The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information. + + + + + + + + + + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + + CVE-2000-0362 + 1999-10-22T00:00:00.000-04:00 + 2008-09-10T15:04:13.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 738 + + + SUSE + 19991019 Security hole in cdwtools < 093 + + Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges. + + + + + + + + + + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + + CVE-2000-0363 + 1999-10-22T00:00:00.000-04:00 + 2008-09-10T15:04:13.507-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 738 + + + SUSE + 19991019 Security hole in cdwtools < 093 + + Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-2000-0364 + 1999-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:13.587-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 309 + + + REDHAT + RHSA1999014_01 + + + BUGTRAQ + 19990606 RedHat 6.0, /dev/pts permissions bug when using xterm + + + BUGTRAQ + 19990606 RedHat 6.0, /dev/pts permissions bug when using xterm + + screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys. + + + + + + + + + cpe:/o:redhat:linux:6.0 + + CVE-2000-0365 + 1999-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:13.647-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 308 + + + REDHAT + RHSA1999014_01 + + + BUGTRAQ + 19990606 RedHat 6.0, /dev/pts permissions bug when using xterm + + + BUGTRAQ + 19990606 RedHat 6.0, /dev/pts permissions bug when using xterm + + Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices. + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + + CVE-2000-0366 + 1999-12-02T00:00:00.000-05:00 + 2008-09-10T15:04:13.727-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1442 + + + DEBIAN + 19991202 problem restoring symlinks + + dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files. + + + + + + + + + cpe:/a:michael_jennings:eterm:0.8.8 + + CVE-2000-0367 + 1999-02-18T00:00:00.000-05:00 + 2008-09-10T15:04:13.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + 19990218 Root exploit in eterm + + Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges. + + + + + + + + + cpe:/o:cisco:ios:9.1 + + CVE-2000-0368 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:20:49.707-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 19981014 Cisco IOS Command History Release at Login Prompt + + + CIAC + J-009 + + Classic Cisco IOS 9.1 and later allows attackers with access to the loging prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. + + + + + + + + + cpe:/o:caldera:openlinux:2.3 + + CVE-2000-0369 + 1999-10-08T00:00:00.000-04:00 + 2008-09-10T15:04:13.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1266 + + + CALDERA + CSSA-1999-029.1 + + The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service. + + + + + + + + + + + + cpe:/o:caldera:openlinux:1.1 + cpe:/o:caldera:openlinux:1.2 + cpe:/o:caldera:openlinux:1.0 + cpe:/o:caldera:openlinux:1.3 + + CVE-2000-0370 + 1999-01-29T00:00:00.000-05:00 + 2008-09-10T15:04:14.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-1999-001.0 + + + BID + 1268 + + The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command. + + + + + + + + + + cpe:/o:kde:kde:1.1 + cpe:/o:kde:kde:1.1.1 + + CVE-2000-0371 + 1999-03-01T00:00:00.000-05:00 + 2008-09-10T15:04:14.070-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-1999-005.0 + + + BID + 1269 + + The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack. + + + + + + + + + cpe:/o:caldera:openlinux + + CVE-2000-0372 + 2000-07-12T00:00:00.000-04:00 + 2008-09-10T15:04:14.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-rmt + + + CALDERA + CSSA-1999-014.0 + + + OSVDB + 7940 + + Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges. + + + + + + + + + cpe:/a:kde:kvt + + CVE-2000-0373 + 1999-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:14.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kde-kvt + + + REDHAT + RHSA-1999:015-01 + + + CALDERA + CSSA-1999-015.0 + + Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges. + + + + + + + + + + cpe:/o:caldera:openlinux:2.3 + cpe:/o:caldera:openlinux:2.2 + + CVE-2000-0374 + 1999-08-22T00:00:00.000-04:00 + 2008-09-10T15:04:14.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xdmcp-kdm-default-configuration(4856) + + + BID + 1446 + + + MANDRAKE + MDKSA-2002:025 + + + CALDERA + CSSA-1999-021.0 + + The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions. + + + + + + + + + cpe:/o:freebsd:freebsd:3.2 + + CVE-2000-0375 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:04:14.507-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 6084 + + The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files. + + + + + + + + + cpe:/a:i-drive:filo:1.01 + + CVE-2000-0376 + 2000-06-07T00:00:00.000-04:00 + 2008-09-10T15:04:14.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1324 + + Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0377 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:04:14.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS00-040 + + + BID + 1331 + + + MSKB + Q264684 + + + + + The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability. + + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + + CVE-2000-0378 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:14.710-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1176 + + + BUGTRAQ + 20000502 pam_console bug + + The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in. + + + + + + + + + cpe:/h:netopia:r-series_routers:4.6.2 + + CVE-2000-0379 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:16.837-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000507 Advisory: Netopia R9100 router vulnerability + + + CONFIRM + http://www.netopia.com/equipment/purchase/fmw_update.html + + + BID + 1177 + + The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.3t + cpe:/o:cisco:ios:12.0%281%29xa3 + cpe:/o:cisco:ios:11.2%284%29f1 + cpe:/o:cisco:ios:12.0%284%29t + cpe:/o:cisco:ios:11.3%281%29ed + cpe:/o:cisco:ios:11.2%2810%29bc + cpe:/o:cisco:ios:12.0%284%29s + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:12.0%287%29t + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:11.3%281%29 + cpe:/o:cisco:ios:11.2%289%29xa + cpe:/o:cisco:ios:11.3%281%29t + cpe:/o:cisco:ios:12.0%285%29 + cpe:/o:cisco:ios:12.0%281%29xb + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%282%29xg + cpe:/o:cisco:ios:12.0%282%29xf + cpe:/o:cisco:ios:12.0%281%29w + cpe:/o:cisco:ios:11.2%2810%29 + cpe:/o:cisco:ios:12.0%281%29xe + cpe:/o:cisco:ios:12.0%282%29xc + cpe:/o:cisco:ios:12.0%285%29t1 + cpe:/o:cisco:ios:11.3 + cpe:/o:cisco:ios:11.2 + cpe:/o:cisco:ios:11.2p + cpe:/o:cisco:ios:11.2%2817%29 + cpe:/o:cisco:ios:12.0%284%29 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.2%288%29p + cpe:/o:cisco:ios:11.2%288%29 + cpe:/o:cisco:ios:12.0%282%29 + cpe:/o:cisco:ios:12.0%286%29 + cpe:/o:cisco:ios:12.0%283%29t2 + cpe:/o:cisco:ios:12.0%289%29s + cpe:/o:cisco:ios:11.2%289%29p + cpe:/o:cisco:ios:12.0%288%29 + + CVE-2000-0380 + 2000-04-26T00:00:00.000-04:00 + 2008-09-10T00:00:00.000-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 1154 + + + OSVDB + 1302 + + + CISCO + 20000514 Cisco IOS HTTP Server Vulnerability + + + BUGTRAQ + 20000426 Cisco HTTP possible bug: + + + + + The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. + + + + + + + + + cpe:/a:gossamer_threads:dbman:2.0.4 + + CVE-2000-0381 + 2000-05-05T00:00:00.000-04:00 + 2008-09-10T15:04:18.647-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.perfectotech.com/blackwatchlabs/vul5_05.html + + + BID + 1178 + + + BUGTRAQ + 20000505 Black Watch Labs Vulnerability Alert + + The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter. + + + + + + + + + cpe:/a:allaire:clustercats:1.0 + + CVE-2000-0382 + 2000-05-08T00:00:00.000-04:00 + 2008-09-10T15:04:18.757-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB00-12 + + + BID + 1179 + + ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site. + + + + + + + + + cpe:/a:aol:instant_messenger:4.0 + + CVE-2000-0383 + 2000-05-08T00:00:00.000-04:00 + 2008-09-10T15:04:18.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1180 + + + BUGTRAQ + 20000507 AOL Instant Messenger + + The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient. + + + + + + + + + + cpe:/h:intel:netstructure_7180 + cpe:/h:intel:netstructure_7110 + + CVE-2000-0384 + 2000-05-08T00:00:00.000-04:00 + 2008-09-05T16:20:52.237-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1183 + + + BID + 1182 + + + L0PHT + 20000508 NetStructure 7180 remote backdoor vulnerability + + + L0PHT + 20000508 NetStructure 7110 console backdoor + + + CONFIRM + http://216.188.41.136/ + + NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access. + + + + + + + + + cpe:/a:filemaker:filemaker:5.0::pro + + CVE-2000-0385 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:33.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.filemaker.com/support/webcompanion.html + + + MISC + http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html + + FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities. + + + + + + + + + cpe:/a:filemaker:filemaker:5.0::pro + + CVE-2000-0386 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:33.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.filemaker.com/support/webcompanion.html + + + MISC + http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html + + FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email. + + + + + + + + + cpe:/a:alexander_siegel:golddig:2.0 + + CVE-2000-0387 + 2000-05-09T00:00:00.000-04:00 + 2008-09-10T15:04:33.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1184 + + + FREEBSD + FreeBSD-SA-00:16 + + The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + + CVE-2000-0388 + 1990-05-09T00:00:00.000-04:00 + 2008-09-10T15:04:33.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1185 + + + FREEBSD + FreeBSD-SA-00:17 + + Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable. + + + + + + + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/a:cygnus:kerbnet:5.0 + cpe:/o:redhat:linux:6.2::alpha + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0389 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-06 + + + BID + 1220 + + + REDHAT + RHSA-2000:025 + + + FREEBSD + FreeBSD-SA-00:20 + + + BUGTRAQ + 20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS + + Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges. + + + + + + + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/a:cygnus:kerbnet:5.0 + cpe:/o:redhat:linux:6.2::alpha + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0390 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-06 + + + BID + 1220 + + + REDHAT + RHSA-2000:025 + + + OSVDB + 4884 + + + FREEBSD + FreeBSD-SA-00:20 + + + BUGTRAQ + 20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS + + Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges. + + + + + + + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/a:cygnus:kerbnet:5.0 + cpe:/o:redhat:linux:6.2::alpha + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0391 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.243-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-06 + + + BID + 1220 + + + REDHAT + RHSA-2000:025 + + + OSVDB + 4876 + + + FREEBSD + FreeBSD-SA-00:20 + + + BUGTRAQ + 20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS + + Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges. + + + + + + + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/a:cygnus:kerbnet:5.0 + cpe:/o:redhat:linux:6.2::alpha + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0392 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-06 + + + BID + 1220 + + + REDHAT + RHSA-2000:025 + + + FREEBSD + FreeBSD-SA-00:20 + + + BUGTRAQ + 20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS + + Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges. + + + + + + + + + + + + cpe:/o:kde:kde:1.1 + cpe:/o:kde:kde:1.2 + cpe:/o:kde:kde:1.1.1 + cpe:/o:kde:kde:2.0_beta + + CVE-2000-0393 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.383-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1206 + + + SUSE + 20000529 kmulti <= 1.1.2 + + + BUGTRAQ + 20000516 kscd vulnerability + + The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute. + + + + + + + + + cpe:/a:axent:netprowler:3.0 + + CVE-2000-0394 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:34.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000522 RFP2K05 - NetProwler "Fragmentation" Issue + + + BID + 1225 + + + BUGTRAQ + 20000519 RFP2K05: NetProwler vs. RFProwler + + NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature. + + + + + + + + + cpe:/a:computalynx:cproxy_server:3.3sp2 + + CVE-2000-0395 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:34.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000516 CProxy v3.3 SP 2 DoS + + + BID + 1213 + + Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request. + + + + + + + + + cpe:/a:pacific_software:carello:1.2.1 + + CVE-2000-0396 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:34.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1245 + + + BUGTRAQ + 20000524 Alert: Carello File Creation flaw + + The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files. + + + + + + + + + cpe:/a:seattle_lab_software:emurl:2.0 + + CVE-2000-0397 + 2000-05-15T00:00:00.000-04:00 + 2008-09-10T15:04:34.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1203 + + + BUGTRAQ + 20000515 Vulnerability in EMURL-based e-mail providers + + The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account. + + + + + + + + + cpe:/a:rockliffe:mailsite:4.2.10 + + CVE-2000-0398 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:34.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1244 + + + BUGTRAQ + 20000524 Alert: Buffer overflow in Rockliffe's MailSite + + Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request. + + + + + + + + + + cpe:/a:alt-n:mdaemon:3.1_beta + cpe:/a:alt-n:mdaemon:3.0.3 + + CVE-2000-0399 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:34.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1250 + + + BUGTRAQ + 20000524 Deerfield Communications MDaemon Mail Server DoS + + Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name. + + + + + + + + + cpe:/a:microsoft:active_movie_control:1.0 + + CVE-2000-0400 + 2000-05-13T00:00:00.000-04:00 + 2008-09-10T15:04:35.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1221 + + + BUGTRAQ + 20000516 MICROSOFT SECURITY FLAW? + + The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post. + + + + + + + + + cpe:/a:pdgsoft:pdg_shopping_cart:1.5 + + CVE-2000-0401 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:35.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1256 + + + CONFIRM + http://www.pdgsoft.com/Security/security2.html + + + NTBUGTRAQ + 20000525 Alert: PDG Cart Overflows + + + BUGTRAQ + 20000525 Alert: PDG Cart Overflows + + Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp1 + + CVE-2000-0402 + 2000-05-30T00:00:00.000-04:00 + 2008-09-10T15:04:35.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-035 + + + BID + 1281 + + + MSKB + Q263968 + + The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0403 + 2000-05-25T00:00:00.000-04:00 + 2008-09-10T15:04:35.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-036 + + + BID + 1261 + + + MSKB + Q263307 + + The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability. + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/a:microsoft:terminal_server + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0404 + 2000-05-25T00:00:00.000-04:00 + 2008-09-10T15:04:35.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-036 + + + BID + 1262 + + + MSKB + Q262694 + + The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. + + + + + + + + + + cpe:/a:atstake:antisniff:1.0.1 + cpe:/a:atstake:antisniff:1.0::researchers + + CVE-2000-0405 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:35.633-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + L0PHT + 20000515 AntiSniff version 1.01 and Researchers version 1 DNS overflow + + + BID + 1207 + + + OSVDB + 3179 + + Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet. + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.05 + cpe:/a:netscape:communicator:4.5_beta + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.72 + cpe:/a:netscape:communicator:4.07 + + CVE-2000-0406 + 2000-05-10T00:00:00.000-04:00 + 2008-09-10T15:04:35.757-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-05 + + + BID + 1188 + + + REDHAT + RHSA-2000:028 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt + + Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2000-0407 + 2000-05-12T00:00:00.000-04:00 + 2008-09-10T15:04:35.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1200 + + + BUGTRAQ + 20000512 New Solaris root exploit for /usr/lib/lp/bin/netpr + + Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0408 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:35.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-030 + + + MISC + http://www.ussrback.com/labs40.html + + + BID + 1190 + + + MSKB + Q260205 + + IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.72 + + CVE-2000-0409 + 2000-05-10T00:00:00.000-04:00 + 2008-09-10T15:04:35.960-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1201 + + + BUGTRAQ + 20000510 Possible symlink problems with Netscape 4.73 + + Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate. + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.5.1 + + CVE-2000-0410 + 2000-05-10T00:00:00.000-04:00 + 2008-09-10T15:04:36.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000510 Cold Fusion Server 4.5.1 DoS Vulnerability. + + + BID + 1192 + + ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory. + + + + + + + + + cpe:/a:matt_wright:formmail:1.6 + + CVE-2000-0411 + 2000-05-10T00:00:00.000-04:00 + 2008-09-10T15:04:36.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.perfectotech.com/blackwatchlabs/vul5_10.html + + + BID + 1187 + + + BUGTRAQ + 20000510 Black Watch Labs Vulnerability Alert + + Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. + + + + + + + + + cpe:/a:napster:knapster:napster + + CVE-2000-0412 + 1999-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:36.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1186 + + + BUGTRAQ + 20000510 Gnapster Vulnerability Compromises User-readable Files + + + BUGTRAQ + 20000510 KNapster Vulnerability Compromises User-readable Files + + + FREEBSD + FreeBSD-SA-00:18 + + The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:frontpage + + CVE-2000-0413 + 2000-05-06T00:00:00.000-04:00 + 2008-09-10T15:04:36.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1174 + + + BUGTRAQ + 20000506 shtml.exe reveal local path of IIS web directory + + The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:vvos:11.04 + cpe:/o:hp:vvos:10.24 + + CVE-2000-0414 + 2000-05-04T00:00:00.000-04:00 + 2008-09-10T15:04:36.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1214 + + + HP + HPSBUX0005-113 + + + + + Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables. + + + + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:4.72.3120.0 + cpe:/a:microsoft:outlook_express:4.27.3110.1 + cpe:/a:microsoft:outlook_express:4.72.2106.4 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook_express:4.0 + cpe:/a:microsoft:outlook_express:4.72.3612.1700 + cpe:/a:microsoft:outlook_express:4.01 + + CVE-2000-0415 + 2000-05-12T00:00:00.000-04:00 + 2008-09-05T16:20:57.050-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1195 + + + BUGTRAQ + 20000512 Overflow in Outlook Express 4.* - too long filenames with graphic format extension + + Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0416 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:36.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm + + + BUGTRAQ + 20000511 NTMail Proxy Exploit + + + BID + 1196 + + NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server. + + + + + + + + + + + + cpe:/h:cayman:3220-h_dsl_router:1.0 + cpe:/h:cayman:gatorsurf:5.3build_r1 + cpe:/h:cayman:gatorsurf:5.3build_r2 + cpe:/h:cayman:gatorsurf:5.5build_r0 + + CVE-2000-0417 + 2000-05-17T00:00:00.000-04:00 + 2008-09-10T15:04:36.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1219 + + + BUGTRAQ + 20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack + + + BUGTRAQ + 20000505 Cayman 3220-H DSL Router DOS + + The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password. + + + + + + + + + + + + + + cpe:/h:cayman:gatorsurf:5.3 + cpe:/h:cayman:3220-h_dsl_router:1.0 + cpe:/h:cayman:gatorsurf:5.3build_r1 + cpe:/h:cayman:gatorsurf:5.3build_r2 + cpe:/h:cayman:gatorsurf:5.5build_r1 + cpe:/h:cayman:gatorsurf:5.5build_r0 + + CVE-2000-0418 + 2000-05-23T00:00:00.000-04:00 + 2008-09-10T15:04:36.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1240 + + + BUGTRAQ + 20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack + + The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:powerpoint:2000 + cpe:/a:microsoft:photodraw_2000:1.0 + cpe:/a:microsoft:project:2000 + cpe:/a:microsoft:access:2000 + cpe:/a:microsoft:works:2000 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:frontpage:2000 + cpe:/a:microsoft:excel:2000 + cpe:/a:microsoft:office:2000 + + CVE-2000-0419 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:37.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2000-07 + + + MS + MS00-034 + + + BID + 1197 + + + MSKB + Q262767 + + The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0420 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:37.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1198 + + + NTBUGTRAQ + 20000511 ISS SAVANT Advisory 00/26 + + The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.8 + + CVE-2000-0421 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:37.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1199 + + + BUGTRAQ + 20000510 Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8 + + The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:netwin:dmail:2.5d + + CVE-2000-0422 + 2000-05-04T00:00:00.000-04:00 + 2008-09-10T15:04:37.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1171 + + + BUGTRAQ + 20000504 Alert: DMailWeb buffer overflow + + Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter. + + + + + + + + + cpe:/a:netwin:dnews:5.3 + + CVE-2000-0423 + 2000-05-05T00:00:00.000-04:00 + 2008-09-10T15:04:37.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1172 + + + BUGTRAQ + 20000505 Alert: DNewsWeb buffer overflow + + Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. + + + + + + + + + + cpe:/a:george_burgyan:cgi_counter:4.0.7 + cpe:/a:george_burgyan:cgi_counter:4.0.2 + + CVE-2000-0424 + 2000-05-15T00:00:00.000-04:00 + 2008-09-10T15:04:37.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000514 Vulnerability in CGI counter 4.0.7 by George Burgyan + + + BID + 1202 + + The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:lsoft:listserv:1.8 + + CVE-2000-0425 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:37.477-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.lsoft.com/news/default.asp?item=Advisory0 + + + BID + 1167 + + + BUGTRAQ + 20000505 Alert: Listserv Web Archives (wa) buffer overflow + + Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:ultrascripts:ultraboard:1.6 + + CVE-2000-0426 + 2000-05-05T00:00:00.000-04:00 + 2008-09-10T15:04:37.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1175 + + + BUGTRAQ + 20000505 Re: Fun with UltraBoard V1.6X + + UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself. + + + + + + + + + cpe:/a:aladdin_knowledge_systems:etoken:3.3.3 + + CVE-2000-0427 + 2000-05-04T00:00:00.000-04:00 + 2008-09-10T15:04:37.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1170 + + + OSVDB + 3266 + + + L0PHT + 20000504 eToken Private Information Extraction and Physical Attack + + The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM. + + + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.32 + cpe:/a:trend_micro:interscan_viruswall:3.3 + cpe:/a:trend_micro:interscan_viruswall:3.2.3 + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2000-0428 + 2000-05-04T00:00:00.000-04:00 + 2008-09-10T15:04:37.697-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1168 + + + NAI + 20000503 Trend Micro InterScan VirusWall Remote Overflow + + Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment. + + + + + + + + + + cpe:/a:mcmurtrey_whitaker_and_associates:cart32:3.0 + cpe:/a:mcmurtrey_whitaker_and_associates:cart32:2.6 + + CVE-2000-0429 + 2000-04-27T00:00:00.000-04:00 + 2008-09-10T15:04:40.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.cart32.com/kbshow.asp?article=c048 + + + BUGTRAQ + 20000427 Alert: Cart32 secret password backdoor (CISADV000427) + + A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:mcmurtrey_whitaker_and_associates:cart32:3.0 + + CVE-2000-0430 + 2000-05-03T00:00:00.000-04:00 + 2008-09-10T15:04:40.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1358 + + + BUGTRAQ + 20000503 Another interesting Cart32 command + + Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request. + + + + + + + + + + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2000-0431 + 2000-05-22T00:00:00.000-04:00 + 2008-09-10T15:04:40.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1238 + + + CONFIRM + http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html + + + BUGTRAQ + 20000522 Problem with FrontPage on Cobalt RaQ2/RaQ3 + + + OSVDB + 1346 + + Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files. + + + + + + + + + cpe:/a:matt_kruse:calendar_script:2.2 + + CVE-2000-0432 + 2000-05-16T00:00:00.000-04:00 + 2008-09-10T15:04:40.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1215 + + + BUGTRAQ + 20000516 Vuln in calender.pl (Matt Kruse calender script) + + The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.1:alpha + + CVE-2000-0433 + 2000-05-02T00:00:00.000-04:00 + 2008-09-10T15:04:40.710-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUSE + 20000502 aaabase < 2000.5.2 + + The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles. + + + + + + + + + cpe:/a:matthew_redman:allmanage:2.6 + + CVE-2000-0434 + 2000-05-13T00:00:00.000-04:00 + 2008-09-10T15:04:40.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1217 + + + BUGTRAQ + 20000516 Allmanage.pl Vulnerabilities + + The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers. + + + + + + + + + cpe:/a:matthew_redman:allmanage:2.6 + + CVE-2000-0435 + 2000-05-13T00:00:00.000-04:00 + 2008-09-10T15:04:40.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1217 + + + OSVDB + 1337 + + + BUGTRAQ + 20000516 Allmanage.pl Vulnerabilities + + The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages. + + + + + + + + + + + cpe:/a:metaproducts:offline_explorer:1.2 + cpe:/a:metaproducts:offline_explorer:1.1 + cpe:/a:metaproducts:offline_explorer:1.0 + + CVE-2000-0436 + 2000-05-19T00:00:00.000-04:00 + 2008-09-10T15:04:41.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.metaproducts.com/mpOE-HY.html + + + BID + 1231 + + + BUGTRAQ + 20000522 MetaProducts Offline Explorer Directory Traversal Vulnerability + + MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + cpe:/h:network_associates:webshield_e-ppliance:300.0 + cpe:/a:network_associates:gauntlet_firewall:5.5 + cpe:/a:network_associates:gauntlet_firewall:5.0 + cpe:/a:network_associates:gauntlet_firewall:4.1 + cpe:/a:network_associates:webshield:4.0::solaris + cpe:/a:network_associates:gauntlet_firewall:4.2 + cpe:/h:network_associates:webshield_e-ppliance:100.0 + + CVE-2000-0437 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:41.540-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.tis.com/support/cyberadvisory.html + + + CONFIRM + http://www.pgp.com/jump/gauntlet_advisory.asp + + + BID + 1234 + + + OSVDB + 322 + + + BUGTRAQ + 20000522 Gauntlet CyberPatrol Buffer Overflow + + Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:5.2 + cpe:/o:suse:suse_linux:5.3 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:5.0 + cpe:/o:suse:suse_linux:5.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:slackware:slackware_linux:3.4 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:slackware:slackware_linux:3.5 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:slackware:slackware_linux:3.3 + cpe:/o:turbolinux:turbolinux:6.0.1 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:suse:suse_linux:6.0 + cpe:/o:slackware:slackware_linux:4.0 + cpe:/o:suse:suse_linux:4.4.1 + cpe:/o:turbolinux:turbolinux:6.0 + cpe:/o:slackware:slackware_linux:3.6 + cpe:/o:slackware:slackware_linux:3.9 + cpe:/o:suse:suse_linux:4.2 + cpe:/o:caldera:openlinux:7.0 + cpe:/o:suse:suse_linux:4.3 + cpe:/o:suse:suse_linux:4.4 + + CVE-2000-0438 + 2000-05-22T00:00:00.000-04:00 + 2008-09-10T15:04:41.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1239 + + + BUGTRAQ + 20000522 fdmount buffer overflow + + Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter. + + + + + + + + + + + + + + cpe:/a:microsoft:ie:3.0 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:3.2 + + CVE-2000-0439 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T15:04:41.697-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-033 + + + XF + ie-cookie-disclosure(4447) + + + BUGTRAQ + 20000511 IE Domain Confusion Vulnerability is an Email problem also + + + BUGTRAQ + 20000510 IE Domain Confusion Vulnerability + + + BID + 1194 + + + OSVDB + 1326 + + Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-0440 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:41.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1173 + + + BUGTRAQ + 20000506 [NHC20000504a.0: NetBSD Panics when sent unaligned IP options] + + + NETBSD + NetBSD-SA2000-002 + + NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:ibm:aix:4.1 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:ibm:aix:4.1.3 + cpe:/o:ibm:aix:3.2 + + CVE-2000-0441 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:41.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1241 + + + IBM + ERS-OAR-E01-2000:087.1 + + Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems. + + + + + + + + + + + + cpe:/a:qualcomm:qpopper:2.52 + cpe:/a:qualcomm:qpopper:2.53 + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2000-0442 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:41.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1242 + + + SUSE + 20000608 pop <= 2000.3.4 + + + BUGTRAQ + 20000523 Qpopper 2.53 remote problem, user can gain gid=mail + + Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command. + + + + + + + + + cpe:/a:hp:jetadmin:6.0 + + CVE-2000-0443 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:41.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1243 + + + OSVDB + 1350 + + + BUGTRAQ + 20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability + + The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:hp:jetadmin:6.0 + + CVE-2000-0444 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:42.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1246 + + + BUGTRAQ + 20000524 HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability + + HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000. + + + + + + + + + + + cpe:/a:pgp:pgp:5.0_linux + cpe:/a:pgp:pgp:6.5_linux + cpe:/a:pgp:pgp:5.0i + + CVE-2000-0445 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:42.147-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-09 + + + BID + 1251 + + + OSVDB + 1355 + + + BUGTRAQ + 20000523 Key Generation Security Flaw in PGP 5.0 + + The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys. + + + + + + + + + cpe:/a:marty_bochane:mdbms:0.9_xbx + + CVE-2000-0446 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:42.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1252 + + + BUGTRAQ + 20000524 Remote xploit for MDBMS + + Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string. + + + + + + + + + cpe:/a:network_associates:webshield:4.5.44 + + CVE-2000-0447 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:42.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool + + + BID + 1254 + + + OSVDB + 327 + + Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service. + + + + + + + + + cpe:/a:network_associates:webshield:4.5.44 + + CVE-2000-0448 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:42.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool + + + BID + 1253 + + + OSVDB + 326 + + The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command. + + + + + + + + + cpe:/a:omnis:studio:2.4 + + CVE-2000-0449 + 2000-05-01T00:00:00.000-04:00 + 2008-09-10T15:04:42.507-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1255 + + + BUGTRAQ + 20000525 Omnis Weak Encryption - Many products affected + + Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. + + + + + + + + + + + + cpe:/a:sean_macguire:big_brother:1.4h1 + cpe:/a:sean_macguire:big_brother:1.4 + cpe:/a:sean_macguire:big_brother:1.4g + cpe:/a:sean_macguire:big_brother:1.3b + + CVE-2000-0450 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:42.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1257 + + + BUGTRAQ + 20000518 FW: Security Notice: Big Brother System and Network Monitor + + Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands. + + + + + + + + + cpe:/h:intel:express_8100 + + CVE-2000-0451 + 2000-05-19T00:00:00.000-04:00 + 2008-09-10T15:04:42.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1228 + + + BUGTRAQ + 20000518 Remote Dos attack against Intel express 8100 router + + The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets. + + + + + + + + + + + + + + cpe:/a:lotus:domino_mail_server:5.0.1 + cpe:/a:lotus:domino_mail_server:5.0.3 + cpe:/a:lotus:domino_mail_server:5.0.2 + cpe:/a:lotus:domino_enterprise_server:5.0.1 + cpe:/a:lotus:domino_enterprise_server:5.0.2 + cpe:/a:lotus:domino_enterprise_server:5.0.3 + + CVE-2000-0452 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:42.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1229 + + + OSVDB + 321 + + + BUGTRAQ + 20000518 Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) + + Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command. + + + + + + + + + + + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:xfree86_project:x11r6:3.3.5 + cpe:/a:xfree86_project:x11r6:3.3.6 + + CVE-2000-0453 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:42.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1235 + + + BUGTRAQ + 20000518 Nasty XFree Xserver DoS + + + CALDERA + CSSA-2000-012.0 + + XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000. + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:7.0 + + CVE-2000-0454 + 2000-05-29T00:00:00.000-04:00 + 2008-09-10T15:04:43.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1265 + + + BUGTRAQ + 20000607 Conectiva Linux Security Announcement - cdrecord + + + BUGTRAQ + 20000603 [Gael Duval ] [Security Announce] cdrecord + + + BUGTRAQ + 20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2) + + Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter. + + + + + + + + + cpe:/a:david_bagley:xlock:4.16 + + CVE-2000-0455 + 2000-05-29T00:00:00.000-04:00 + 2008-09-10T15:04:43.147-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1267 + + + NAI + 20000529 Initialized Data Overflow in Xlock + + + TURBO + TLSA2000012-1 + + + NETBSD + NetBSD-SA2000-003 + + Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option. + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.4.1::sparc + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4.1::arm32 + cpe:/o:netbsd:netbsd:1.4.1::alpha + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:netbsd:netbsd:1.4.2::alpha + cpe:/o:netbsd:netbsd:1.4.1::x86 + + CVE-2000-0456 + 2000-05-28T00:00:00.000-04:00 + 2008-09-10T15:04:43.227-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1272 + + + OSVDB + 1365 + + + NETBSD + NetBSD-SA2000-005 + + NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog". + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0457 + 2000-05-11T00:00:00.000-04:00 + 2008-09-10T19:55:31.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + iis-ism-file-access(4448) + + + BID + 1193 + + + MS + MS00-031 + + + BUGTRAQ + 20000511 Alert: IIS ism.dll exposes file contents + + ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability. + + + + + + + + + + + + + cpe:/a:imp:imp:2.2_pre9 + cpe:/a:imp:imp:2.0.11 + cpe:/a:imp:imp:2.0.9 + cpe:/a:imp:imp:2.0.10 + cpe:/a:imp:imp:2.2_pre10 + + CVE-2000-0458 + 2000-04-22T00:00:00.000-04:00 + 2008-09-10T19:55:31.663-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1360 + + + BUGTRAQ + 20000424 Two Problems in IMP 2 + + The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information. + + + + + + + + + + + + + + + cpe:/a:imp:imp:2.2_pre9 + cpe:/a:imp:imp:2.0.11 + cpe:/a:imp:imp:2.0.9 + cpe:/a:imp:imp:2.0.10 + cpe:/a:imp:imp:2.2_pre10 + cpe:/a:imp:imp:2.2_pre12 + cpe:/a:imp:imp:2.2_pre11 + + CVE-2000-0459 + 2000-04-22T00:00:00.000-04:00 + 2008-09-10T19:55:31.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1361 + + + BUGTRAQ + 20000424 Two Problems in IMP 2 + + IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request. + + + + + + + + + + + + cpe:/o:kde:kde:1.1 + cpe:/o:kde:kde:1.2 + cpe:/o:kde:kde:1.1.1 + cpe:/o:kde:kde:1.1.2 + + CVE-2000-0460 + 2000-05-27T00:00:00.000-04:00 + 2008-09-10T15:04:43.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000526 KDE: /usr/bin/kdesud, gid = 0 exploit + + + BID + 1274 + + Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:netbsd:netbsd:1.4.1::arm32 + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.4.1::sparc + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:freebsd:freebsd:2.1.6.1 + cpe:/o:freebsd:freebsd:2.1.7.1 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4.1::alpha + cpe:/o:netbsd:netbsd:1.4.2::alpha + cpe:/o:freebsd:freebsd:5.0:alpha + cpe:/o:freebsd:freebsd:2.1.0 + + CVE-2000-0461 + 2000-05-29T00:00:00.000-04:00 + 2008-09-10T15:04:43.587-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1270 + + + OPENBSD + 20000526 + + + NETBSD + NetBSD-SA2000-004 + + + FREEBSD + FreeBSD-SA-00:19 + + The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call. + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:netbsd:netbsd:1.4.2::alpha + + CVE-2000-0462 + 2000-05-28T00:00:00.000-04:00 + 2008-09-10T15:04:43.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1273 + + + OSVDB + 1366 + + + NETBSD + NetBSD-SA2000-006 + + ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory. + + + + + + + + + cpe:/o:be:beos:5.0 + + CVE-2000-0463 + 2000-05-18T00:00:00.000-04:00 + 2008-09-10T15:04:43.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1222 + + + BUGTRAQ + 20000517 AUX Security Advisory on Be/OS 5.0 (DoS) + + BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0464 + 2000-05-17T00:00:00.000-04:00 + 2008-09-10T15:04:43.930-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS00-033 + + + BID + 1223 + + + MSKB + Q261257 + + Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5:preview + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0465 + 2000-05-17T00:00:00.000-04:00 + 2008-09-10T15:04:44.057-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS00-033 + + + BID + 1224 + + + MSKB + Q255676 + + + MSKB + Q251108 + + Internet Explorer 4.x and 5.x does properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability. + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + + CVE-2000-0466 + 2000-06-20T00:00:00.000-04:00 + 2008-09-05T16:21:04.970-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1384 + + + ISS + 20000620 Insecure call of external program in AIX cdmount + + AIX cdmount allows local users to gain root privileges via shell metacharacters. + + + + + + + + + cpe:/a:sam_lantinga:splitvt:1.6.3 + + CVE-2000-0467 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:44.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000614 Splitvt exploit + + + BID + 1346 + + Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0468 + 2000-06-02T00:00:00.000-04:00 + 2008-09-10T15:04:44.290-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1302 + + + BUGTRAQ + 20000601 HP Security vulnerability in the man command + + man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack. + + + + + + + + + cpe:/a:selena_sol:webbanner:4.0 + + CVE-2000-0469 + 2000-02-02T00:00:00.000-05:00 + 2008-09-10T15:04:44.353-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000613 CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability + + + BUGTRAQ + 20000620 Re: CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability + + + BID + 1347 + + Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:allegro:rom_pager:2.10 + + CVE-2000-0470 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:44.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rompager-malformed-dos + + + BID + 1290 + + + BUGTRAQ + 20000601 Hardware Exploit - Gets network Down + + Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:::x86 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:5.5 + cpe:/o:sun:solaris:5.4 + cpe:/o:sun:solaris:1.2 + cpe:/o:sun:solaris:1.1.2 + cpe:/o:sun:solaris:1.1.4 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:1.1.3 + cpe:/o:sun:solaris:1.1 + cpe:/o:sun:solaris:5.3 + cpe:/o:sun:sunos:5.6 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6:hw5 + cpe:/o:sun:solaris:1.1.4::jl + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:5.5.1 + cpe:/o:sun:solaris:2.6:hw3 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:1.1.3:u1 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:1.1.1a + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:5.6::x86 + cpe:/o:sun:solaris:5.5::x86 + cpe:/o:sun:solaris:5.5.1::x86 + cpe:/o:sun:solaris:5.4::x86 + + CVE-2000-0471 + 2000-06-14T00:00:00.000-04:00 + 2008-09-05T16:21:05.703-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#36866 + + + BID + 1348 + + + XF + sol-ufsrestore-bo + + + OSVDB + 1398 + + + SUN + 00210 + + + BUGTRAQ + 20000614 Vulnerability in Solaris ufsrestore + + Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname. + + + + + + + + + + + + + cpe:/a:isc:inn:2.2.1 + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:2.2.2 + cpe:/a:isc:inn:2.0 + cpe:/a:isc:inn:2.1 + + CVE-2000-0472 + 2000-02-06T00:00:00.000-05:00 + 2008-09-10T15:04:44.570-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + innd-cancel-overflow + + + BID + 1316 + + + BUGTRAQ + 20000722 MDKSA-2000:023 inn update + + + BUGTRAQ + 20000721 [ANNOUNCE] INN 2.2.3 available + + + BUGTRAQ + 20000707 inn update + + + BUGTRAQ + 20000106 innd 2.2.2 remote buffer overflow + + + CALDERA + CSSA-2000-016.0 + + Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID. + + + + + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.01 + cpe:/a:analogx:simpleserver_www:1.03 + cpe:/a:analogx:simpleserver_www:1.05 + cpe:/a:analogx:simpleserver_www:1.04 + cpe:/a:analogx:simpleserver_www:1.06 + + CVE-2000-0473 + 2000-06-15T00:00:00.000-04:00 + 2008-09-10T15:04:44.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1349 + + + MISC + http://www.analogx.com/contents/download/network/sswww.htm + + Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory. + + + + + + + + + + + cpe:/a:realnetworks:realserver:7.0.1 + cpe:/a:realnetworks:realserver:8.0_beta + cpe:/a:realnetworks:realserver:7.0 + + CVE-2000-0474 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:44.710-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1288 + + + XF + realserver-malformed-remote-dos + + + BUGTRAQ + 20000601 Remote DoS attack in RealServer: USSR-2000043 + + + BUGTRAQ + 20000601 Remote DoS attack in Real Networks Real Server (Strike #2) Vulnerability + + Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0475 + 2000-06-15T00:00:00.000-04:00 + 2008-09-05T16:21:06.393-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + win2k-desktop-separation + + + BID + 1350 + + + MS + MS00-020 + + Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability. + + + + + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/a:michael_jennings:eterm:0.8.10 + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:putty:putty:0.48 + cpe:/a:rxvt:rxvt:2.6.1 + + CVE-2000-0476 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:44.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1298 + + + BUGTRAQ + 20000601 [rootshell.com] Xterm DoS Attack + + + BUGTRAQ + 20000601 [rootshell.com] Xterm DoS Attack + + xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. + + + + + + + + + + cpe:/a:symantec:norton_antivirus:2.0::ms_exchange + cpe:/a:symantec:norton_antivirus:1.5::ms_exchange + + CVE-2000-0477 + 2000-06-14T00:00:00.000-04:00 + 2008-09-10T15:04:45.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1351 + + + XF + antivirus-nav-zip-bo + + + BUGTRAQ + 20000614 Vulnerabilities in Norton Antivirus for Exchange + + Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names. + + + + + + + + + + cpe:/a:symantec:norton_antivirus:2.0::ms_exchange + cpe:/a:symantec:norton_antivirus:1.5::ms_exchange + + CVE-2000-0478 + 2000-06-14T00:00:00.000-04:00 + 2008-09-10T15:04:45.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1351 + + + XF + antivirus-nav-fail-open + + + OSVDB + 6266 + + + BUGTRAQ + 20000614 Vulnerabilities in Norton Antivirus for Exchange + + In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server. + + + + + + + + + + cpe:/a:shadow_op_software:dragon_server:2.0 + cpe:/a:shadow_op_software:dragon_server:1.0 + + CVE-2000-0479 + 2000-06-16T00:00:00.000-04:00 + 2008-09-10T15:04:47.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1352 + + + BUGTRAQ + 20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00 + + Dragon FTP server allows remote attackers to cause a denial of service via a long USER command. + + + + + + + + + + cpe:/a:shadow_op_software:dragon_server:2.0 + cpe:/a:shadow_op_software:dragon_server:1.0 + + CVE-2000-0480 + 2000-06-16T00:00:00.000-04:00 + 2008-09-10T15:04:47.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1352 + + + BUGTRAQ + 20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00 + + Dragon telnet server allows remote attackers to cause a denial of service via a long username. + + + + + + + + + + + + + + + + cpe:/a:kde:k-mail:1.0.27 + cpe:/a:kde:k-mail:1.0.26 + cpe:/a:kde:k-mail:1.0.29 + cpe:/a:kde:k-mail:1.0.28 + cpe:/a:kde:k-mail:1.0.23 + cpe:/a:kde:k-mail:1.0.25 + cpe:/a:kde:k-mail:1.0.24 + cpe:/a:kde:k-mail:1.0.29.1 + + CVE-2000-0481 + 1999-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:47.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1380 + + + VULN-DEV + 20000601 Kmail heap overflow + + + XF + kde-kmail-attachment-dos + + Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + + CVE-2000-0482 + 2000-06-06T00:00:00.000-04:00 + 2008-09-10T15:04:47.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1312 + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation + + + XF + fw1-packet-fragment-dos + + + OSVDB + 1379 + + + BUGTRAQ + 20000605 FW-1 IP Fragmentation Vulnerability + + Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets. + + + + + + + + + + + + + cpe:/a:zope:zope:1.10.3 + cpe:/a:redhat:linux_powertools:6.1 + cpe:/a:redhat:linux_powertools:6.2 + cpe:/a:zope:zope:2.1.7 + cpe:/a:zope:zope:2.1.1 + + CVE-2000-0483 + 2000-06-15T00:00:00.000-04:00 + 2008-09-05T16:21:07.580-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert + + + BUGTRAQ + 20000615 [Brian@digicool.com: [Zope] Zope security alert and 2.1.7 update [*important*]] + + + XF + zope-dtml-remote-modify + + + BUGTRAQ + 2000615 Conectiva Linux Security Announcement - ZOPE + + + BID + 1354 + + + REDHAT + RHSA-2000:038 + + + BUGTRAQ + 20000728 MDKSA-2000:026 Zope update + + + FREEBSD + FreeBSD-SA-00:38 + + The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization. + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:1.212 + + CVE-2000-0484 + 2000-06-15T00:00:00.000-04:00 + 2008-09-10T15:04:47.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + small-http-get-overflow-dos + + + BID + 1355 + + + NTBUGTRAQ + 20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability + + + BUGTRAQ + 20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability + + Buffer overflow in Small HTTP Server allows remote attackers to cause a denial of service via a long GET request. + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:6.5 + + CVE-2000-0485 + 2000-05-30T00:00:00.000-04:00 + 2008-09-10T15:04:48.057-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-041 + + + XF + mssql-dts-reveal-passwords + + + BID + 1292 + + + BUGTRAQ + 20000530 Fw: Steal Passwords Using SQL Server EM + + Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability. + + + + + + + + + + + + + + + cpe:/a:cisco:tacacs%2b:f4.0.2alpha + cpe:/o:cisco:ios + cpe:/a:cisco:tacacs%2b:f4.0.3alpha + + CVE-2000-0486 + 2000-05-30T00:00:00.000-04:00 + 2008-09-10T15:04:48.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000530 An Analysis of the TACACS+ Protocol and its Implementations + + + CONFIRM + http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html + + + XF + tacacsplus-packet-length-dos + + + BID + 1293 + + Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0487 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:48.180-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1295 + + + MS + MS00-032 + + The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. + + + + + + + + + cpe:/a:ithouse:ithouse_mail_server:1.0.4 + + CVE-2000-0488 + 2000-05-30T00:00:00.000-04:00 + 2008-09-10T15:04:48.257-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ithouse-rcpt-overflow(4580) + + + BUGTRAQ + 20000601 DST2K0007: Buffer Overrun in ITHouse Mail Server v1.04 + + + BID + 1285 + + Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1::arm32 + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.4.1::sparc + cpe:/o:netbsd:netbsd:1.4::x86 + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4.1::alpha + cpe:/o:netbsd:netbsd:1.4.2::alpha + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:netbsd:netbsd:1.4.1::x86 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:5.0:alpha + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0489 + 1999-09-05T00:00:00.000-04:00 + 2008-09-10T15:04:48.353-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-setsockopt-dos + + + BUGTRAQ + 19990826 Local DoS in FreeBSD + + + BUGTRAQ + 20000601 Local FreeBSD, Openbsd, NetBSD, DoS Vulnerability - Mac OS X affected + + + BID + 622 + + FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers. + + + + + + + + + + + + + + cpe:/a:netwin:dmail:2.8f + cpe:/a:netwin:dmail:2.8g + cpe:/a:netwin:dmail:2.8h + cpe:/a:netwin:dmail:2.7 + cpe:/a:netwin:dmail:2.7q + cpe:/a:netwin:dmail:2.8e + + CVE-2000-0490 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:48.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1297 + + + XF + dmail-etrn-dos + + + CONFIRM + http://netwinsite.com/dmail/security.htm + + + BUGTRAQ + 20000601 Netwin's Dmail package + + Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux + cpe:/o:suse:suse_linux:6.2 + cpe:/a:gnome:gdm:1.0 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-0491 + 2000-05-24T00:00:00.000-04:00 + 2008-09-10T15:04:48.663-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-2000-013.0 + + + BID + 1370 + + + BID + 1279 + + + BID + 1233 + + + SUSE + 20000524 Security hole in gdm <= 2.0beta4-25 + + + BUGTRAQ + 20000607 Conectiva Linux Security Announcement - gdm + + + BUGTRAQ + 20000521 "gdm" remote hole + + Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. + + + + + + + + + cpe:/a:passwd:passwd:1.2 + + CVE-2000-0492 + 2000-06-04T00:00:00.000-04:00 + 2008-09-10T15:04:48.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000609 Insecure encryption in PassWD v1.2 + + + BID + 1300 + + PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. + + + + + + + + + cpe:/a:atrius_trivalie_sn:time_sync:1.0.1 + + CVE-2000-0493 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:48.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + timesync-bo-execute + + + VULN-DEV + 20000601 Vulnerability in SNTS + + + BID + 1289 + + Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string. + + + + + + + + + + + cpe:/a:symantec_veritas:volume_manager:3.0.2 + cpe:/a:symantec_veritas:volume_manager:3.0.3 + cpe:/a:symantec_veritas:volume_manager:3.0.4 + + CVE-2000-0494 + 2000-06-16T00:00:00.000-04:00 + 2008-09-10T15:04:48.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1356 + + + BUGTRAQ + 20000616 Veritas Volume Manager 3.0.x hole + + + CONFIRM + http://seer.support.veritas.com/tnotes/volumeman/230053.htm + + Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script. + + + + + + + + + + cpe:/a:microsoft:windows_media_services:4.1 + cpe:/a:microsoft:windows_media_services:4.0 + + CVE-2000-0495 + 2000-05-30T00:00:00.000-04:00 + 2008-09-10T15:04:49.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ms-malformed-media-dos + + + MS + MS00-038 + + + BID + 1282 + + Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability. + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.0.21 + + CVE-2000-0497 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:04:49.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000612 IBM WebSphere JSP showcode vulnerability + + + CONFIRM + http://www-4.ibm.com/software/webservers/appserv/efix.html + + + BID + 1328 + + IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. + + + + + + + + + cpe:/a:unify:ewave_servletexec:3.0 + + CVE-2000-0498 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:04:49.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ewave-servletexec-jsp-source-read(4649) + + + NTBUGTRAQ + 20000608 Potential vulnerability in Unify eWave ServletExec + + + BID + 1328 + + Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. + + + + + + + + + + + + cpe:/a:bea:weblogic_server:3.1.8 + cpe:/a:bea:weblogic_server:::express + cpe:/a:bea:weblogic_server:4.5.1 + cpe:/a:bea:weblogic_server:4.0.4 + + CVE-2000-0499 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:04:50.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1328 + + + CONFIRM + http://developer.bea.com/alerts/security_000612.html + + + XF + weblogic-jsp-source-read + + + NTBUGTRAQ + 20000612 BEA WebLogic JSP showcode vulnerability + + The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:3.1.8 + cpe:/a:bea:weblogic_server:4.0 + cpe:/a:bea:weblogic_server:4.5::express + cpe:/a:bea:weblogic_server:3.1.8::express + cpe:/a:bea:weblogic_server:5.1::express + cpe:/a:bea:weblogic_server:5.1 + cpe:/a:bea:weblogic_server:4.5 + cpe:/a:bea:weblogic_server:4.0::express + + CVE-2000-0500 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:04:50.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1378 + + + XF + weblogic-file-source-read + + + CONFIRM + http://www.weblogic.com/docs51/admindocs/http.html#file + + + BUGTRAQ + 20000621 BEA WebLogic /file/ showcode vulnerability + + The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing. + + + + + + + + + cpe:/a:alt-n:mdaemon:2.8.5.0 + + CVE-2000-0501 + 2000-06-16T00:00:00.000-04:00 + 2008-09-10T15:04:50.507-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mdaemon-pass-dos + + + NTBUGTRAQ + 20000616 mdaemon 2.8.5.0 WinNT and Win9x remote DoS + + + BID + 1366 + + Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server. + + + + + + + + + cpe:/a:mcafee:virusscan:4.0.3 + + CVE-2000-0502 + 2000-06-08T00:00:00.000-04:00 + 2008-09-05T16:21:10.407-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1326 + + + BUGTRAQ + 20000607 Mcafee Alerting DOS vulnerability + + + XF + mcafee-alerting-dos(4641) + + + OSVDB + 6287 + + Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5:preview + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0503 + 2000-06-06T00:00:00.000-04:00 + 2008-09-10T15:04:50.663-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000606 IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control + + + BID + 1311 + + The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. + + + + + + + + + + + + + + + + + + + + + cpe:/a:open_group:x:11.0r6.3 + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/a:open_group:x:11.0r6.2 + cpe:/a:xfree86_project:x11r6:3.3.5 + cpe:/a:open_group:x:11.0r6.4 + cpe:/a:xfree86_project:x11r6:3.3.4 + cpe:/a:open_group:x:11.0r6.1 + cpe:/a:xfree86_project:x11r6:3.3.6 + cpe:/a:open_group:x:11.0r6 + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:gnome:gdm:1.0 + cpe:/a:gnome:gdm:1.1 + cpe:/a:open_group:x:11.0r5 + + CVE-2000-0504 + 2000-06-19T00:00:00.000-04:00 + 2008-09-10T15:04:50.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1369 + + + CONFIRM + http://www.xfree86.org/security/ + + + BUGTRAQ + 20000619 XFree86: libICE DoS + + libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro. + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.11::win32 + cpe:/a:apache:http_server:1.3.12::win32 + cpe:/a:ibm:http_server:1.3.3::win32 + cpe:/a:apache:http_server:1.3.6::win32 + cpe:/a:ibm:http_server:1.3.6.2::win32 + cpe:/a:apache:http_server:1.3.9::win32 + + CVE-2000-0505 + 2000-05-31T00:00:00.000-04:00 + 2008-09-10T15:04:51.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000603 Re: IBM HTTP SERVER / APACHE + + + BID + 1284 + + + XF + ibm-http-file-retrieve + + The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.16:pre5 + cpe:/o:linux:linux_kernel:2.0.35 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.0.36 + cpe:/o:linux:linux_kernel:2.0.33 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.0.34 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.15:pre16 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.0.30 + cpe:/o:linux:linux_kernel:2.0.38 + cpe:/o:linux:linux_kernel:2.0.37 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.15_pre20 + cpe:/o:linux:linux_kernel:2.1 + cpe:/o:linux:linux_kernel:2.0 + + CVE-2000-0506 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:04:51.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000609 Sendmail & procmail local root exploits on Linux kernel up to 2.2.16pre5 + + + BID + 1322 + + + REDHAT + RHSA-2000:037 + + + BUGTRAQ + 20000608 CONECTIVA LINUX SECURITY ANNOUNCEMENT - kernel + + + BUGTRAQ + 20000609 Trustix Security Advisory + + + SGI + 20000802-01-P + + The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability." + + + + + + + + + cpe:/a:concatus:imate_webmail_server:2.5 + + CVE-2000-0507 + 2000-06-01T00:00:00.000-04:00 + 2008-09-05T16:21:11.237-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-webmail-dos + + + BUGTRAQ + 20000601 DST2K0006: Denial of Service Possibility in Imate WebMail Server + + + BID + 1286 + + Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command. + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + + CVE-2000-0508 + 1994-12-19T00:00:00.000-05:00 + 2008-09-05T16:21:11.393-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1372 + + + BUGTRAQ + 20000608 Remote DOS in linux rpc.lockd + + + XF + linux-lockd-remote-dos + + rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request. + + + + + + + + + cpe:/a:sambar:sambar_server:4.3:beta9 + + CVE-2000-0509 + 2000-06-01T00:00:00.000-04:00 + 2008-09-10T15:04:51.320-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1287 + + + BUGTRAQ + 20000601 DST2K0008: Buffer Overrun in Sambar Server 4.3 + + Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname. + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-0510 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:04:51.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch + + + BID + 1373 + + + XF + debian-cups-malformed-ipp + + + BUGTRAQ + 20000620 CUPS DoS Bugs + + CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request. + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-0511 + 2000-06-21T00:00:00.000-04:00 + 2011-03-07T21:03:18.813-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch + + + BID + 1373 + + + XF + debian-cups-posts + + + BUGTRAQ + 20000620 CUPS DoS Bugs + + CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request. + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-0512 + 2000-06-16T00:00:00.000-04:00 + 2008-09-10T15:04:51.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch + + + BID + 1373 + + + XF + debian-cups-posts + + + BUGTRAQ + 20000620 CUPS DoS Bugs + + CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service. + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-0513 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:04:51.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch + + + XF + debian-cups-posts + + + BID + 1373 + + + BUGTRAQ + 20000620 CUPS DoS Bugs + + CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password. + + + + + + + + + + cpe:/a:mit:kerberos:5_1.1 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0514 + 2000-06-14T00:00:00.000-04:00 + 2008-09-10T15:04:51.897-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kerberos-gssftpd-dos + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/ftp.txt + + + BUGTRAQ + 20000614 Security Advisory: REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON + + + BID + 1374 + + + OSVDB + 4885 + + GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0515 + 2000-06-07T00:00:00.000-04:00 + 2008-09-10T15:04:51.993-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hpux-snmp-daemon + + + BUGTRAQ + 20000608 Re: HP-UX SNMP daemon vulnerability + + + BUGTRAQ + 20000607 [ Hackerslab bug_paper ] HP-UX SNMP daemon vulnerability + + + BID + 1327 + + The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges. + + + + + + + + + cpe:/a:intel:shiva_access_manager:5.0::solaris + + CVE-2000-0516 + 2000-06-06T00:00:00.000-04:00 + 2008-09-10T15:04:52.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000606 Shiva Access Manager 5.0.0 Plaintext LDAP root password. + + + XF + shiva-plaintext-ldap-password + + + BID + 1329 + + When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server. + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.72 + + CVE-2000-0517 + 2000-05-26T00:00:00.000-04:00 + 2008-09-05T16:21:12.767-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-08 + + + XF + netscape-ssl-certificate + + + BID + 1260 + + Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:4.0.1::windows_98 + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:4.0.1::windows_nt + cpe:/a:microsoft:ie:5.0.1::windows_2000 + cpe:/a:microsoft:ie:4.0.1::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:5.0::windows_2000 + cpe:/a:microsoft:ie:5.0.1::windows_nt_4.0 + cpe:/a:microsoft:ie:5.0.1::windows_98 + cpe:/a:microsoft:ie:5.0.1::windows_95 + cpe:/a:microsoft:ie:4.0::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5::windows_nt_4.0 + cpe:/a:microsoft:ie:4.0::windows_nt + + CVE-2000-0518 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:12.923-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-10 + + + XF + ie-invalid-frame-image-certificate + + + BID + 1309 + + + MS + MS00-039 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt + + Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:4.0.1::windows_98 + cpe:/a:microsoft:ie:5.0::windows_nt_4.0 + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:4.0.1::windows_nt + cpe:/a:microsoft:ie:5.0.1::windows_2000 + cpe:/a:microsoft:ie:4.0.1::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:5.0::windows_2000 + cpe:/a:microsoft:ie:5.0.1::windows_nt_4.0 + cpe:/a:microsoft:ie:5.0.1::windows_98 + cpe:/a:microsoft:ie:5.0.1::windows_95 + cpe:/a:microsoft:ie:4.0::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0::windows_nt + + CVE-2000-0519 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:13.110-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-10 + + + XF + ie-revalidate-certificate + + + BID + 1309 + + + MS + MS00-039 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt + + Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities. + + + + + + + + + + + + + + cpe:/a:stelian:pop_dump:0.4b15.30 + cpe:/a:stelian:pop_dump:0.4b9.9 + cpe:/a:stelian:pop_dump:0.4b15.1 + cpe:/a:stelian:pop_dump:0.4b16.0 + cpe:/a:stelian:pop_dump:0.4b9.0 + cpe:/a:stelian:pop_dump:0.4b17.0 + + CVE-2000-0520 + 2000-06-07T00:00:00.000-04:00 + 2008-09-10T15:04:52.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1330 + + + MISC + http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880 + + + BUGTRAQ + 20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT - dump + + Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name. + + + + + + + + + cpe:/a:michael_lamont:savant_webserver:2.1 + + CVE-2000-0521 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:13.437-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1313 + + + BUGTRAQ + 20000605 MDMA Advisory #5: Reading of CGI Scripts under Savant Webserver + + + XF + savant-source-read + + Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number. + + + + + + + + + + + + + cpe:/a:rsa:ace_server:3.3 + cpe:/a:rsa:ace_server:3.1 + cpe:/a:rsa:ace_server:3.3.1 + cpe:/a:rsa:ace_server:4.1 + cpe:/a:rsa:ace_server:4.0 + + CVE-2000-0522 + 2000-06-08T00:00:00.000-04:00 + 2008-09-05T16:21:13.610-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aceserver-udp-packet-dos + + + BID + 1332 + + + BUGTRAQ + 20000714 Re: RSA Aceserver UDP Flood Vulnerability + + + CONFIRM + ftp://ftp.securid.com/support/outgoing/dos/readme.txt + + + BUGTRAQ + 20000608 Potential DoS Attack on RSA's ACE/Server + + RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash. + + + + + + + + + cpe:/a:etype:eserv:2.9.2 + + CVE-2000-0523 + 2000-06-06T00:00:00.000-04:00 + 2008-09-05T16:21:13.767-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + eserv-logging-overflow + + + BID + 1315 + + + BUGTRAQ + 20000606 MDMA Advisory #6: EServ Logging Heap Overflow Vulnerability + + Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command. + + + + + + + + + + + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:exchange_server:4.0 + cpe:/a:microsoft:exchange_server:5.0 + + CVE-2000-0524 + 2000-06-05T00:00:00.000-04:00 + 2008-09-10T15:04:55.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1333 + + + BUGTRAQ + 20000604 Microsoft Outlook (Express) bug.. + + Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. + + + + + + + + + + + cpe:/a:openbsd:openssh:1.2 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:openbsd:openssh:2.1 + + CVE-2000-0525 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:04:55.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + openssh-uselogin-remote-exec + + + BID + 1334 + + + OSVDB + 341 + + + OPENBSD + 20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used. + + + BUGTRAQ + 20000609 OpenSSH's UseLogin option allows remote access with root privilege. + + OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon. + + + + + + + + + cpe:/a:3r_soft:mailstudio_2000:2.0 + + CVE-2000-0526 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:04:55.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1335 + + + BUGTRAQ + 20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4] + + mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:3r_soft:mailstudio_2000:2.0 + + CVE-2000-0527 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:04:55.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1335 + + + BUGTRAQ + 20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4] + + userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:network_associates:net_tools_pki_server:1.0 + + CVE-2000-0528 + 2000-06-19T00:00:00.000-04:00 + 2008-09-05T16:21:14.487-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nettools-pki-unauthenticated-access + + + BID + 1364 + + + BUGTRAQ + 20000619 Net Tools PKI server exploits + + + CONFIRM + ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt + + + OSVDB + 4353 + + Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files. + + + + + + + + + cpe:/a:network_associates:net_tools_pki_server:1.0 + + CVE-2000-0529 + 2000-06-19T00:00:00.000-04:00 + 2008-09-05T16:21:14.640-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nettools-pki-http-bo + + + BID + 1363 + + + BUGTRAQ + 20000619 Net Tools PKI server exploits + + + CONFIRM + ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt + + + OSVDB + 4352 + + Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request. + + + + + + + + + + cpe:/o:caldera:openlinux:2.4 + cpe:/o:kde:kde:1.1.2 + + CVE-2000-0530 + 2000-05-31T00:00:00.000-04:00 + 2008-09-05T16:21:14.783-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kde-configuration-file-creation + + + BID + 1291 + + + BUGTRAQ + 20000531 KDE::KApplication feature? + + + REDHAT + RHSA-2000:032 + + + CALDERA + CSSA-2000-015.0 + + The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files. + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/o:caldera:openlinux:2.4 + cpe:/o:caldera:openlinux:2.3 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0531 + 1999-11-23T00:00:00.000-05:00 + 2008-09-05T16:21:14.937-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-gpm-gpmctl-dos + + + BID + 1377 + + + BUGTRAQ + 20000620 Bug in gpm + + + REDHAT + RHSA-2000:045 + + + BUGTRAQ + 20000728 MDKSA:2000-025 gpm update + + Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets. + + + + + + + + + cpe:/o:freebsd:freebsd:4.0 + + CVE-2000-0532 + 2000-06-07T00:00:00.000-04:00 + 2008-09-05T16:21:15.093-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + freebsd-ssh-ports + + + BID + 1323 + + + FREEBSD + FreeBSD-SA-00:21 + + + OSVDB + 1387 + + A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered. + + + + + + + + + cpe:/a:sgi:workshop_debugger_and_performance_tools:2.6 + + CVE-2000-0533 + 2000-06-20T00:00:00.000-04:00 + 2008-09-05T16:21:15.237-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + irix-workshop-cvconnect-overwrite + + + BID + 1379 + + + SGI + 20000601-01-P + + Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files. + + + + + + + + + cpe:/o:aps_filter_development_team:apsfilter:5.4 + + CVE-2000-0534 + 2000-06-07T00:00:00.000-04:00 + 2008-09-10T15:05:00.413-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1325 + + + XF + apsfilter-elevate-privileges + + + OSVDB + 1389 + + The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user. + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:5.0:alpha + cpe:/a:openssl:openssl:0.9.4 + + CVE-2000-0535 + 2000-06-12T00:00:00.000-04:00 + 2008-09-10T15:05:00.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1340 + + + FREEBSD + FreeBSD-SA-00:25 + + OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken. + + + + + + + + + + + + + + + + + cpe:/a:xinetd:xinetd:2.1.88 + cpe:/a:xinetd:xinetd:2.1.87 + cpe:/a:xinetd:xinetd:2.1.89_pre2 + cpe:/a:xinetd:xinetd:2.1.89_pre3 + cpe:/a:xinetd:xinetd:2.1.89_pre4 + cpe:/a:xinetd:xinetd:2.1.89_pre5 + cpe:/a:xinetd:xinetd:2.1.88_pre1 + cpe:/a:xinetd:xinetd:2.1.89_pre1 + cpe:/a:xinetd:xinetd:2.1.88_pre2 + + CVE-2000-0536 + 2000-06-04T00:00:00.000-04:00 + 2008-09-05T16:21:15.687-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + xinetd-improper-restrictions + + + CONFIRM + http://www.synack.net/xinetd/ + + + BID + 1381 + + + DEBIAN + 20000619 xinetd: bug in access control mechanism + + xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry. + + + + + + + + + + cpe:/a:tolis_group:bru:16.0 + cpe:/a:tolis_group:bru:15.1 + + CVE-2000-0537 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:15.843-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bru-execlog-env-variable + + + BID + 1321 + + + BUGTRAQ + 20000606 BRU Vulnerability + + + CALDERA + CSSA-2000-018.0 + + BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable. + + + + + + + + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.5.1 + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:4.0.1 + cpe:/a:allaire:coldfusion_server:3.12 + cpe:/a:allaire:coldfusion_server:2.0 + cpe:/a:allaire:coldfusion_server:3.0 + cpe:/a:allaire:coldfusion_server:3.11 + cpe:/a:allaire:coldfusion_server:4.5 + cpe:/a:allaire:coldfusion_server:3.1 + cpe:/a:allaire:coldfusion_server:3.01 + + CVE-2000-0538 + 2000-06-07T00:00:00.000-04:00 + 2008-09-05T16:21:16.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + coldfusion-parse-dos + + + BID + 1314 + + + ALLAIRE + ASB00-14 + + + OSVDB + 3399 + + + BUGTRAQ + 20000607 New Allaire ColdFusion DoS + + ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password. + + + + + + + + + cpe:/a:macromedia:jrun:2.3 + + CVE-2000-0539 + 2000-06-22T00:00:00.000-04:00 + 2008-09-05T16:21:16.157-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + jrun-read-sample-files + + + BID + 1386 + + + ALLAIRE + ASB00-015 + + + OSVDB + 818 + + Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet. + + + + + + + + + cpe:/a:macromedia:jrun:2.3 + + CVE-2000-0540 + 2000-06-22T00:00:00.000-04:00 + 2008-09-05T16:21:16.313-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + jrun-read-sample-files + + + BID + 1386 + + + ALLAIRE + ASB00-015 + + + OSVDB + 2713 + + JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information. + + + + + + + + + cpe:/a:panda:panda_antivirus:2.0::netware + + CVE-2000-0541 + 2000-06-17T00:00:00.000-04:00 + 2008-09-10T15:05:01.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1359 + + + BUGTRAQ + 20000617 Infosec.20000617.panda.a + + + XF + panda-antivirus-remote-admin(4707) + + The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command. + + + + + + + + + + + cpe:/a:ericsson:axc_tigris_multiservice_access_platform:623.0 + cpe:/a:ericsson:axc_tigris_multiservice_access_platform:711.0 + cpe:/a:ericsson:axc_tigris_multiservice_access_platform:627.0 + + CVE-2000-0542 + 2000-06-13T00:00:00.000-04:00 + 2008-09-05T16:21:16.593-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tigris-radius-login-failure + + + BID + 1345 + + + BUGTRAQ + 20000612 ACC/Ericsson Tigris Accounting Failure + + Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds. + + + + + + + + + + cpe:/a:pgp:certificate_server:2.5 + cpe:/a:pgp:certificate_server:2.5.1 + + CVE-2000-0543 + 2000-06-14T00:00:00.000-04:00 + 2008-09-05T16:21:16.750-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pgp-cert-server-dos + + + BID + 1343 + + + BUGTRAQ + 20000614 Remote DoS attack in Networks Associates PGP Certificate Server Version 2.5 Vulnerability + + The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0544 + 2000-06-05T00:00:00.000-04:00 + 2008-09-10T15:05:01.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1304 + + + NTBUGTRAQ + 20000604 anonymous SMBwriteX DoS + + Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. + + + + + + + + + + + + + + + + + cpe:/a:sgi:mailx:6.1 + cpe:/a:sgi:mailx:6.0.1 + cpe:/a:sgi:mailx:6.5 + cpe:/a:sgi:mailx:4 + cpe:/a:sgi:mailx:6.4 + cpe:/a:sgi:mailx:5 + cpe:/a:sgi:mailx:6.3 + cpe:/a:sgi:mailx:6.2 + cpe:/a:sgi:mailx:3 + + CVE-2000-0545 + 2000-08-08T00:00:00.000-04:00 + 2008-09-10T15:05:01.367-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1305 + + + DEBIAN + 20000605 mailx: mail group exploit in mailx + + + BUGTRAQ + 20000602 /usr/bin/Mail exploit for Slackware 7.0 (mail-slack.c) + + Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter. + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/a:cygnus:kerbnet + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:mit:kerberos:5_1.1 + cpe:/a:cygnus:cygnus_network_security + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0546 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:05:01.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-11 + + + BUGTRAQ + 20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC + + + BID + 1338 + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt + + + CIAC + K-051 + + Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function. + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/a:cygnus:kerbnet + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:mit:kerberos:5_1.1 + cpe:/a:cygnus:cygnus_network_security + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0547 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:05:01.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-11 + + + BUGTRAQ + 20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC + + + BID + 1338 + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt + + + CIAC + K-051 + + Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function. + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/a:cygnus:kerbnet + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:mit:kerberos:5_1.1 + cpe:/a:cygnus:cygnus_network_security + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0548 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:05:01.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-11 + + + BUGTRAQ + 20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt + + + REDHAT + RHSA-2000:031 + + + OSVDB + 4875 + + + CIAC + K-051 + + Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function. + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/a:cygnus:kerbnet:5.0 + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/a:mit:kerberos:5-1.1 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0549 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:05:01.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-11 + + + BUGTRAQ + 20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt + + + REDHAT + RHSA-2000:031 + + + CIAC + K-051 + + Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request. + + + + + + + + + + + + + + cpe:/a:mit:kerberos:4.0 + cpe:/a:cygnus:kerbnet:5.0 + cpe:/a:mit:kerberos:5_1.0 + cpe:/a:cygnus:cygnus_network_security:4.0 + cpe:/a:mit:kerberos:5-1.1 + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2000-0550 + 2000-06-09T00:00:00.000-04:00 + 2008-09-10T15:05:01.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-11 + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt + + + BID + 1465 + + + REDHAT + RHSA-2000:031 + + + CIAC + K-051 + + + BUGTRAQ + 20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC + + Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service. + + + + + + + + + + cpe:/a:danware_data:netop:6.50 + cpe:/a:danware_data:netop:6.0 + + CVE-2000-0551 + 2000-05-23T00:00:00.000-04:00 + 2008-09-05T16:21:17.987-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + danware-netop-bypass-security(4569) + + + BID + 1263 + + + BUGTRAQ + 20000523 I think + + The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files. + + + + + + + + + cpe:/a:mirabilis:icq:2000.0a + + CVE-2000-0552 + 2000-06-06T00:00:00.000-04:00 + 2008-09-05T16:21:18.127-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1307 + + + NTBUGTRAQ + 20000606 ICQ2000A ICQmail temparary internet link vulnearbility + + + XF + icq-temp-link + + ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information. + + + + + + + + + + cpe:/a:darren_reed:ipfilter:3.4.3 + cpe:/a:darren_reed:ipfilter:3.3.15 + + CVE-2000-0553 + 2000-05-26T00:00:00.000-04:00 + 2008-09-05T16:21:18.267-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1308 + + + BUGTRAQ + 20000525 Security Vulnerability in IPFilter 3.3.15 and 3.4.3 + + + XF + ipfilter-firewall-race-condition + + + OSVDB + 1377 + + Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions. + + + + + + + + + cpe:/a:lilikoi:ceilidh:2.60 + + CVE-2000-0554 + 2000-06-08T00:00:00.000-04:00 + 2008-09-10T15:05:02.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000608 DST2K0010: DoS & Path Revealing Vulnerability in Ceilidh v2.60a + + + BID + 1320 + + Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field. + + + + + + + + + cpe:/a:lilikoi:ceilidh:2.60 + + CVE-2000-0555 + 2000-06-09T00:00:00.000-04:00 + 2008-09-05T16:21:18.563-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000608 DST2K0010: DoS & Path Revealing Vulnerability in Ceilidh v2.60a + + + XF + ceilidh-post-dos + + + BID + 1320 + + Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests. + + + + + + + + + cpe:/a:computalynx:cmail:2.4.7 + + CVE-2000-0556 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:18.720-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cmail-long-username-dos + + + BID + 1319 + + + NTBUGTRAQ + 20000608 DST2K0011: DoS & BufferOverrun in CMail v2.4.7 WebMail + + + CONFIRM + http://www.computalynx.net/news/Jun2000/news0806200001.html + + Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002. + + + + + + + + + cpe:/a:computalynx:cmail:2.4.7 + + CVE-2000-0557 + 2000-06-05T00:00:00.000-04:00 + 2008-09-05T16:21:18.860-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cmail-get-overflow-execute + + + BID + 1318 + + + NTBUGTRAQ + 20000608 DST2K0011: DoS & BufferOverrun in CMail v2.4.7 WebMail + + Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.1 + + CVE-2000-0558 + 2000-06-06T00:00:00.000-04:00 + 2008-09-10T15:05:02.557-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1317 + + + NTBUGTRAQ + 20000608 DST2K0012: BufferOverrun in HP Openview Network Node Manager v6.1 + + Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345. + + + + + + + + + cpe:/a:ca:etrust_intrusion_detection:1.4.1.13 + + CVE-2000-0559 + 2000-06-07T00:00:00.000-04:00 + 2008-09-10T15:05:02.633-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1341 + + + BUGTRAQ + 20000607 SessionWall-3 Paper + (links to) code + + eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords. + + + + + + + + + + cpe:/a:international_telecommunications:international_telecommunications_webbbs:1.17 + cpe:/a:international_telecommunications:international_telecommunications_webbbs:1.1.5 + + CVE-2000-0561 + 2000-06-19T00:00:00.000-04:00 + 2008-09-05T16:21:19.313-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + webbbs-get-request-overflow + + + BID + 1365 + + + BUGTRAQ + 20000620 DST2K0018: Multiple BufferOverruns in WebBBS HTTP Server v1.15 + + + OSVDB + 3544 + + Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request. + + + + + + + + + + cpe:/a:iss:blackice_agent:2.0.23 + cpe:/a:iss:blackice_defender:2.1 + + CVE-2000-0562 + 2000-06-22T00:00:00.000-04:00 + 2008-09-10T15:05:02.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000620 BlackICE by Network ICE Corp vulnerability against Back Orifice 1.2 + + BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. + + + + + + + + + cpe:/a:apple:mac_os_runtime_for_java:2.1::java + + CVE-2000-0563 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:19.593-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000609 Security Holes Found in URLConnection of MRJ and IE of Mac OS (was Re: Reappearance of an old IE security bug) + + + BID + 1336 + + + BUGTRAQ + 20000513 Re: Reappearance of an old IE security bug + + The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. + + + + + + + + + + + + + + cpe:/a:mirabilis:icq:99a_2.21build1800 + cpe:/a:mirabilis:icq:99a_2.15build1701 + cpe:/a:mirabilis:icq:0.99b_1.1.1.1 + cpe:/a:mirabilis:icq:98.0a + cpe:/a:mirabilis:icq:2000.0a + cpe:/a:mirabilis:icq:0.99b_v.3.19 + + CVE-2000-0564 + 2000-05-29T00:00:00.000-04:00 + 2008-09-10T15:05:03.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000529 ICQ Web Front Remote DoS Attack Vulnerability + + The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter. + + + + + + + + + cpe:/a:mindstorm:smartftp_daemon:0.2 + + CVE-2000-0565 + 2000-06-13T00:00:00.000-04:00 + 2008-09-05T16:21:19.890-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + smartftp-directory-traversal + + + BID + 1344 + + + BUGTRAQ + 20000613 SmartFTP Daemon v0.2 Beta Build 9 - Remote Exploit + + + OSVDB + 1394 + + SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::alpha + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:caldera:openlinux:2.4 + cpe:/o:caldera:openlinux:2.3 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:5.2::sparc + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0566 + 2000-07-03T00:00:00.000-04:00 + 2008-09-10T15:05:03.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-man-makewhatis-tmp + + + BID + 1434 + + + REDHAT + RHSA-2000:041 + + + MANDRAKE + MDKSA-2000:015 + + + BUGTRAQ + 20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN + + + CALDERA + CSSA-2000-021.0 + + makewhatis in Linux man package allows local users to overwrite files via a symlink attack. + + + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook_express:4.0 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:outlook_express:4.01 + + CVE-2000-0567 + 2000-07-18T00:00:00.000-04:00 + 2008-09-10T15:05:03.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + outlook-date-overflow + + + BID + 1481 + + + MS + MS00-043 + + Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability. + + + + + + + + + cpe:/a:sybergen:secure_desktop:2.1 + + CVE-2000-0568 + 2000-06-30T00:00:00.000-04:00 + 2008-09-10T15:05:03.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000630 Multiple vulnerabilities in Sybergen Secure Desktop + + + BID + 1417 + + Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes. + + + + + + + + + + cpe:/a:sybergen:sygate:3.11 + cpe:/a:sybergen:sygate:2.0 + + CVE-2000-0569 + 2000-06-30T00:00:00.000-04:00 + 2008-09-05T16:21:20.563-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1420 + + + WIN2KSEC + 20000630 Any LAN user can crash Sygate + + + XF + sygate-udp-packet-dos(5049) + + Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface. + + + + + + + + + cpe:/a:centrinity:firstclass_intranet_server:5.770 + + CVE-2000-0570 + 2000-06-27T00:00:00.000-04:00 + 2008-09-05T16:21:20.720-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + firstclass-large-bcc-dos(4843) + + + BID + 1421 + + + BUGTRAQ + 20000627 DoS in FirstClass Internet Services 5.770 + + + OSVDB + 5718 + + FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header. + + + + + + + + + cpe:/a:west_street_software:localweb_http_server:1.2 + + CVE-2000-0571 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:03.570-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + localweb-get-bo + + + BUGTRAQ + 20000703 Remote DoS Attack in LocalWEB HTTP Server 1.2.0 Vulnerability + + + BID + 1423 + + LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request. + + + + + + + + + cpe:/a:visible_systems:razor:4.1 + + CVE-2000-0572 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:03.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000704 Recovering Passwords in Visible Systems' Razor + + + BID + 1424 + + The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0573 + 2000-07-07T00:00:00.000-04:00 + 2008-09-10T15:05:03.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-13 + + + XF + wuftp-format-string-stack-overwrite(4773) + + + BUGTRAQ + 20000623 ftpd: the advisory version + + + BID + 1387 + + + REDHAT + RHSA-2000:039 + + + CALDERA + CSSA-2000-020.0 + + + BUGTRAQ + 20000707 New Released Version of the WuFTPD Sploit + + + BUGTRAQ + 20000623 WUFTPD 2.6.0 remote root exploit + + + BUGTRAQ + 20000622 WuFTPD: Providing *remote* root since at least1994 + + + BUGTRAQ + 20000702 [Security Announce] wu-ftpd update + + + BUGTRAQ + 20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release) + + + NETBSD + NetBSD-SA2000-009 + + + FREEBSD + FreeBSD-SA-00:29 + + + AUSCERT + AA-2000.02 + + The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.5 + cpe:/a:openbsd:ftpd:5.60 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta1::academ + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7 + cpe:/a:openbsd:ftpd:5.51 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ + cpe:/a:washington_university:wu-ftpd:2.6 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr16 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr17 + + CVE-2000-0574 + 2000-07-07T00:00:00.000-04:00 + 2008-09-10T15:05:03.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-13 + + + BID + 1438 + + + BID + 1425 + + + BUGTRAQ + 20000710 opieftpd setproctitle() patches + + + BUGTRAQ + 20000706 ftpd and setproctitle() + + + BUGTRAQ + 20000705 proftp advisory + + + NETBSD + NetBSD-SA2000-009 + + FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands. + + + + + + + + + cpe:/a:ssh:ssh:1.2.27 + + CVE-2000-0575 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:03.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ssh-kerberos-tickets-disclosure(4903) + + + BID + 1426 + + + BUGTRAQ + 20000630 Kerberos security vulnerability in SSH-1.2.27 + + SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS. + + + + + + + + + + cpe:/a:oracle:web_listener:4.0.7::aix + cpe:/a:oracle:web_listener:4.0.8::aix + + CVE-2000-0576 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:03.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1427 + + + BUGTRAQ + 20000704 Oracle Web Listener for AIX DoS + + Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL. + + + + + + + + + cpe:/a:netscape:professional_services_ftpserver:1.3.6 + + CVE-2000-0577 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:04.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000621 Netscape FTP Server - "Professional" as hell :> + + + BID + 1411 + + + BUGTRAQ + 20000629 (forw) Re: Netscape ftp Server (fwd) + + Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:sgi:mipspro_compilers:7.2.1 + cpe:/a:sgi:mipspro_compilers:7.1 + + CVE-2000-0578 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:04.087-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1412 + + + BUGTRAQ + 20000621 Predictability Problems in IRIX Cron and Compilers + + SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user. + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.3 + + CVE-2000-0579 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:04.147-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1413 + + + BUGTRAQ + 20000621 Predictability Problems in IRIX Cron and Compilers + + IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:2000.0.2195 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_2000:2000.2072 + + CVE-2000-0580 + 2000-06-30T00:00:00.000-04:00 + 2008-09-10T15:05:04.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000630 SecureXpert Advisory [SX-20000620-2] + + + BID + 1415 + + Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:2000.0.2195 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_2000:2000.2031 + cpe:/o:microsoft:windows_2000:2000.2072 + + CVE-2000-0581 + 2000-06-30T00:00:00.000-04:00 + 2008-09-10T15:05:05.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000630 SecureXpert Advisory [SX-20000620-1] + + + BID + 1414 + + Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + + CVE-2000-0582 + 2000-06-30T00:00:00.000-04:00 + 2008-09-10T15:05:06.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000630 SecureXpert Advisory [SX-20000620-3] + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security + + + BID + 1416 + + + OSVDB + 1438 + + Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy. + + + + + + + + + + cpe:/a:inter7:vpopmail_vchkpw:4.5 + cpe:/a:inter7:vpopmail_vchkpw:4.7 + + CVE-2000-0583 + 2000-06-30T00:00:00.000-04:00 + 2008-09-10T15:05:09.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.vpopmail.cx/vpopmail-ChangeLog + + + BUGTRAQ + 20000626 vpopmail-3.4.11 problems + + + BID + 1418 + + vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives. + + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0584 + 2000-07-02T00:00:00.000-04:00 + 2011-03-07T21:03:32.220-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + canna-bin-execute-bo + + + MISC + http://shadowpenguin.backsection.net/advisories/advisory038.html + + + FREEBSD + FreeBSD-SA-00:31 + + + BID + 1445 + + Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name. + + + + + + + + + + cpe:/a:isc:dhcp_client:3.0b1 + cpe:/a:isc:dhcp_client:2.0 + + CVE-2000-0585 + 2000-06-24T00:00:00.000-04:00 + 2008-09-10T15:05:09.727-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + openbsd-isc-dhcp + + + BUGTRAQ + 20000624 Possible root exploit in ISC DHCP client. + + + BID + 1388 + + + SUSE + 20000711 Security Hole in dhclient < 2.0 + + + DEBIAN + 20000628 dhcp client: remote root exploit in dhcp client + + + BUGTRAQ + 20000702 [Security Announce] dhcp update + + + NETBSD + NetBSD-SA2000-008 + + + FREEBSD + FreeBSD-SA-00:34 + + ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:dalnet:ircd:4.6.5 + + CVE-2000-0586 + 2000-06-29T00:00:00.000-04:00 + 2008-09-10T15:05:09.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1404 + + + VULN-DEV + 20000628 dalnet 4.6.5 remote vulnerability + + Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command. + + + + + + + + + + + + + + + + + + + cpe:/a:glftpd:glftpd:1.21b4 + cpe:/a:glftpd:glftpd:1.18 + cpe:/a:glftpd:glftpd:1.21b5 + cpe:/a:glftpd:glftpd:1.19 + cpe:/a:glftpd:glftpd:1.21b6 + cpe:/a:glftpd:glftpd:1.21b7 + cpe:/a:glftpd:glftpd:1.21b1 + cpe:/a:glftpd:glftpd:1.21b2 + cpe:/a:glftpd:glftpd:1.21b3 + cpe:/a:glftpd:glftpd:1.20 + cpe:/a:glftpd:glftpd:1.21b8 + + CVE-2000-0587 + 2000-06-26T00:00:00.000-04:00 + 2008-09-10T15:05:09.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000626 Glftpd privpath bugs... +fix + + + BID + 1401 + + + BUGTRAQ + 20000627 Re: Glftpd privpath bugs... +fix + + The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. + + + + + + + + + cpe:/a:sawmill:sawmill:5.0.21 + + CVE-2000-0588 + 2000-06-26T00:00:00.000-04:00 + 2013-07-30T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 1402 + + + BUGTRAQ + 20000706 Patch for Flowerfire Sawmill Vulnerabilities Available + + + BUGTRAQ + 20000626 sawmill5.0.21 old path bug & weak hash algorithm + + SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands. + + + + + + + + + cpe:/a:sawmill:sawmill:5.0.21 + + CVE-2000-0589 + 2000-06-26T00:00:00.000-04:00 + 2013-07-30T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BUGTRAQ + 20000626 sawmill5.0.21 old path bug & weak hash algorithm + + + BID + 1403 + + + BUGTRAQ + 20000706 Patch for Flowerfire Sawmill Vulnerabilities Available + + SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. + + + + + + + + + cpe:/a:cgi-world:poll_it:2.0 + + CVE-2000-0590 + 2000-07-04T00:00:00.000-04:00 + 2008-09-05T16:21:23.737-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1431 + + + BUGTRAQ + 20000706 Vulnerability in Poll_It cgi v2.0 + + + XF + http-cgi-pollit-variable-overwrite(4878) + + Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter. + + + + + + + + + + cpe:/a:novell:bordermanager:3.5 + cpe:/a:novell:bordermanager:3.0 + + CVE-2000-0591 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:10.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000705 Novell BorderManager 3.0 EE - Encoded URL rule bypass + + + BID + 1432 + + Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL. + + + + + + + + + + cpe:/a:sapporoworks:sapporoworks_winproxy:2.0.1 + cpe:/a:sapporoworks:sapporoworks_winproxy:2.0 + + CVE-2000-0592 + 2000-06-27T00:00:00.000-04:00 + 2008-09-10T15:05:10.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow + + + BID + 1400 + + Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands. + + + + + + + + + + cpe:/a:sapporoworks:sapporoworks_winproxy:2.0.1 + cpe:/a:sapporoworks:sapporoworks_winproxy:2.0 + + CVE-2000-0593 + 2000-06-27T00:00:00.000-04:00 + 2008-09-10T15:05:10.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + winproxy-get-dos(4831) + + + BUGTRAQ + 20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow + + + BID + 1400 + + WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number. + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/a:caldera:openlinux_ebuilder:2.3 + cpe:/o:mandrakesoft:mandrake_linux:2007 + cpe:/o:freebsd:freebsd:4.0 + cpe:/a:caldera:openlinux_desktop:2.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0594 + 2000-07-04T00:00:00.000-04:00 + 2008-09-10T15:05:10.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + irc-bitchx-invite-dos + + + BID + 1436 + + + REDHAT + RHSA-2000:042 + + + CALDERA + CSSA-2000-022.0 + + + VULN-DEV + 20000704 BitchX /ignore bug + + + FREEBSD + FreeBSD-SA-00:32 + + + BUGTRAQ + 20000707 BitchX update + + + BUGTRAQ + 20000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchX + + + BUGTRAQ + 20000704 BitchX exploit possibly waiting to happen, certain DoS + + BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + + CVE-2000-0595 + 2000-07-05T00:00:00.000-04:00 + 2008-09-10T15:05:10.523-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1437 + + + FREEBSD + FreeBSD-SA-00:24 + + + OSVDB + 1446 + + libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory. + + + + + + + + + + cpe:/a:microsoft:ie:5 + cpe:/a:microsoft:ie:4.0.1:sp2 + + CVE-2000-0596 + 2000-06-27T00:00:00.000-04:00 + 2008-09-10T15:05:10.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2000-16 + + + BUGTRAQ + 20000627 IE 5 and Access 2000 vulnerability - executing programs + + + MS + MS00-049 + + + BUGTRAQ + 20000627 FW: IE 5 and Access 2000 vulnerability - executing programs + + + BID + 1398 + + Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability. + + + + + + + + + + + cpe:/a:microsoft:powerpoint:2000 + cpe:/a:microsoft:powerpoint:97 + cpe:/a:microsoft:excel:2000 + + CVE-2000-0597 + 2000-06-27T00:00:00.000-04:00 + 2008-09-10T15:05:10.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000627 IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs + + + MS + MS00-049 + + + BID + 1399 + + Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability. + + + + + + + + + cpe:/a:fortech:proxy%2b:2.40 + + CVE-2000-0598 + 2000-06-26T00:00:00.000-04:00 + 2008-09-10T15:05:11.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000626 Proxy+ Telnet Gateway Problems + + + MISC + http://www.proxyplus.cz/faq/articles/EN/art01002.htm + + + BID + 1395 + + Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy. + + + + + + + + + cpe:/a:imesh.com:imesh:1.02 + + CVE-2000-0599 + 2000-06-29T00:00:00.000-04:00 + 2008-09-10T15:05:11.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000629 iMesh 1.02 vulnerability + + + MISC + http://www.imesh.com/download/download.html + + + BID + 1407 + + Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port. + + + + + + + + + + + + + + + + cpe:/o:novell:netware:5.0 + cpe:/a:netscape:enterprise_server:5.0::netware + cpe:/a:netscape:enterprise_server:4.1.1::netware + cpe:/o:novell:netware:5.1 + + CVE-2000-0600 + 2000-06-26T00:00:00.000-04:00 + 2008-09-05T16:21:25.220-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + netscape-virtual-directory-bo(4780) + + + BID + 1393 + + + BUGTRAQ + 20000626 Netscape Enterprise Server for NetWare Virtual Directory Vulnerab ility + + Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL. + + + + + + + + + cpe:/a:leafdigital:leafchat:1.7 + + CVE-2000-0601 + 2000-06-25T00:00:00.000-04:00 + 2008-09-10T15:05:11.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000625 LeafChat Denial of Service + + + CONFIRM + http://www.leafdigital.com/Software/leafChat/history.html + + + BID + 1396 + + LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages. + + + + + + + + + + cpe:/a:kevin_lindsay:secure_locate:2.1 + cpe:/a:kevin_lindsay:secure_locate:2.0 + + CVE-2000-0602 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:11.743-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000621 rh 6.2 - gid compromises, etc + + + BID + 1385 + + Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable. + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + + CVE-2000-0603 + 2000-07-07T00:00:00.000-04:00 + 2008-09-10T15:05:11.807-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1444 + + + MS + MS00-048 + + + XF + mssql-procedure-perms + + Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability. + + + + + + + + + cpe:/o:redhat:linux:6.2 + + CVE-2000-0604 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:11.883-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000621 rh 6.2 - gid compromises, etc + + + BID + 1383 + + gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp. + + + + + + + + + cpe:/a:blackboard:courseinfo:4.0 + + CVE-2000-0605 + 2000-07-10T00:00:00.000-04:00 + 2008-09-10T15:05:11.947-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1460 + + + NTBUGTRAQ + 20000710 Two issues: Blackboard CourseInfo 4.0 stores admin password in clear text; strange settings on the winreg key. + + Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords. + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + + CVE-2000-0606 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:12.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000619 Problems with "kon2" package + + + BID + 1371 + + Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter. + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.3 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + + CVE-2000-0607 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:12.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000619 Problems with "kon2" package + + + BID + 1371 + + Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings. + + + + + + + + + + + + + + + + cpe:/a:netwin:dmailweb:2.6i + cpe:/a:netwin:dmailweb:2.6j + cpe:/a:netwin:dmailweb:2.5e + cpe:/a:netwin:dmailweb:2.6g + cpe:/a:netwin:cwmail:2.6g + cpe:/a:netwin:cwmail:2.6i + cpe:/a:netwin:cwmail:2.5e + cpe:/a:netwin:cwmail:2.6j + + CVE-2000-0608 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:12.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000620 NetWin dMailWeb Denial of Service + + + BID + 1376 + + NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost). + + + + + + + + + + + + + + + + cpe:/a:netwin:dmailweb:2.6i + cpe:/a:netwin:dmailweb:2.6j + cpe:/a:netwin:dmailweb:2.5e + cpe:/a:netwin:dmailweb:2.6g + cpe:/a:netwin:cwmail:2.6g + cpe:/a:netwin:cwmail:2.6i + cpe:/a:netwin:cwmail:2.5e + cpe:/a:netwin:cwmail:2.6j + + CVE-2000-0609 + 2000-06-21T00:00:00.000-04:00 + 2008-09-10T15:05:12.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000620 NetWin dMailWeb Denial of Service + + + BID + 1376 + + NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter. + + + + + + + + + + cpe:/a:netwin:dmailweb:2.6g + cpe:/a:netwin:cwmail:2.6g + + CVE-2000-0610 + 2000-06-23T00:00:00.000-04:00 + 2008-09-10T15:05:12.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1390 + + + XF + netwin-dmailweb-newline + + + BUGTRAQ + 20000623 NetWin dMailWeb Unrestricted Mail Relay + + NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return. + + + + + + + + + + cpe:/a:netwin:dmailweb:2.6g + cpe:/a:netwin:cwmail:2.6g + + CVE-2000-0611 + 2000-06-23T00:00:00.000-04:00 + 2008-09-05T16:21:26.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netwin-dmailweb-auth + + + BID + 1391 + + + BUGTRAQ + 20000623 NetWin dMailWeb Unrestricted Mail Relay + + The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-2000-0612 + 2000-06-29T00:00:00.000-04:00 + 2008-09-10T15:05:12.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000629 Buggy ARP handling in Windoze + + + BID + 1406 + + Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table. + + + + + + + + + cpe:/a:cisco:pix_firewall + + CVE-2000-0613 + 2000-03-20T00:00:00.000-05:00 + 2008-09-10T15:05:12.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000320 PIX DMZ Denial of Service - TCP Resets + + + XF + cisco-pix-firewall-tcp + + + BID + 1454 + + + OSVDB + 1457 + + + CISCO + 20000711 Cisco Secure PIX Firewall TCP Reset Vulnerability + + Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections. + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-0614 + 2000-07-10T00:00:00.000-04:00 + 2008-09-10T15:05:12.680-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1450 + + + SUSE + 20000710 Security Hole in tnef < 0-124 + + Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:astart_technologies:lprng:3.6.6 + cpe:/o:astart_technologies:lprng:3.6.7 + cpe:/o:astart_technologies:lprng:3.6.8 + cpe:/o:astart_technologies:lprng:3.6.9 + cpe:/o:astart_technologies:lprng:3.6.10 + cpe:/o:astart_technologies:lprng:3.6.13 + cpe:/o:astart_technologies:lprng:3.6.14 + cpe:/o:astart_technologies:lprng:3.6.11 + cpe:/o:astart_technologies:lprng:3.6.12 + cpe:/o:astart_technologies:lprng:3.6.1 + cpe:/o:astart_technologies:lprng:3.6.2 + cpe:/o:astart_technologies:lprng:3.6.3 + cpe:/o:astart_technologies:lprng:3.6.4 + cpe:/o:astart_technologies:lprng:3.6.15 + cpe:/o:astart_technologies:lprng:3.6.5 + + CVE-2000-0615 + 2000-07-19T00:00:00.000-04:00 + 2008-09-05T16:21:27.500-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1447 + + + BUGTRAQ + 20000709 LPRng lpd should not be SETUID root + + + XF + lpd-suid-root(7361) + + LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files. + + + + + + + + + + + + + cpe:/o:hp:mpe_ix:5.5 + cpe:/o:hp:mpe_ix:4.5 + cpe:/o:hp:mpe_ix:5.0 + cpe:/o:hp:mpe_ix:6.0 + cpe:/o:hp:mpe_ix:6.5 + + CVE-2000-0616 + 2000-06-26T00:00:00.000-04:00 + 2008-09-10T15:05:12.837-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1405 + + + HP + HPSBMP0006-007 + + Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS. + + + + + + + + + cpe:/a:stanley_t._shebs:xconq:7.2.2 + + CVE-2000-0617 + 2000-06-22T00:00:00.000-04:00 + 2008-09-10T15:05:12.960-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000622 RHL 6.2 xconq package - overflows yield gid games + + Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable. + + + + + + + + + cpe:/a:stanley_t._shebs:xconq:7.2.2 + + CVE-2000-0618 + 2000-06-22T00:00:00.000-04:00 + 2008-09-10T15:05:13.023-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000622 RHL 6.2 xconq package - overflows yield gid games + + Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable. + + + + + + + + + cpe:/h:toplayer:appswitch:2500.0 + + CVE-2000-0619 + 2000-07-19T00:00:00.000-04:00 + 2008-09-05T16:21:28.110-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1258 + + + VULN-DEV + 20000614 Update on TopLayer Advisory + + + VULN-DEV + 20000520 TopLayer layer 7 switch Advisory + + + XF + toplayer-icmp-dos(7364) + + Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets. + + + + + + + + + + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/a:open_group:x:11.0r6.3 + cpe:/a:open_group:x:11.0r6 + cpe:/a:open_group:x:11.0r6.2 + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:xfree86_project:x11r6:3.3.5 + cpe:/a:xfree86_project:x11r6:3.3.4 + cpe:/a:open_group:x:11.0r6.4 + cpe:/a:open_group:x:11.0r6.1 + cpe:/a:xfree86_project:x11r6:3.3.6 + + CVE-2000-0620 + 2000-06-19T00:00:00.000-04:00 + 2008-09-10T15:05:13.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + libx11-infinite-loop-dos(4996) + + + BID + 1409 + + + BUGTRAQ + 20000619 XFree86: Various nasty libX11 holes + + libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop. + + + + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook_express:4.0 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:outlook_express:5.0.1 + cpe:/a:microsoft:outlook_express:4.01 + + CVE-2000-0621 + 2000-07-20T00:00:00.000-04:00 + 2008-09-05T16:21:28.423-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2000-14 + + + BID + 1501 + + + MS + MS00-046 + + + XF + outlook-cache-bypass + + Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability. + + + + + + + + + + + cpe:/a:oreilly:website_professional:2.4 + cpe:/a:oreilly:website_professional:2.3.18 + cpe:/a:oreilly:website_professional:2.4.9 + + CVE-2000-0622 + 2000-07-19T00:00:00.000-04:00 + 2008-09-10T15:05:13.540-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://website.oreilly.com/support/software/wspro25_releasenotes.txt + + + XF + website-webfind-bo(4962) + + + BID + 1487 + + + NAI + 20000719 O'Reilly WebSite Professional Overflow + + Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter. + + + + + + + + + + + cpe:/a:oreilly:website_professional:2.4 + cpe:/a:oreilly:website_professional:2.3.18 + cpe:/a:oreilly:website_professional:2.4.9 + + CVE-2000-0623 + 2000-07-17T00:00:00.000-04:00 + 2008-09-10T15:05:13.663-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1492 + + + NTBUGTRAQ + 20000719 Alert: Buffer Overrun is O'Reilly WebsitePro httpd32.exe (CISADV000717) + + Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header. + + + + + + + + + cpe:/a:nullsoft:winamp:2.64 + + CVE-2000-0624 + 2000-07-20T00:00:00.000-04:00 + 2008-09-05T16:21:28.877-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + winamp-playlist-parser-bo + + + CONFIRM + http://www.winamp.com/getwinamp/newfeatures.jhtml + + + BID + 1496 + + + BUGTRAQ + 20000720 Winamp M3U playlist parser buffer overflow security vulnerability + + Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist. + + + + + + + + + cpe:/a:netzero:zeroport:3.0 + + CVE-2000-0625 + 2000-07-18T00:00:00.000-04:00 + 2008-09-10T15:05:28.210-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1483 + + + L0PHT + 20000718 NetZero Password Encryption Algorithm + + NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password. + + + + + + + + + cpe:/a:computer_software_manufaktur:alibaba:2.0 + + CVE-2000-0626 + 2000-07-18T00:00:00.000-04:00 + 2008-09-10T15:05:28.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1482 + + + BUGTRAQ + 20000718 Multiple bugs in Alibaba 2.0 + + Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. + + + + + + + + + + cpe:/a:blackboard:courseinfo:4.0 + cpe:/a:blackboard:courseinfo:unix + + CVE-2000-0627 + 2000-07-18T00:00:00.000-04:00 + 2008-09-05T16:21:29.313-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + blackboard-courseinfo-dbase-modification + + + BID + 1486 + + + BUGTRAQ + 20000718 Blackboard Courseinfo v4.0 User Authentication + + + BUGTRAQ + 20000719 Security Fix for Blackboard CourseInfo 4.0 + + BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl. + + + + + + + + + + + + cpe:/a:joshua_chamas:apache_asp:1.93 + cpe:/a:joshua_chamas:apache_asp:0.18 + cpe:/a:joshua_chamas:apache_asp:0.17 + cpe:/a:joshua_chamas:apache_asp:0.16 + + CVE-2000-0628 + 2000-07-11T00:00:00.000-04:00 + 2008-09-05T16:21:29.453-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + apache-source-asp-file-write + + + BID + 1457 + + + BUGTRAQ + 20000710 ANNOUNCE Apache::ASP v1.95 - Security Hole Fixed + + + CONFIRM + http://www.nodeworks.com/asp/changes.html + + The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files. + + + + + + + + + + cpe:/a:sun:java_system_web_server:1.1.3 + cpe:/a:sun:java_system_web_server:2.0 + + CVE-2000-0629 + 2000-07-12T00:00:00.000-04:00 + 2008-09-10T15:05:28.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html + + + BUGTRAQ + 20000711 Sun's Java Web Server remote command execution vulnerability + + + BID + 1459 + + The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0630 + 2000-07-17T00:00:00.000-04:00 + 2008-09-10T15:05:28.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-044 + + + XF + iis-htr-obtain-code + + + BID + 1488 + + IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0631 + 2000-07-14T00:00:00.000-04:00 + 2008-09-05T16:21:29.890-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-absent-directory-dos + + + BID + 1476 + + + MS + MS00-044 + + + BUGTRAQ + 20000718 ISBASE Security Advisory(SA2000-02) + + An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. + + + + + + + + + + cpe:/a:lsoft:listserv:1.8c + cpe:/a:lsoft:listserv:1.8d + + CVE-2000-0632 + 2000-07-17T00:00:00.000-04:00 + 2008-09-10T15:05:30.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.lsoft.com/news/default.asp?item=Advisory1 + + + XF + lsoft-listserv-querystring-bo + + + BID + 1490 + + + NAI + 20000717 [COVERT-2000-07] LISTSERV Web Archive Remote Overflow + + Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.2e::alpha + cpe:/o:conectiva:linux:4.0es + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:conectiva:linux:4.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.2e::i386 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2e::sparc + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0633 + 2000-07-18T00:00:00.000-04:00 + 2008-09-05T16:21:30.187-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-usermode-dos + + + BID + 1489 + + + BUGTRAQ + 20000718 MDKSA-2000:020 usermode update + + + REDHAT + RHSA-2000:053 + + + BUGTRAQ + 20000812 Conectiva Linux security announcement - usermode + + Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system. + + + + + + + + + cpe:/a:stalker:communigate_pro:3.2.4 + + CVE-2000-0634 + 2000-04-03T00:00:00.000-04:00 + 2008-09-10T15:05:31.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1493 + + + BUGTRAQ + 20000717 S21SEC-003: Vulnerabilities in CommuniGate Pro v3.2.4 + + + XF + communigate-pro-file-read + + + OSVDB + 5774 + + The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + cpe:/a:akopia:minivend:4.0.4 + cpe:/a:akopia:minivend:4.0 + cpe:/a:akopia:minivend:3.0 + + CVE-2000-0635 + 2000-07-10T00:00:00.000-04:00 + 2008-09-05T16:21:30.517-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + minivend-viewpage-sample + + + BID + 1449 + + + CONFIRM + http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html + + + BUGTRAQ + 20000711 Akopia MiniVend Piped Command Execution Vulnerability + + The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + + + + + + + + + cpe:/h:hp:jetdirect:rev._h.08.20 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.17 + cpe:/h:hp:jetdirect:rev._g.08.20 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.02 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.03 + cpe:/h:hp:jetdirect:rev._h.08.05 + cpe:/h:hp:jetdirect:j3111a_rev._a.08.06 + cpe:/h:hp:jetdirect:rev._g.08.04 + cpe:/h:hp:jetdirect:j3111a_rev._g.08.03 + cpe:/h:hp:jetdirect:j3111a_rev._g.05.35 + + CVE-2000-0636 + 2000-07-19T00:00:00.000-04:00 + 2008-09-05T16:21:30.673-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1491 + + + BUGTRAQ + 20000719 HP Jetdirect - Invalid FTP Command DoS + + + XF + hp-jetdirect-quote-dos + + HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command. + + + + + + + + + + cpe:/a:microsoft:excel:97 + cpe:/a:microsoft:excel:2000 + + CVE-2000-0637 + 2000-07-26T00:00:00.000-04:00 + 2008-09-05T16:21:30.877-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + excel-register-function + + + BUGTRAQ + 20000711 Excel 2000 vulnerability - executing programs + + + MS + MS00-051 + + + BID + 1451 + + Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability. + + + + + + + + + + + + + + + + + + + + cpe:/a:sean_macguire:big_brother:1.3 + cpe:/a:sean_macguire:big_brother:1.4h1 + cpe:/a:sean_macguire:big_brother:1.4 + cpe:/a:sean_macguire:big_brother:1.1 + cpe:/a:sean_macguire:big_brother:1.2 + cpe:/a:sean_macguire:big_brother:1.4h + cpe:/a:sean_macguire:big_brother:1.4g + cpe:/a:sean_macguire:big_brother:1.0 + cpe:/a:sean_macguire:big_brother:1.3b + cpe:/a:sean_macguire:big_brother:1.09c + cpe:/a:sean_macguire:big_brother:1.09b + cpe:/a:sean_macguire:big_brother:1.09d + + CVE-2000-0638 + 2000-07-11T00:00:00.000-04:00 + 2008-09-10T15:05:31.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-bigbrother-bbhostsvc + + + BID + 1455 + + + CONFIRM + http://bb4.com/README.CHANGES + + + BUGTRAQ + 20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER + + + BUGTRAQ + 20000711 BIG BROTHER EXPLOIT + + bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter. + + + + + + + + + + + + + + + + + + + + cpe:/a:sean_macguire:big_brother:1.3 + cpe:/a:sean_macguire:big_brother:1.4h1 + cpe:/a:sean_macguire:big_brother:1.4 + cpe:/a:sean_macguire:big_brother:1.1 + cpe:/a:sean_macguire:big_brother:1.2 + cpe:/a:sean_macguire:big_brother:1.4h + cpe:/a:sean_macguire:big_brother:1.4g + cpe:/a:sean_macguire:big_brother:1.0 + cpe:/a:sean_macguire:big_brother:1.3b + cpe:/a:sean_macguire:big_brother:1.09c + cpe:/a:sean_macguire:big_brother:1.09b + cpe:/a:sean_macguire:big_brother:1.09d + + CVE-2000-0639 + 2000-06-11T00:00:00.000-04:00 + 2008-09-10T15:05:31.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000711 Big Brother filename extension vulnerability + + + BID + 1494 + + + XF + big-brother-filename-extension + + + OSVDB + 1472 + + The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server. + + + + + + + + + cpe:/a:steve_poulsen:guildftpd:0.9.7 + + CVE-2000-0640 + 2000-07-08T00:00:00.000-04:00 + 2008-09-05T16:21:31.360-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd + + + XF + guild-ftpd-disclosure + + + BID + 1452 + + + OSVDB + 573 + + Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not. + + + + + + + + + cpe:/a:michael_lamont:savant_webserver:2.1 + + CVE-2000-0641 + 2000-07-08T00:00:00.000-04:00 + 2008-09-05T16:21:31.500-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + savant-get-bo + + + BID + 1453 + + + BUGTRAQ + 20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd + + Savant web server allows remote attackers to execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:itafrica:webactive:1.0 + + CVE-2000-0642 + 2000-07-12T00:00:00.000-04:00 + 2008-09-05T16:21:31.640-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000711 Lame DoS in WEBactive win65/NT server + + + BID + 1497 + + + XF + webactive-active-log + + The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page. + + + + + + + + + cpe:/a:itafrica:webactive:1.0 + + CVE-2000-0643 + 2000-07-12T00:00:00.000-04:00 + 2008-09-05T16:21:31.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + webactive-long-get-dos + + + BUGTRAQ + 20000711 Lame DoS in WEBactive win65/NT server + + + BID + 1470 + + Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0644 + 2000-07-21T00:00:00.000-04:00 + 2008-09-10T15:05:31.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1506 + + + BUGTRAQ + 20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities. + + + XF + wftpd-stat-dos + + + OSVDB + 1477 + + WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0645 + 2000-07-21T00:00:00.000-04:00 + 2008-09-10T15:05:31.837-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1506 + + + BUGTRAQ + 20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities. + + WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE). + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0646 + 2000-07-21T00:00:00.000-04:00 + 2008-09-10T15:05:31.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1506 + + + BUGTRAQ + 20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities. + + WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred. + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0647 + 2000-07-21T00:00:00.000-04:00 + 2008-09-10T15:05:32.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1506 + + + BUGTRAQ + 20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities. + + WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server. + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.4.1 + + CVE-2000-0648 + 2000-07-11T00:00:00.000-04:00 + 2008-09-10T15:05:32.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1456 + + + BUGTRAQ + 20000711 WFTPD/WFTPD Pro 2.41 RC10 denial-of-service + + WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command. + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:3.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:internet_information_server:2.0 + + CVE-2000-0649 + 2000-07-13T00:00:00.000-04:00 + 2008-09-10T15:05:32.147-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 1499 + + + NTBUGTRAQ + 20000713 IIS4 Basic authentication realm issue + + IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. + + + + + + + + + + cpe:/a:network_associates:virusscan:4.5::windows_nt + cpe:/a:network_associates:netshield:4.5 + + CVE-2000-0650 + 2000-07-11T00:00:00.000-04:00 + 2008-09-05T16:21:32.827-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1458 + + + NTBUGTRAQ + 20000711 Potential Vulnerability in McAfee Netshield and VirusScan 4.5 + + + XF + nai-virusscan-netshield-autoupgrade(5177) + + + OSVDB + 4200 + + + OSVDB + 1458 + + The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse. + + + + + + + + + + cpe:/a:novell:bordermanager:3.5 + cpe:/a:novell:bordermanager:3.0 + + CVE-2000-0651 + 2000-07-07T00:00:00.000-04:00 + 2008-09-10T15:05:32.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1440 + + + XF + novell-bordermanager-verification + + + BUGTRAQ + 20000707 Novell Border Manger - Anyone can pose as an authenticated user + + The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine. + + + + + + + + + + + cpe:/a:ibm:websphere_application_server:2.0 + cpe:/a:ibm:websphere_application_server:3.0.21 + cpe:/a:ibm:websphere_application_server:3.0 + + CVE-2000-0652 + 2000-07-24T00:00:00.000-04:00 + 2008-09-10T15:05:32.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1500 + + + BUGTRAQ + 20000723 IBM WebSphere default servlet handler showcode vulnerability + + + XF + websphere-showcode + + IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string. + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook_express:4.0 + cpe:/a:microsoft:outlook_express:5.0.1 + cpe:/a:microsoft:outlook_express:4.01 + + CVE-2000-0653 + 2000-07-20T00:00:00.000-04:00 + 2008-09-10T15:05:32.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1502 + + + MS + MS00-045 + + Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability. + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + + CVE-2000-0654 + 2000-07-11T00:00:00.000-04:00 + 2008-09-05T16:21:33.407-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mssql-dts-reveal-passwords + + + BID + 1466 + + + MS + MS00-041 + + Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.5_beta + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:mozilla:mozilla:m15 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.05 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.72 + cpe:/a:netscape:communicator:4.07 + + CVE-2000-0655 + 2000-07-25T00:00:00.000-04:00 + 2008-09-10T15:05:32.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000724 JPEG COM Marker Processing Vulnerability in Netscape Browsers + + + TURBO + TLSA2000017-1 + + + BID + 1503 + + + REDHAT + RHSA-2000:046 + + + SUSE + 20000823 Security Hole in Netscape, Versions 4.x, possibly others + + + BUGTRAQ + 20000810 Conectiva Linux Security Announcement - netscape + + + BUGTRAQ + 20000801 MDKSA-2000:027-1 netscape update + + + NETBSD + NetBSD-SA2000-011 + + + FREEBSD + FreeBSD-SA-00:39 + + Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1. + + + + + + + + + cpe:/a:analogx:proxy:4.4 + + CVE-2000-0656 + 2000-07-25T00:00:00.000-04:00 + 2008-09-10T15:05:32.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1504 + + + BUGTRAQ + 20000724 AnalogX Proxy DoS + + + CONFIRM + http://www.analogx.com/contents/download/network/proxy.htm + + Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol. + + + + + + + + + cpe:/a:analogx:proxy:4.4 + + CVE-2000-0657 + 2000-07-25T00:00:00.000-04:00 + 2008-09-05T16:21:33.877-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1504 + + + BUGTRAQ + 20000724 AnalogX Proxy DoS + + + CONFIRM + http://www.analogx.com/contents/download/network/proxy.htm + + Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol. + + + + + + + + + cpe:/a:analogx:proxy:4.4 + + CVE-2000-0658 + 2000-07-25T00:00:00.000-04:00 + 2008-09-10T15:05:32.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1504 + + + BUGTRAQ + 20000724 AnalogX Proxy DoS + + + CONFIRM + http://www.analogx.com/contents/download/network/proxy.htm + + Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol. + + + + + + + + + cpe:/a:analogx:proxy:4.4 + + CVE-2000-0659 + 2000-07-25T00:00:00.000-04:00 + 2008-09-10T15:05:33.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1504 + + + BUGTRAQ + 20000724 AnalogX Proxy DoS + + Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request. + + + + + + + + + cpe:/a:alt-n:worldclient:2.1::standard + + CVE-2000-0660 + 2000-07-12T00:00:00.000-04:00 + 2008-09-05T16:21:34.327-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000712 Infosec.20000712.worldclient.2.1 + + + XF + worldclient-dir-traverse + + + BID + 1462 + + + CONFIRM + http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt + + + OSVDB + 1459 + + The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:wircsrv:irc_server:5.0.7s + + CVE-2000-0661 + 2000-07-10T00:00:00.000-04:00 + 2008-09-05T16:21:34.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wircsrv-character-flood-dos + + + BID + 1448 + + + BUGTRAQ + 20000710 Remote DoS Attack in WircSrv Irc Server v5.07s Vulnerability + + WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0662 + 2000-07-14T00:00:00.000-04:00 + 2008-09-10T15:05:33.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000714 IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files + + + XF + ie-dhtmled-file-read(5107) + + + BID + 1474 + + Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED). + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0663 + 2000-07-25T00:00:00.000-04:00 + 2008-09-05T16:21:34.750-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + explorer-relative-path-name + + + BID + 1507 + + + MS + MS00-052 + + + MSKB + Q269049 + + The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability. + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.0.6 + + CVE-2000-0664 + 2000-07-26T00:00:00.000-04:00 + 2008-09-10T15:05:33.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000726 AnalogX "SimpleServer:WWW" dot dot bug + + + CONFIRM + http://www.analogx.com/contents/download/network/sswww.htm + + + XF + analogx-simpleserver-directory-path + + + BID + 1508 + + + OSVDB + 388 + + AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots. + + + + + + + + + + cpe:/a:gamsoft:telsrv:1.4 + cpe:/a:gamsoft:telsrv:1.5 + + CVE-2000-0665 + 2000-07-17T00:00:00.000-04:00 + 2008-09-05T16:21:35.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000717 DoS in Gamsoft TelSrv telnet server for MS Windows 95/98/NT/2k. + + + XF + gamsoft-telsrv-dos + + + BID + 1478 + + + OSVDB + 373 + + + NTBUGTRAQ + 20000729 TelSrv Reveals Usernames & Passwords After DoS Attack + + GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.3::sparc + cpe:/o:debian:debian_linux:2.3::alpha + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:suse:suse_linux:6.4:alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:conectiva:linux:4.0es + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:conectiva:linux:4.2 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:conectiva:linux:4.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:trustix:secure_linux:1.0 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:conectiva:linux:4.0 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:debian:debian_linux:2.3 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::powerpc + cpe:/o:debian:debian_linux:2.3::powerpc + + CVE-2000-0666 + 2000-07-16T00:00:00.000-04:00 + 2008-09-05T16:21:35.187-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-17 + + + XF + linux-rpcstatd-format-overwrite + + + BID + 1480 + + + BUGTRAQ + 20000716 Lots and lots of fun with rpc.statd + + + REDHAT + RHSA-2000:043 + + + CALDERA + CSSA-2000-025.0 + + + BUGTRAQ + 20000718 [Security Announce] MDKSA-2000:021 nfs-utils update + + + BUGTRAQ + 20000718 Trustix Security Advisory - nfs-utils + + + BUGTRAQ + 20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils + + rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. + + + + + + + + + + + + + + cpe:/o:conectiva:linux:4.0es + cpe:/o:conectiva:linux:4.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2000-0667 + 2000-07-27T00:00:00.000-04:00 + 2008-09-10T15:05:33.883-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1512 + + + CALDERA + CSSA-2000-024.0 + + Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:4.0es + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:conectiva:linux:4.2 + cpe:/o:conectiva:linux:4.1 + cpe:/a:michael_k._johnson:pam_console:0.72_unpatched + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:conectiva:linux:5.1 + cpe:/a:michael_k._johnson:pam_console:0.66 + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0668 + 2000-07-27T00:00:00.000-04:00 + 2008-09-10T15:05:33.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-pam-console + + + BID + 1513 + + + REDHAT + RHSA-2000:044 + + + BUGTRAQ + 20000801 MDKSA-2000:029 pam update + + + BUGTRAQ + 20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - PAM + + pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled. + + + + + + + + + cpe:/o:novell:netware:5.0:sp5 + + CVE-2000-0669 + 2000-07-11T00:00:00.000-04:00 + 2008-09-10T15:05:34.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000711 Remote Denial Of Service -- NetWare 5.0 with SP 5 + + + BID + 1467 + + Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data. + + + + + + + + + cpe:/a:cvsweb_developer:cvsweb:1.80 + + CVE-2000-0670 + 2000-07-12T00:00:00.000-04:00 + 2008-09-10T15:05:34.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cvsweb-shell-access + + + BUGTRAQ + 20000714 MDKSA-2000:019 cvsweb update + + + TURBO + TLSA2000016-1 + + + BID + 1469 + + + BUGTRAQ + 20000712 cvsweb: remote shell for cvs committers + + + FREEBSD + FreeBSD-SA-00:37 + + The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:roxen:webserver:2.0.x + + CVE-2000-0671 + 2000-07-21T00:00:00.000-04:00 + 2008-09-10T15:05:34.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000721 Roxen security alert: Problems with URLs containing null characters. + + + XF + roxen-null-char-url + + + BID + 1510 + + + BUGTRAQ + 20000721 Roxen Web Server Vulnerability + + Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL. + + + + + + + + + + + cpe:/a:apache:tomcat:3.1 + cpe:/a:apache:tomcat:3.0 + cpe:/a:apache:http_server:3.1 + + CVE-2000-0672 + 2000-07-20T00:00:00.000-04:00 + 2008-09-10T15:05:34.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000721 Jakarta-tomcat.../admin + + + XF + jakarta-tomcat-admin + + + BID + 1548 + + The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory. + + + + + + + + + + + cpe:/o:microsoft:windows_nt:terminal_server + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0673 + 2000-07-27T00:00:00.000-04:00 + 2008-09-05T16:21:36.327-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netbios-name-server-spoofing + + + BID + 1514 + + + MS + MS00-047 + + + BID + 1515 + + + NAI + 20000727 Windows NetBIOS Name Conflicts + + The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability. + + + + + + + + + cpe:/a:virtual_vision:ftp_browser:1.0 + + CVE-2000-0674 + 2000-07-12T00:00:00.000-04:00 + 2008-09-05T16:21:36.483-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1471 + + + BUGTRAQ + 20000712 ftp.pl vulnerability + + + XF + virtualvision-ftp-browser + + ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack. + + + + + + + + + cpe:/a:infopulse:gatekeeper:3.5 + + CVE-2000-0675 + 2000-07-13T00:00:00.000-04:00 + 2008-09-05T16:21:36.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + gatekeeper-long-string-bo + + + BID + 1477 + + + BUGTRAQ + 20000713 The MDMA Crew's GateKeeper Exploit + + Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.04 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.05 + cpe:/a:netscape:communicator:4.5_beta + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.72 + cpe:/a:netscape:communicator:4.07 + + CVE-2000-0676 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:34.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-15 + + + BID + 1546 + + + REDHAT + RHSA-2000:054 + + + SUSE + 20000823 Security Hole in Netscape, Versions 4.x, possibly others + + + CALDERA + CSSA-2000-027.1 + + + BUGTRAQ + 20000821 MDKSA-2000:036 - netscape update + + + BUGTRAQ + 20000818 Conectiva Linux Security Announcement - netscape + + + BUGTRAQ + 20000810 MDKSA-2000:033 Netscape Java vulnerability + + + BUGTRAQ + 20000804 Dangerous Java/Netscape Security Hole + + + FREEBSD + FreeBSD-SA-00:39 + + Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice. + + + + + + + + + cpe:/a:ibm:net.data + + CVE-2000-0677 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:36.937-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ISS + 20000907 Buffer Overflow in IBM Net.Data db2www CGI program. + + + XF + ibm-netdata-db2www-bo + + Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable. + + + + + + + + + + + cpe:/a:pgp:pgp:6.5.3i + cpe:/a:pgp:pgp:6.5.1i + cpe:/a:pgp:pgp:5.5.3i + + CVE-2000-0678 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:34.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-18 + + + BID + 1606 + + + OSVDB + 4354 + + PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate. + + + + + + + + + cpe:/a:cvs:cvs:1.10.8 + + CVE-2000-0679 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:37.233-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000728 cvs security problem + + + BID + 1523 + + The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files. + + + + + + + + + cpe:/a:cvs:cvs:1.10.8 + + CVE-2000-0680 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:37.373-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1524 + + + BUGTRAQ + 20000728 cvs security problem + + The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action. + + + + + + + + + cpe:/a:bea:weblogic_server:4.5.2:sp2 + + CVE-2000-0681 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:37.517-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1570 + + + BUGTRAQ + 20000815 BEA Weblogic server proxy library vulnerabilities + + Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:5.1:sp2:express + cpe:/a:bea:weblogic_server:5.1:sp3:express + cpe:/a:bea:weblogic_server:5.1:sp4:express + cpe:/a:bea:weblogic_server:5.1:sp1:express + cpe:/a:bea:weblogic_server:5.1:sp7:express + cpe:/a:bea:weblogic_server:5.1:sp11:express + cpe:/a:bea:weblogic_server:5.1:sp8:express + cpe:/a:bea:weblogic_server:5.1:sp5:express + cpe:/a:bea:weblogic_server:5.1:sp12:express + cpe:/a:bea:weblogic_server:5.1 + cpe:/a:bea:weblogic_server:5.1:sp10:express + cpe:/a:bea:weblogic_server:5.1:sp9:express + cpe:/a:bea:weblogic_server:5.1::enterprise + cpe:/a:bea:weblogic_server:5.1:sp6:express + cpe:/a:bea:weblogic_server:5.1::express + + CVE-2000-0682 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:37.670-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1518 + + + BUGTRAQ + 20000728 BEA's WebLogic force handlers show code vulnerability + + + OSVDB + 1481 + + + CONFIRM + http://developer.bea.com/alerts/security_000731.html + + BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:5.1:sp2:express + cpe:/a:bea:weblogic_server:5.1:sp3:express + cpe:/a:bea:weblogic_server:5.1:sp4:express + cpe:/a:bea:weblogic_server:5.1:sp1:express + cpe:/a:bea:weblogic_server:5.1:sp7:express + cpe:/a:bea:weblogic_server:5.1:sp11:express + cpe:/a:bea:weblogic_server:5.1:sp8:express + cpe:/a:bea:weblogic_server:5.1:sp5:express + cpe:/a:bea:weblogic_server:5.1:sp12:express + cpe:/a:bea:weblogic_server:5.1 + cpe:/a:bea:weblogic_server:5.1:sp10:express + cpe:/a:bea:weblogic_server:5.1:sp9:express + cpe:/a:bea:weblogic_server:5.1::enterprise + cpe:/a:bea:weblogic_server:5.1:sp6:express + cpe:/a:bea:weblogic_server:5.1::express + + CVE-2000-0683 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:37.843-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1517 + + + BUGTRAQ + 20000728 BEA's WebLogic force handlers show code vulnerability + + + OSVDB + 1480 + + + CONFIRM + http://developer.bea.com/alerts/security_000728.html + + BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet. + + + + + + + + + + + cpe:/a:bea:weblogic_server:3.1.8 + cpe:/a:bea:weblogic_server:4.5.1 + cpe:/a:bea:weblogic_server:4.0.4 + + CVE-2000-0684 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:37.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1525 + + + BUGTRAQ + 20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution + + + CONFIRM + http://developer.bea.com/alerts/security_000731.html + + BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file. + + + + + + + + + + + cpe:/a:bea:weblogic_server:3.1.8 + cpe:/a:bea:weblogic_server:4.5.1 + cpe:/a:bea:weblogic_server:4.0.4 + + CVE-2000-0685 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:37.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1525 + + + BUGTRAQ + 20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution + + + CONFIRM + http://developer.bea.com/alerts/security_000731.html + + BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file. + + + + + + + + + cpe:/a:cgi_script_center:auction_weaver:1.02 + + CVE-2000-0686 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:38.313-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1630 + + + BUGTRAQ + 20000823 Auction WeaverT LITE 1.0 + + Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter. + + + + + + + + + cpe:/a:cgi_script_center:auction_weaver:1.02 + + CVE-2000-0687 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:38.453-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1630 + + + BUGTRAQ + 20000823 Auction WeaverT LITE 1.0 + + Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter. + + + + + + + + + cpe:/a:cgi_script_center:subscribe_me_lite:2.0 + + CVE-2000-0688 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:38.593-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1607 + + + CONFIRM + http://www.cgiscriptcenter.com/subscribe/ + + + BUGTRAQ + 20000823 Subscribe Me Vulnerability + + + BUGTRAQ + 20000823 Re: Subscribe Me CGI Vulnerability + + Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter. + + + + + + + + + + cpe:/a:cgi_script_center:account_manager:lite_1.0 + cpe:/a:cgi_script_center:account_manager:pro_1.0 + + CVE-2000-0689 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:38.733-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1604 + + + CONFIRM + http://www.cgiscriptcenter.com/acctlite/ + + + BUGTRAQ + 20000823 Account Manager CGI Vulnerability + + + XF + account-manager-overwrite-password(5125) + + + OSVDB + 13341 + + Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter. + + + + + + + + + + cpe:/a:cgi_script_center:auction_weaver:1.02 + cpe:/a:cgi_script_center:auction_weaver:1.0 + + CVE-2000-0690 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:38.697-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000830 More problems with Auction Weaver & CGI Script Center. + + + BUGTRAQ + 20000830 More problems with Auction Weaver & CGI Script Center. + + Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter. + + + + + + + + + + + cpe:/a:gert_doering:mgetty:1.1.19 + cpe:/a:gert_doering:mgetty:1.1.20 + cpe:/a:gert_doering:mgetty:1.1.21 + + CVE-2000-0691 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:39.030-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1612 + + + CALDERA + CSSA-2000-029.0 + + + CONFIRM + http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html + + + BUGTRAQ + 20000826 Advisory: mgetty local compromise + + The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file. + + + + + + + + + + cpe:/a:iss:realsecure:3.2.2 + cpe:/a:iss:realsecure:3.2.1 + + CVE-2000-0692 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:39.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000822 DOS on RealSecure 3.2 + + + BID + 1597 + + ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set. + + + + + + + + + cpe:/a:tech-source:raptor_gfx_pgx32:2.3.1 + + CVE-2000-0693 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:39.327-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1563 + + + BUGTRAQ + 20000802 Local root compromise in PGX Config Sun Sparc Solaris + + + OSVDB + 1501 + + pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program. + + + + + + + + + cpe:/a:tech-source:raptor_gfx_pgx32:2.3.1 + + CVE-2000-0694 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:39.467-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000802 Local root compromise in PGX Config Sun Sparc Solaris + + + OSVDB + 5740 + + pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack. + + + + + + + + + cpe:/a:tech-source:raptor_gfx_pgx32:2.3.1 + + CVE-2000-0695 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:39.610-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000802 Local root compromise in PGX Config Sun Sparc Solaris + + Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options. + + + + + + + + + + + + cpe:/a:sun:solaris_answerbook2:1.4 + cpe:/a:sun:solaris_answerbook2:1.3 + cpe:/a:sun:solaris_answerbook2:1.4.2 + cpe:/a:sun:solaris_answerbook2:1.4.1 + + CVE-2000-0696 + 2000-10-20T00:00:00.000-04:00 + 2008-09-24T00:07:12.157-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1554 + + + SUN + 00196 + + + XF + solaris-answerbook2-admin-interface(5069) + + + MISC + http://www.s21sec.com/en/avisos/s21sec-004-en.txt + + + BUGTRAQ + 20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server + + The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script. + + + + + + + + + + + + cpe:/a:sun:solaris_answerbook2:1.4 + cpe:/a:sun:solaris_answerbook2:1.3 + cpe:/a:sun:solaris_answerbook2:1.4.2 + cpe:/a:sun:solaris_answerbook2:1.4.1 + + CVE-2000-0697 + 2000-10-20T00:00:00.000-04:00 + 2008-09-24T00:07:12.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1556 + + + SUN + 00196 + + + MISC + http://www.s21sec.com/en/avisos/s21sec-004-en.txt + + + XF + solaris-answerbook2-remote-execution(5058) + + + BUGTRAQ + 20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server + + The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters. + + + + + + + + + + + + cpe:/a:minicom:minicom:1.83.1 + cpe:/a:minicom:minicom:1.83.0 + cpe:/a:minicom:minicom:1.82.1 + cpe:/a:minicom:minicom:1.82.0 + + CVE-2000-0698 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:40.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1599 + + + BUGTRAQ + 20000819 RH 6.1 / 6.2 minicom vulnerability + + + XF + minicom-capture-groupown + + Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0699 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:40.203-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1560 + + + BUGTRAQ + 20000806 HPUX FTPd vulnerability + + Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.2%2810%29 + cpe:/o:cisco:ios:11.3 + cpe:/o:cisco:ios:11.2 + cpe:/o:cisco:ios:11.2p + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.0%283%29 + cpe:/o:cisco:ios:12.0%287%29t + cpe:/o:cisco:ios:12.0%284%29 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.2%288%29 + cpe:/h:cisco:gigabit_switch_router_12012 + cpe:/o:cisco:ios:11.3%281%29 + cpe:/o:cisco:ios:12.0%282%29 + cpe:/h:cisco:gigabit_switch_router_12016 + cpe:/o:cisco:ios:12.0%281%29 + cpe:/h:cisco:gigabit_switch_router_12008 + cpe:/o:cisco:ios:12.0%286%29 + cpe:/o:cisco:ios:12.0%285%29 + + CVE-2000-0700 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:40.360-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1541 + + + CISCO + 20000803 Possible Access Control Bypass and Denial of Service in Gigabit Switch Routers Using Gigabit Ethernet or Fast Ethernet Cards + + + OSVDB + 798 + + + OSVDB + 793 + + + + + Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets. + + + + + + + + + + + + + + + + + + + cpe:/a:gnu:mailman:2.0:beta3 + cpe:/o:redhat:linux + cpe:/o:conectiva:linux:4.2 + cpe:/o:conectiva:linux:4.1 + cpe:/a:gnu:mailman:2.0:beta4 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2000-0701 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:39.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1539 + + + BUGTRAQ + 20000801 Advisory: mailman local compromise + + + BUGTRAQ + 20000802 CONECTIVA LINUX SECURITY ANNOUNCEMENT - mailman + + + REDHAT + RHSA-2000:030 + + + BUGTRAQ + 20000802 MDKSA-2000:030 - Linux-Mandrake not affected by mailman problem + + + CONFIRM + http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000802105050.A11733@rak.isternet.sk + + The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0702 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:40.703-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1602 + + + BUGTRAQ + 20000821 [HackersLab bugpaper] HP-UX net.init rc script + + + XF + hp-netinit-symlink + + The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file. + + + + + + + + + + + + cpe:/a:larry_wall:perl:5.4.5 + cpe:/a:larry_wall:perl:5.5.3 + cpe:/a:larry_wall:perl:5.6 + cpe:/a:larry_wall:perl:5.5 + + CVE-2000-0703 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:39.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1547 + + + CALDERA + CSSA-2000-026.0 + + + BUGTRAQ + 20000805 sperl 5.00503 (and newer ;) exploit + + + TURBO + TLSA2000018-1 + + + REDHAT + RHSA-2000:048 + + + SUSE + 20000810 Security Hole in perl, all versions + + + BUGTRAQ + 20000814 Trustix Security Advisory - perl and mailx + + + BUGTRAQ + 20000810 Conectiva Linux security announcemente - PERL + + + BUGTRAQ + 20000808 MDKSA-2000:031 perl update + + suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence. + + + + + + + + + + + + + + + cpe:/a:omron:worldview:6.5 + cpe:/a:freewnn:freewnn:1.1.1_axxx + cpe:/a:wnn:wnn4:4.2.5tl + cpe:/a:wnn:wnn4:4.2.2tl + cpe:/a:freewnn:freewnn:1.1 + cpe:/a:wnn:wnn4:4.2.8 + cpe:/a:freewnn:freewnn:1.0 + + CVE-2000-0704 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:41.030-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1603 + + + SGI + 20000803-01-A + + + XF + irix-worldview-wnn-bo(5163) + + + OSVDB + 11080 + + Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands. + + + + + + + + + cpe:/a:luca_deri:ntop:1.2a7_9 + + CVE-2000-0705 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:39.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1550 + + + BUGTRAQ + 20000802 [ Hackerslab bug_paper ] ntop web mode vulnerabliity + + + REDHAT + RHSA-2000:049 + + + OSVDB + 1496 + + ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:luca_deri:ntop:1.2a7_9 + cpe:/a:luca_deri:ntop:1.3.1 + + CVE-2000-0706 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:40.057-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1576 + + + DEBIAN + 20000830 ntop: Still remotely exploitable using buffer overflows + + + OSVDB + 1513 + + + FREEBSD + FreeBSD-SA-00:36 + + Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands. + + + + + + + + + + cpe:/a:pccs-linux:mysqldatabase_admin_tool:1.2.3 + cpe:/a:pccs-linux:mysqldatabase_admin_tool:1.2.4 + + CVE-2000-0707 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:41.483-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1557 + + + BUGTRAQ + 20000804 PCCS MySQL DB Admin Tool v1.2.3- Advisory + + + CONFIRM + http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&key=965951324 + + PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password. + + + + + + + + + cpe:/a:pragma_systems:telnetserver:2000 + + CVE-2000-0708 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:41.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1605 + + + CONFIRM + http://www.pragmasys.com/TelnetServer/ + + + NTBUGTRAQ + 20000824 Remote DoS Attack in Pragma TelnetServer 2000 (Remote Execute Daemon) Vulnerability + + Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port. + + + + + + + + + cpe:/a:microsoft:frontpage + + CVE-2000-0709 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:41.767-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1608 + + + BUGTRAQ + 20000823 Xato Advisory: FrontPage DOS Device DoS + + + CONFIRM + http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp + + The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name. + + + + + + + + + cpe:/a:microsoft:frontpage + + CVE-2000-0710 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:41.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1608 + + + BUGTRAQ + 20000823 Xato Advisory: FrontPage DOS Device DoS + + + CONFIRM + http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp + + The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3200 + cpe:/a:netscape:communicator:4.0 + cpe:/a:microsoft:virtual_machine:2000 + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.7 + cpe:/a:microsoft:virtual_machine:3300 + cpe:/a:netscape:communicator:4.6 + cpe:/a:microsoft:virtual_machine:3100 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.04 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.05 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.72 + cpe:/a:netscape:communicator:4.07 + + CVE-2000-0711 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:42.047-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2000-15 + + + BID + 1545 + + + BUGTRAQ + 20000816 JDK 1.1.x Listening Socket Vulnerability (was Re: BrownOrifice can break firewalls!) + + + BUGTRAQ + 20000805 Dangerous Java/Netscape Security Hole + + Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice. + + + + + + + + + cpe:/a:lids:lids:0.9.7 + + CVE-2000-0712 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:42.233-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1549 + + + CONFIRM + http://www.lids.org/changelog.html + + + MISC + http://www.egroups.com/message/lids/1038 + + + BUGTRAQ + 2000803 LIDS severe bug + + + OSVDB + 1495 + + Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option. + + + + + + + + + + + + + + + + cpe:/a:adobe:acrobat_reader:3.0 + cpe:/a:adobe:acrobat_reader:4.0 + cpe:/a:adobe:acrobat:4.0 + cpe:/a:adobe:acrobat_reader:4.0.5 + cpe:/a:adobe:acrobat:3.0 + cpe:/a:adobe:acrobat_business_tools:4.05 + cpe:/a:adobe:acrobat:4.0.5 + cpe:/a:adobe:acrobat_business_tools:4.0 + + CVE-2000-0713 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:42.373-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1509 + + + BUGTRAQ + 20000726 [SPSadvisory#39]Adobe Acrobat Series PDF File Buffer Overflow + + + CONFIRM + http://www.adobe.com/misc/pdfsecurity.html + + Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier. + + + + + + + + + cpe:/a:university_of_massachusetts:scheme:3.2.11 + + CVE-2000-0714 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:41.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1551 + + + REDHAT + RHSA-2000:047 + + umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files. + + + + + + + + + + + cpe:/a:kirk_bauer:diskcheck:3.1.1 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2000-0715 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:41.557-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 1552 + + + BUGTRAQ + 20000622 Re: rh 6.2 - gid compromises, etc [+ MORE!!!] + + + BUGTRAQ + 20000807 Re: Diskcheck 3.1.1 Symlink Vulnerability + + + BUGTRAQ + 20000805 Diskcheck 3.1.1 Symlink Vulnerability + + DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:alt-n:mdaemon:2.8 + + CVE-2000-0716 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:42.813-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1553 + + + NTBUGTRAQ + 20000809 Session hijacking in Alt-N's MDaemon 2.8 + + + XF + mdaemon-session-id-hijack + + WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijcak the session ID and read the user's email. + + + + + + + + + + + cpe:/a:goodtech:ftp_server_nt_2000:3.0 + cpe:/a:goodtech:ftp_server_95_98:3.0 + cpe:/a:goodtech:ftp_server_95_98:3.0.1 + + CVE-2000-0717 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:42.953-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000830 [EXPL] GoodTech's FTP Server vulnerable to a DoS (RNTO) + + + BID + 1619 + + + XF + ftp-goodtech-rnto-dos(5166) + + GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands. + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + + CVE-2000-0718 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.107-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1567 + + + BUGTRAQ + 20000812 MDKSA-2000:034 MandrakeUpdate update + + A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed. + + + + + + + + + cpe:/a:varicad:varicad:7.0 + + CVE-2000-0719 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.250-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000810 VariCAD 7.0 premission vulnerability + + VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program. + + + + + + + + + + + + cpe:/a:gwscripts:gwscripts_news_publisher:1.05b + cpe:/a:gwscripts:gwscripts_news_publisher:1.05a + cpe:/a:gwscripts:gwscripts_news_publisher:1.05 + cpe:/a:gwscripts:gwscripts_news_publisher:1.06 + + CVE-2000-0720 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.390-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000829 News Publisher CGI Vulnerability + + + BID + 1621 + + + XF + news-publisher-add-author(5169) + + news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program. + + + + + + + + + cpe:/a:multisoft:flagship:4.4 + + CVE-2000-0721 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.547-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000810 FlagShip v4.48.7449 premission vulnerability + + + BID + 1586 + + The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses. + + + + + + + + + + + + + cpe:/a:helix_code:gnome_updater:0.1 + cpe:/a:helix_code:gnome_updater:0.4 + cpe:/a:helix_code:gnome_updater:0.5 + cpe:/a:helix_code:gnome_updater:0.2 + cpe:/a:helix_code:gnome_updater:0.3 + + CVE-2000-0722 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.687-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1593 + + + BUGTRAQ + 20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer + + + BUGTRAQ + 20000820 Helix Code Security Advisory - Helix GNOME Update + + + BUGTRAQ + 20000819 Multiple Local Vulnerabilities in Helix Gnome Installer + + Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. + + + + + + + + + cpe:/a:helix_code:gnome_installer:0.2 + + CVE-2000-0723 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.843-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1596 + + + BUGTRAQ + 20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer + + + BUGTRAQ + 20000819 Multiple Local Vulnerabilities in Helix Gnome Installer + + Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. + + + + + + + + + cpe:/a:helix_code:go-gnome_pre-installer:1.5 + + CVE-2000-0724 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:43.983-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1622 + + + BUGTRAQ + 20000829 Helix Code Security Advisory - go-gnome pre-installer + + + BUGTRAQ + 20000829 More Helix Code installation problems (go-gnome) + + The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. + + + + + + + + + + + + cpe:/a:zope:zope:1.10.3 + cpe:/a:zope:zope:2.1.7 + cpe:/a:zope:zope:2.1.1 + cpe:/a:zope:zope:2.2_beta1 + + CVE-2000-0725 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:42.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1577 + + + BUGTRAQ + 20000821 Conectiva Linux Security Announcement - Zope + + + BUGTRAQ + 20000816 MDKSA-2000:035 Zope update + + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert + + + DEBIAN + 20000821 zope: unauthorized escalation of privilege (update) + + + REDHAT + RHSA-2000:052 + + Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. + + + + + + + + + cpe:/a:stalkerlab:mailers:1.1.2 + + CVE-2000-0726 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:44.267-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000829 Stalker's CGImail Gives Read Access to All Server Files + + + BID + 1623 + + + XF + mailers-cgimail-spoof(5165) + + CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable. + + + + + + + + + cpe:/a:xpdf:xpdf:0.90 + + CVE-2000-0727 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:44.407-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1624 + + + DEBIAN + 20000910 xpdf: local exploit + + + CALDERA + CSSA-2000-031.0 + + + BUGTRAQ + 20000829 MDKSA-2000:041 - xpdf update + + + REDHAT + RHSA-2000:060 + + + BUGTRAQ + 20000913 Conectiva Linux Security Announcement - xpdf + + xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters. + + + + + + + + + cpe:/a:xpdf:xpdf:0.90 + + CVE-2000-0728 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:42.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1624 + + + BUGTRAQ + 20000913 Conectiva Linux Security Announcement - xpdf + + + BUGTRAQ + 20000829 MDKSA-2000:041 - xpdf update + + + REDHAT + RHSA-2000:060 + + + CALDERA + CSSA-2000-031.0 + + xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:5.0:alpha + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0729 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:44.687-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1625 + + + FREEBSD + FreeBSD-SA-00:41 + + + XF + freebsd-elf-dos(5967) + + + OSVDB + 1534 + + FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0730 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:44.857-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1580 + + + HP + HPSBUX0008-118 + + + + + Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges. + + + + + + + + + cpe:/a:jeremy_arnold:worm_webserver:1.0 + + CVE-2000-0731 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000825 DST2K0023: Directory Traversal Possible & Denial of Service in Wo rm HTTP Server + + + BID + 1626 + + + XF + wormhttp-dir-traverse(5148) + + + OSVDB + 1535 + + Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:jeremy_arnold:worm_webserver:1.0 + + CVE-2000-0732 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.140-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000825 DST2K0023: Directory Traversal Possible & Denial of Service in Wo rm HTTP Server + + + BID + 1626 + + + XF + wormhttp-filename-dos + + Worm HTTP server allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:5.3::xfs + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.0.1::xfs + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.5.3f + cpe:/o:sgi:irix:6.1 + + CVE-2000-0733 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.280-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000814 [LSD] IRIX telnetd remote vulnerability + + + BID + 1572 + + + SGI + 20000801-02-P + + Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request. + + + + + + + + + + cpe:/a:spynet:capturenet:3.0.12 + cpe:/a:eeye_digital_security:iris:1.0.1 + + CVE-2000-0734 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1627 + + + BUGTRAQ + 20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12 + + eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. + + + + + + + + + cpe:/a:rimarts_inc.:becky_internet_mail:1.26.3 + + CVE-2000-0735 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.607-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000818 Becky! Internet Mail Buffer overflow + + + BID + 1588 + + + CONFIRM + http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt + + Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message. + + + + + + + + + cpe:/a:rimarts_inc.:becky_internet_mail:1.26.3 + + CVE-2000-0736 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.750-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000818 Becky! Internet Mail Buffer overflow + + + BID + 1588 + + + CONFIRM + http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt + + Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0737 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:45.907-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1535 + + + MS + MS00-053 + + The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. + + + + + + + + + cpe:/a:network_associates:webshield_smtp:4.5 + + CVE-2000-0738 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1589 + + + NTBUGTRAQ + 20000818 WebShield SMTP infinite loop DoS Attack + + + XF + webshield-smtp-dos + + WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail. + + + + + + + + + + + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix2 + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix1 + cpe:/a:network_associates:net_tools_pki_server:1.0 + + CVE-2000-0739 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1537 + + + CONFIRM + http://download.nai.com/products/licensed/pgp/hf3pki10.txt + + + BUGTRAQ + 20000802 NAI Net Tools PKI Server vulnerabilities + + + XF + nettools-pki-dir-traverse(5066) + + + OSVDB + 1489 + + Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server. + + + + + + + + + + + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix2 + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix1 + cpe:/a:network_associates:net_tools_pki_server:1.0 + + CVE-2000-0740 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.327-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1536 + + + CONFIRM + http://download.nai.com/products/licensed/pgp/hf3pki10.txt + + + BUGTRAQ + 20000802 NAI Net Tools PKI Server vulnerabilities + + + XF + nai-nettools-strong-bo(5026) + + + OSVDB + 1488 + + Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port. + + + + + + + + + + + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix2 + cpe:/a:network_associates:net_tools_pki_server:1.0hotfix1 + cpe:/a:network_associates:net_tools_pki_server:1.0 + + CVE-2000-0741 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.483-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1538 + + + CONFIRM + http://download.nai.com/products/licensed/pgp/hf3pki10.txt + + + BUGTRAQ + 20000802 NAI Net Tools PKI Server vulnerabilities + + + OSVDB + 1490 + + Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + + CVE-2000-0742 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1544 + + + MS + MS00-054 + + + BUGTRAQ + 20000602 ipx storm + + + XF + win-ipx-ping-packet(5079) + + The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability. + + + + + + + + + + cpe:/a:university_of_minnesota:gopherd:2.3.1 + cpe:/a:university_of_minnesota:gopherd:2.3 + + CVE-2000-0743 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:46.763-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1569 + + + BUGTRAQ + 20000810 Remote vulnerability in Gopherd 2.x + + Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value. + + + + + + + + + + cpe:/a:university_of_minnesota:gopherd:2.3.1 + cpe:/a:university_of_minnesota:gopherd:2.3 + + CVE-2000-0744 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:45.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-2000-0743. + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:1.0 + cpe:/a:francisco_burzi:php-nuke:2.5 + + CVE-2000-0745 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.060-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1592 + + + BUGTRAQ + 20000821 Vuln. in all sites using PHP-Nuke, versions less than 3 + + + OSVDB + 1521 + + admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:frontpage + + CVE-2000-0746 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.203-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1595 + + + BID + 1594 + + + MS + MS00-060 + + + BUGTRAQ + 20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll + + Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. + + + + + + + + + + + cpe:/o:conectiva:linux:4.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:5.0 + + CVE-2000-0747 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.357-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP + + + XF + openldap-logrotate-script-dos(5036) + + The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it. + + + + + + + + + + + + + cpe:/a:openldap:openldap:1.2.9 + cpe:/a:openldap:openldap:1.2.8 + cpe:/a:openldap:openldap:1.2.7 + cpe:/a:openldap:openldap:1.2.10 + cpe:/a:openldap:openldap:1.2.11 + + CVE-2000-0748 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.500-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1511 + + + BUGTRAQ + 20000726 Group-writable executable in OpenLDAP + + OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse. + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0749 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.657-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1628 + + + FREEBSD + FreeBSD-SA-00:42 + + + XF + freebsd-linux-module-bo(5968) + + + OSVDB + 1536 + + Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system. + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:redhat:linux:6.2 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:redhat:linux:6.1 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:redhat:linux:6.0 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-0750 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:45.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1558 + + + FREEBSD + FreeBSD-SA-00:40 + + + BUGTRAQ + 20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow + + + REDHAT + RHSA-2000:050 + + + OPENBSD + 20000705 Mopd contained a buffer overflow. + + + MISC + http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&r2=1.8&f=h + + Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name. + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:redhat:linux:6.2 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:redhat:linux:6.1 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:redhat:linux:6.0 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-0751 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:47.967-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1559 + + + FREEBSD + FreeBSD-SA-00:40 + + + BUGTRAQ + 20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow + + + REDHAT + RHSA-2000:050 + + + OPENBSD + 20000705 Mopd contained a buffer overflow. + + + MISC + http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&r2=1.8&f=h + + mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:5.0:alpha + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0752 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:48.140-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1629 + + + FREEBSD + FreeBSD-SA-00:43 + + Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments. + + + + + + + + + + + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook:2000 + + CVE-2000-0753 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:46.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1631 + + + XF + outlook-reveal-path(5508) + + + BUGTRAQ + 20000824 Outlook winmail.dat + + + BUGTRAQ + 20010802 Outlook 2000 Rich Text information disclosure + + The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.1 + + CVE-2000-0754 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:48.437-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX0008-119 + + + BID + 1581 + + Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords. + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.1 + + CVE-2000-0755 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:48.577-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBUX0008-118 + + + BID + 1581 + + Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges. + + + + + + + + + + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook:2000 + + CVE-2000-0756 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:48.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1633 + + + BUGTRAQ + 20000831 vCard DoS on Outlook 2000 + + Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. + + + + + + + + + cpe:/a:aptis_software:totalbill:3.0 + + CVE-2000-0757 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:48.857-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1555 + + + BUGTRAQ + 20000808 Exploit for Totalbill... + + The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. + + + + + + + + + + cpe:/a:lyris:list_manager:4.0 + cpe:/a:lyris:list_manager:3.0 + + CVE-2000-0758 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.000-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1584 + + + BUGTRAQ + 20000811 Lyris List Manager Administration Hole + + + CONFIRM + http://www.lyris.com/lm/lm_updates.html + + The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field. + + + + + + + + + cpe:/a:apache:tomcat:3.1 + + CVE-2000-0759 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.157-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000719 [LoWNOISE] Tomcat 3.1 Path Revealing Problem. + + + BID + 1531 + + + XF + tomcat-error-path-reveal(4967) + + Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. + + + + + + + + + + cpe:/a:apache:tomcat:3.1 + cpe:/a:apache:tomcat:3.0 + + CVE-2000-0760 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.297-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000719 [LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0) + + + BID + 1532 + + The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. + + + + + + + + + + + cpe:/a:ibm:os2_ftp_server:4.0 + cpe:/a:ibm:os2_ftp_server:4.3 + cpe:/a:ibm:os2_ftp_server:4.2 + + CVE-2000-0761 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.437-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1582 + + + BUGTRAQ + 20000815 OS/2 Warp 4.5 FTP Server DoS + + + CONFIRM + ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README + + OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username. + + + + + + + + + + + + cpe:/a:ca:etrust_access_control:5.0 + cpe:/a:ca:etrust_access_control:4.1 + cpe:/a:ca:etrust_access_control:5.0:sp1 + cpe:/a:ca:etrust_access_control:4.1:sp1 + + CVE-2000-0762 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.577-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000811 eTrust Access Control - Root compromise for default install + + + BID + 1583 + + + CONFIRM + http://support.ca.com/techbases/eTrust/etrust_access_control-response.html + + + XF + etrust-access-control-default + + + OSVDB + 1517 + + The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges. + + + + + + + + + + cpe:/a:david_bagley:xlock:4.16 + cpe:/a:david_bagley:xlock:4.16.1 + + CVE-2000-0763 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.733-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000816 xlock vulnerability + + + BID + 1585 + + + DEBIAN + 20000816 xlockmore: possible shadow file compromise + + + FREEBSD + FreeBSD-SA-00:44.xlockmore + + + BUGTRAQ + 20000823 MDKSA-2000:038 - xlockmore update + + + BUGTRAQ + 20000817 Conectiva Linux Security Announcement - xlockmore + + xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option. + + + + + + + + + cpe:/h:intel:express_8100 + + CVE-2000-0764 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:49.873-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1609 + + + BUGTRAQ + 20000828 Intel Express Switch 500 series DoS + + + XF + intel-express-switch-dos + + Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet. + + + + + + + + + + + cpe:/a:microsoft:powerpoint:2000 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:excel:2000 + + CVE-2000-0765 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:50.013-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1561 + + + MS + MS00-056 + + Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. + + + + + + + + + cpe:/a:vqsoft:vqserver:1.4.49 + + CVE-2000-0766 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:50.170-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1610 + + + BUGTRAQ + 20000819 D.o.S Vulnerability in vqServer + + + XF + vqserver-get-dos + + Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0767 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:50.310-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1564 + + + MS + MS00-055 + + The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0::windows + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0::windows_95 + cpe:/a:microsoft:ie:5.0::windows_98 + cpe:/a:microsoft:ie:5.0::windows_2000 + cpe:/a:microsoft:ie:4.0::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0::windows_nt + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0768 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:50.453-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1564 + + + MS + MS00-055 + + A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + cpe:/a:oreilly:website_pro:2.3.7 + + CVE-2000-0769 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:48.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1611 + + + BUGTRAQ + 20000824 WebServer Pro 2.3.7 Vulnerability + + O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0770 + 2000-10-20T00:00:00.000-04:00 + 2011-03-07T21:03:49.563-05:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1565 + + + MS + MS00-057 + + IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0771 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:50.907-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1613 + + + MS + MS00-062 + + Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. + + + + + + + + + + + cpe:/a:tumbleweed:messaging_management_system:4.3 + cpe:/a:tumbleweed:messaging_management_system:4.6 + cpe:/a:tumbleweed:messaging_management_system:4.5 + + CVE-2000-0772 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.047-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1562 + + + XF + tumbleweed-mms-blank-password + + + CONFIRM + http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm + + + BUGTRAQ + 20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vulnerability + + The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. + + + + + + + + + cpe:/a:bajie:java_http_server:1.0 + + CVE-2000-0773 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.233-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bajie-view-arbitrary-files(5021) + + + BID + 1522 + + + BUGTRAQ + 20000731 Two security flaws in Bajie Webserver + + Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. + + + + + + + + + cpe:/a:bajie:java_http_server:1.0 + + CVE-2000-0774 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.373-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1521 + + + BUGTRAQ + 20000731 Two security flaws in Bajie Webserver + + The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. + + + + + + + + + cpe:/a:robtex:viking_server:1.0.6_build355 + + CVE-2000-0775 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.513-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1614 + + + CONFIRM + http://www.robtex.com/viking/bugs.htm + + + BUGTRAQ + 20000828 [NT] Viking security vulnerabilities enable remote code execution (long URL, date parsing) + + Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers. + + + + + + + + + cpe:/a:mediahouse_software:statistics_server_livestats:5.02 + + CVE-2000-0776 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.657-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1568 + + + BUGTRAQ + 20000810 [DeepZone Advisory] Statistics Server 5.02x stack overflow (Win2k remote exploit) + + + XF + mediahouse-stats-livestats-bo(5113) + + Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. + + + + + + + + + + cpe:/a:microsoft:money:2000 + cpe:/a:microsoft:money:2001 + + CVE-2000-0777 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:51.797-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-061 + + + BID + 1615 + + The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2000-0778 + 2000-10-20T00:00:00.000-04:00 + 2013-08-03T00:14:09.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BUGTRAQ + 20000815 Translate:f summary, history and thoughts + + + BID + 1578 + + + NTBUGTRAQ + 20000816 Translate: f + + + MS + MS00-058 + + + + + IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0779 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:49.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1534 + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr + + + OSVDB + 1487 + + Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests. + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:6.4 + cpe:/a:ipswitch:imail:5.0 + cpe:/a:ipswitch:imail:6.3 + cpe:/a:ipswitch:imail:6.0 + + CVE-2000-0780 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:52.233-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1617 + + + CONFIRM + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20000830 Vulnerability Report On IPSWITCH's IMail + + The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:ca:arcserve_backup:6.63_linux + + CVE-2000-0781 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:50.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + arcserveit-clientagent-temp-file(5023) + + + BID + 1519 + + + BUGTRAQ + 20000728 Client Agent 6.62 for Unix Vulnerability + + uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved. + + + + + + + + + cpe:/a:netwin:netauth:4.2 + + CVE-2000-0782 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:52.530-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000817 Netauth: Web Based Email Management System + + + BID + 1587 + + + CONFIRM + http://netwinsite.com/netauth/updates.htm + + + XF + netwin-netauth-dir-traverse(5090) + + netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/h:watchguard:firebox:ii + + CVE-2000-0783 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:52.670-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1573 + + + BUGTRAQ + 20000815 Watchguard Firebox Authentication DoS + + + XF + firebox-url-dos + + Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100. + + + + + + + + + + + + cpe:/h:rapidstream:rapidstream:4000 + cpe:/h:rapidstream:rapidstream:2000 + cpe:/h:rapidstream:rapidstream:6000 + cpe:/h:rapidstream:rapidstream:8000 + + CVE-2000-0784 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:52.810-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1574 + + + BUGTRAQ + 20000816 Remote Root Compromise On All RapidStream VPN Appliances + + sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh. + + + + + + + + + cpe:/a:wircsrv:irc_server:5.0.7s + + CVE-2000-0785 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:50.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000713 More wIRCSrv stupidity + + WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file. + + + + + + + + + cpe:/a:gnu:userv:1.0.0 + + CVE-2000-0786 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.107-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1516 + + + DEBIAN + 20000727 userv: local exploit + + + BUGTRAQ + 20000726 userv security boundary tool 1.0.1 (SECURITY FIX) + + + CONFIRM + http://marc.theaimsgroup.com/?l=bugtraq&m=96473640717095&w=2 + + GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions. + + + + + + + + + + + + + + + + + + + cpe:/a:xchat:xchat:1.4.1 + cpe:/a:xchat:xchat:1.3.12 + cpe:/a:xchat:xchat:1.4.2 + cpe:/a:xchat:xchat:1.3.11 + cpe:/a:xchat:xchat:1.3.13 + cpe:/a:xchat:xchat:1.4 + cpe:/a:xchat:xchat:1.5.6 + cpe:/a:xchat:xchat:1.2.1 + cpe:/a:xchat:xchat:1.3.10 + cpe:/a:xchat:xchat:1.5.xdev + cpe:/a:xchat:xchat:1.3.9 + + CVE-2000-0787 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:50.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1601 + + + BUGTRAQ + 20000825 Conectiva Linux Security Announcement - xchat + + + BUGTRAQ + 20000824 MDKSA-2000:039 - xchat update + + + BUGTRAQ + 20000817 XChat URL handler vulnerabilty + + + REDHAT + RHSA-2000:055 + + IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser. + + + + + + + + + + cpe:/a:microsoft:access:2000 + cpe:/a:microsoft:word:2000 + + CVE-2000-0788 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000807 MS Word and MS Access vulnerability - executing arbitrary programs, may be exploited by IE/Outlook + + + BID + 1566 + + + XF + word-mail-merge(5322) + + + MS + MS00-071 + + The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands. + + + + + + + + + + cpe:/a:bardon_data_systems:winu:4.x + cpe:/a:bardon_data_systems:winu:5.0 + + CVE-2000-0789 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.560-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000816 WinU 4/5 weak password vulnerability + + WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000 + + CVE-2000-0790 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.703-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000. + + + BID + 1571 + + + XF + ie-folder-remote-exe(5097) + + The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder. + + + + + + + + + cpe:/o:trustix:secure_linux:1.1 + + CVE-2000-0791 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.843-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000815 Trustix security advisory - apache-ssl + + + BID + 1575 + + Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse. + + + + + + + + + cpe:/a:alan_cox:gnome-lokkit:0.1 + + CVE-2000-0792 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:53.983-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000819 Security update for Gnome-Lokkit + + + BID + 1590 + + + OSVDB + 1520 + + Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available. + + + + + + + + + + cpe:/a:symantec:norton_antivirus:5.0 + cpe:/a:novell:client:3.1 + + CVE-2000-0793 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.140-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1533 + + + BUGTRAQ + 20000728 Norton Antivirus Protection Disabled under Novell Netware + + Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-2000-0794 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.280-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1527 + + + XF + irix-libgl-bo(5063) + + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + OSVDB + 8568 + + Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview. + + + + + + + + + + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-2000-0795 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.420-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + BID + 1529 + + + OSVDB + 1485 + + Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option. + + + + + + + + + + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-2000-0796 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.560-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + BID + 1528 + + + XF + irix-dmplay-bo(5064) + + + OSVDB + 1484 + + Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option. + + + + + + + + + + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-2000-0797 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.717-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + irix-grosview-bo(5062) + + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + BID + 1526 + + + OSVDB + 3815 + + + SGI + 20040104-01-P + + Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option. + + + + + + + + + + + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + + CVE-2000-0798 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.857-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1540 + + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + OSVDB + 8569 + + The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files. + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.3f + + CVE-2000-0799 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:54.997-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000802 [LSD] some unpublished LSD exploit codes + + + BID + 1530 + + + XF + irix-inpview-symlink(5065) + + + SGI + 20001101-01-I + + inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file. + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.1:alpha + cpe:/o:suse:suse_linux:6.4:alpha + + CVE-2000-0800 + 2000-10-20T00:00:00.000-04:00 + 2008-09-10T15:05:52.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SUSE + 20000810 Security Hole in knfsd, all versions + + String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0801 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:55.327-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1520 + + + BUGTRAQ + 20000727 [ Hackerslab bug_paper ] HP-UX bdf -t option buffer overflow vul. + + Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option. + + + + + + + + + cpe:/a:pgp:personal_privacy:6.5.3 + + CVE-2000-0802 + 2000-10-20T00:00:00.000-04:00 + 2008-09-05T16:21:55.467-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000722 More bad censorware + + The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR. + + + + + + + + + cpe:/a:gnu:groff + + CVE-2000-0803 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:21:55.623-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + gnu-groff-utilities(5280) + + GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0804 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection + + + XF + fw1-remote-bypass + + + OSVDB + 4419 + + Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass." + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0805 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of + + + XF + fw1-client-spoof + + + OSVDB + 4415 + + Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets." + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0806 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications + + + XF + fw1-fwa1-auth-replay + + + OSVDB + 4413 + + The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass." + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0807 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication + + + XF + fw1-opsec-auth-spoof + + + OSVDB + 4420 + + The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability." + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0808 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password + + + XF + fw1-localhost-auth + + + OSVDB + 4421 + + The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication." + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0809 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:52.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer + + + XF + fw1-getkey-bo + + + OSVDB + 4422 + + Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service. + + + + + + + + + + + + + cpe:/a:cgi_script_center:auction_weaver:1.04 + cpe:/a:cgi_script_center:auction_weaver:1.01 + cpe:/a:cgi_script_center:auction_weaver:1.03 + cpe:/a:cgi_script_center:auction_weaver:1.02 + cpe:/a:cgi_script_center:auction_weaver:1.0 + + CVE-2000-0810 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:05:53.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + auction-weaver-delete-files + + + BID + 1782 + + + OSVDB + 1600 + + Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack. + + + + + + + + + + + + + cpe:/a:cgi_script_center:auction_weaver:1.04 + cpe:/a:cgi_script_center:auction_weaver:1.01 + cpe:/a:cgi_script_center:auction_weaver:1.03 + cpe:/a:cgi_script_center:auction_weaver:1.02 + cpe:/a:cgi_script_center:auction_weaver:1.0 + + CVE-2000-0811 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:05:53.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + auction-weaver-username-bidfile + + + BID + 1783 + + + OSVDB + 4053 + + Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields. + + + + + + + + + + + + cpe:/a:sun:java_system_web_server:1.1.2 + cpe:/a:sun:java_system_web_server:1.1.3 + cpe:/a:sun:java_system_web_server:2.0 + cpe:/a:sun:java_system_web_server:1.1_beta + + CVE-2000-0812 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:56.937-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.securityfocus.com/templates/advisory.html?id=2542 + + + SUN + 00197 + + + XF + sunjava-webadmin-bbs + + + BID + 1600 + + The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-0813 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:53.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection + + + XF + fw1-ftp-redirect + + + OSVDB + 4434 + + Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass." + + + + + + + + + + + + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0 + + CVE-2000-0816 + 2000-10-06T00:00:00.000-04:00 + 2008-09-10T15:05:54.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20001006 Insecure call of external programs in Red Hat Linux tmpwatch + + + XF + linux-tmpwatch-fuser(5320) + + + BID + 1785 + + + REDHAT + RHSA-2000:080 + + + MANDRAKE + MDKSA-2000:056 + + Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters. + + + + + + + + + cpe:/a:microsoft:network_monitor + + CVE-2000-0817 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:21:57.390-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20001101 Buffer Overflow in Microsoft Windows NT 4.0 and Windows 2000 Network Monitor + + + MS + MS00-083 + + Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability. + + + + + + + + + + + cpe:/a:oracle:listener:8.0.6 + cpe:/a:oracle:listener:8.1.6 + cpe:/a:oracle:listener:7.3.4 + + CVE-2000-0818 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:21:57.530-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf + + + ISS + 20001025 Vulnerability in the Oracle Listener Program + + + XF + oracle-listener-connect-statements(5380) + + The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands. + + + + + + + + + cpe:/a:gnu:glibc:2.1.1 + + CVE-2000-0824 + 2000-11-14T00:00:00.000-05:00 + 2011-03-07T21:03:54.187-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 648 + + + BUGTRAQ + 20000831 glibc unsetenv bug + + + XF + glibc-ld-unsetenv + + + TURBO + TLSA2000020-1 + + + BID + 1639 + + + REDHAT + RHSA-2000:057 + + + SUSE + 20000924 glibc locale security problem + + + MANDRAKE + MDKSA-2000:045 + + + MANDRAKE + MDKSA-2000:040 + + + DEBIAN + 20000902 glibc: local root exploit + + + CALDERA + CSSA-2000-028.0 + + + BUGTRAQ + 19990917 A few bugs... + + + BUGTRAQ + 20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched + + + BUGTRAQ + 20000905 Conectiva Linux Security Announcement - glibc + + + BUGTRAQ + 20000902 Conectiva Linux Security Announcement - glibc + + The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH. + + + + + + + + + cpe:/a:ipswitch:imail:6.00 + + CVE-2000-0825 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:57.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + WIN2KSEC + 20000817 Imail Web Service Remote DoS Attack v.2 + + + XF + ipswitch-imail-remote-dos(5475) + + + BID + 2011 + + + NTBUGTRAQ + 20000817 Imail Web Service Remote DoS Attack v.2 + + + BUGTRAQ + 20000817 Imail Web Service Remote DoS Attack v.2 + + Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash. + + + + + + + + + cpe:/a:mobius:documentdirect_for_the_internet:1.2 + + CVE-2000-0826 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:57.967-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + documentdirect-get-bo + + + BID + 1657 + + + ATSTAKE + A090800-1 + + Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:mobius:documentdirect_for_the_internet:1.2 + + CVE-2000-0827 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.107-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + documentdirect-username-bo + + + BID + 1657 + + + ATSTAKE + A090800-1 + + Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username. + + + + + + + + + cpe:/a:mobius:documentdirect_for_the_internet:1.2 + + CVE-2000-0828 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.247-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + documentdirect-user-agent-bo + + + BID + 1657 + + + ATSTAKE + A090800-1 + + Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter. + + + + + + + + + + + cpe:/a:redhat:tmpwatch:2.5.1 + cpe:/a:redhat:tmpwatch:2.2 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-0829 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.390-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-tmpwatch-fork-dos + + + BID + 1664 + + + BUGTRAQ + 20000909 tmpwatch: local DoS : fork()bomb as root + + + REDHAT + RHSA-2000:080 + + The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/. + + + + + + + + + cpe:/a:microsoft:webtv + + CVE-2000-0830 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1671 + + + XF + webtv-udp-dos + + + BUGTRAQ + 20000913 trivial DoS in webTV + + + MS + MS00-074 + + annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705. + + + + + + + + + cpe:/a:fastream:ftp%2b%2b_server:2.0 + + CVE-2000-0831 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.687-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + WIN2KSEC + 20000912 DST2K0027: DoS in Faststream FTP++ 2.0 + + Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username. + + + + + + + + + cpe:/a:oscar_nierstrasz:htgrep:3.0 + + CVE-2000-0832 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + htgrep-cgi-view-files(5476) + + + BUGTRAQ + 20000817 Htgrep CGI Arbitrary File Viewing Vulnerability + + Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter. + + + + + + + + + + cpe:/a:jack_de_winter:winsmtp:1.6f + cpe:/a:jack_de_winter:winsmtp:2.x + + CVE-2000-0833 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:58.967-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + winsmtp-helo-bo(5255) + + + BID + 1680 + + + BUGTRAQ + 2000911 WinSMTPD remote exploit/DoS problem + + Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0834 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.123-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1683 + + + MS + MS00-067 + + + XF + win2k-telnet-ntlm-authentication + + + ATSTAKE + A091400-1 + + The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability. + + + + + + + + + + cpe:/a:sambar:sambar_server:4.3 + cpe:/a:sambar:sambar_server:4.4:beta3 + + CVE-2000-0835 + 2000-11-14T00:00:00.000-05:00 + 2010-01-16T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1684 + + + BUGTRAQ + 20000915 Sambar Server search CGI vulnerability + + search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. + + + + + + + + + cpe:/a:broadgun_software:camshot_webcam:2.6trial_version + + CVE-2000-0836 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.403-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + camshot-password-bo + + + BID + 1685 + + + BUGTRAQ + 20000915 [NEWS] Vulnerability in CamShot server (Authorization) + + Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header. + + + + + + + + + cpe:/a:deerfield:ftp_serv-u:2.5e + + CVE-2000-0837 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + servu-null-character-dos + + + BUGTRAQ + 20000804 FTP Serv-U 2.5e vulnerability. + + + BID + 1543 + + FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes. + + + + + + + + + cpe:/a:fastream:fur_http_server:1.0b + + CVE-2000-0838 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.687-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fur-get-dos(5237) + + + WIN2KSEC + 20000914 DST2K0028: DoS in FUR HTTP Server v1.0b + + Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request. + + + + + + + + + cpe:/a:ipswitch:wincom_lpd:1.00.90 + + CVE-2000-0839 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wincom-lpd-dos(5258) + + + BID + 1701 + + + BUGTRAQ + 20000919 VIGILANTE-2000013: WinCOM LPD DoS + + WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515). + + + + + + + + + cpe:/a:davide_libenzi:xmail:0.58 + + CVE-2000-0840 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:21:59.983-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER) + + + XF + xmail-long-user-bo + + + BID + 1652 + + Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command. + + + + + + + + + cpe:/a:davide_libenzi:xmail:0.58 + + CVE-2000-0841 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:05:57.273-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER) + + + XF + xmail-long-apop-bo + + + BID + 1652 + + Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command. + + + + + + + + + cpe:/o:sco:unixware:7.0 + + CVE-2000-0842 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:00.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1663 + + + BUGTRAQ + 20000911 SCO scohelhttp documentation webserver exposes local files + + The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + cpe:/a:dave_airlie:pam_smb:1.1.5 + cpe:/a:luke_kenneth_casson_leighton:pam_ntdom:0.23 + + CVE-2000-0843 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:00.420-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1666 + + + DEBIAN + 20000911 libpam-smb: remote root exploit + + + SUSE + 20000913 pam_smb remotely exploitable buffer overflow + + + MANDRAKE + MDKSA-2000:047 + + + BUGTRAQ + 20000911 Conectiva Linux Security Announcement - pam_smb + + + BUGTRAQ + 20000910 (SRADV00002) Remote root compromise through pam_smb and pam_ntdom + + Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:sgi:irix:6.5 + cpe:/o:ibm:aix:4.0 + cpe:/o:ibm:aix:4.1 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:ibm:aix:3.2 + cpe:/a:immunix:immunix:6.2 + cpe:/o:sun:solaris:8.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:turbolinux:turbolinux:6.0.4 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:sun:solaris:7.0 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:redhat:linux:6.2 + cpe:/o:conectiva:linux:4.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:redhat:linux:6.1 + cpe:/o:conectiva:linux:4.1 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:conectiva:linux:4.0 + cpe:/o:redhat:linux:6.0 + cpe:/o:turbolinux:turbolinux:6.0.1 + cpe:/o:turbolinux:turbolinux:6.0.2 + cpe:/o:turbolinux:turbolinux:6.0.3 + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/o:ibm:aix:3.2.4 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:slackware:slackware_linux:7.1 + cpe:/o:slackware:slackware_linux:7.0 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:ibm:aix:3.2.5 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:caldera:openlinux + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.0 + cpe:/o:conectiva:linux:4.0es + cpe:/o:sun:solaris:2.1 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sun:solaris:2.2 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:trustix:secure_linux:1.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:debian:debian_linux:2.3 + cpe:/o:ibm:aix:4.1.5 + cpe:/o:turbolinux:turbolinux:6.0 + cpe:/o:debian:debian_linux:2.0 + cpe:/o:sgi:irix:6.5.3m + cpe:/o:debian:debian_linux:2.1 + cpe:/a:caldera:openlinux_ebuilder:3.0 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:ibm:aix:4.2.1 + cpe:/o:ibm:aix:4.1.2 + cpe:/o:ibm:aix:4.1.1 + cpe:/o:ibm:aix:4.1.4 + cpe:/o:sgi:irix:6.5.3f + cpe:/o:ibm:aix:4.1.3 + + CVE-2000-0844 + 2000-11-14T00:00:00.000-05:00 + 2009-01-20T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 1634 + + + BUGTRAQ + 20000904 UNIX locale format string vulnerability + + + XF + unix-locale-format-string(5176) + + + REDHAT + RHSA-2000:057 + + + SUSE + 20000906 glibc locale security problem + + + DEBIAN + 20000902 glibc: local root exploit + + + CALDERA + CSSA-2000-030.0 + + + COMPAQ + SSRT0689U + + + AIXAPAR + IY13753 + + + BUGTRAQ + 20000902 Conectiva Linux Security Announcement - glibc + + + SGI + 20000901-01-P + + Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. + + + + + + + + + cpe:/o:digital:unix:4.0f + + CVE-2000-0845 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:00.873-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000918 [ENIGMA] Digital UNIX/Tru64 UNIX remote kdebug Vulnerability + + kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. + + + + + + + + + cpe:/a:ashley_montanaro:darxite:0.4 + + CVE-2000-0846 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.013-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1598 + + + BUGTRAQ + 20000821 Darxite daemon remote exploit/DoS problem + + + XF + darxite-login-bo + + Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password. + + + + + + + + + + + + cpe:/a:university_of_washington:imap:4.7c + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.20 + cpe:/a:university_of_washington:imap:4.7b + + CVE-2000-0847 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.153-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1646 + + + BUGTRAQ + 20000901 More about UW c-client library + + + XF + c-client-dos(5223) + + + BID + 1687 + + + FREEBSD + FreeBSD-SA-00:47.pine + + + BUGTRAQ + 20000901 UW c-client library vulnerability + + Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header. + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.0.2 + + CVE-2000-0848 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.327-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1691 + + + BUGTRAQ + 20000915 WebSphere application server plugin issue & vendor fix + + + MISC + http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security + + + XF + websphere-header-dos + + Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. + + + + + + + + + + cpe:/a:microsoft:windows_media_services:4.1 + cpe:/a:microsoft:windows_media_services:4.0 + + CVE-2000-0849 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.483-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1655 + + + MS + MS00-064 + + + XF + unicast-service-dos(5193) + + Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability. + + + + + + + + + + cpe:/a:netegrity:siteminder:4.0 + cpe:/a:netegrity:siteminder:3.6 + + CVE-2000-0850 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1681 + + + XF + siteminder-bypass-authentication + + + ATSTAKE + A091100-1 + + Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0851 + 2000-11-14T00:00:00.000-05:00 + 2013-07-06T00:11:34.357-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1651 + + + MS + MS00-065 + + + ATSTAKE + A090700-1 + + + XF + w2k-still-image-service + + Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:5.0:alpha + + CVE-2000-0852 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:01.920-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1686 + + + XF + freebsd-eject-port + + + OSVDB + 1559 + + + FREEBSD + FreeBSD-SA-00:49 + + Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges. + + + + + + + + + cpe:/a:yabb:yabb:2000-09-01 + + CVE-2000-0853 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.060-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1668 + + + XF + yabb-file-access + + + BUGTRAQ + 20000909 YaBB 1.9.2000 Vulnerabilitie + + YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:microsoft:office:2000 + + CVE-2000-0854 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.200-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1699 + + + WIN2KSEC + 20000918 Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases + + + XF + office-dll-execution(5263) + + + NTBUGTRAQ + 20000921 Mitigators for possible exploit of Eudora via Guninski #21,2000 + + + BUGTRAQ + 20000922 Eudora + riched20.dll affects WinZip v8.0 as well + + When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document. + + + + + + + + + cpe:/a:xs4all_data:xs4all_data_sunftp:1.0_build_9 + + CVE-2000-0855 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.343-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1637 + + + BUGTRAQ + 20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open) + + SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline. + + + + + + + + + cpe:/a:xs4all_data:xs4all_data_sunftp:1.0_build_9 + + CVE-2000-0856 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.497-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1638 + + + BUGTRAQ + 20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open) + + Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:sebastian_kienzl:muh:2.05d + + CVE-2000-0857 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.640-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1665 + + + XF + muh-log-dos + + + BUGTRAQ + 20000909 Re: format string bug in muh + + + BUGTRAQ + 20000909 format string bug in muh + + The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname. + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0858 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1642 + + + BUGTRAQ + 20000906 VIGILANTE-2000009: "Invalid URL" DoS + + + MS + MS00-063 + + + XF + iis-invald-url-dos + + Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability. + + + + + + + + + + cpe:/a:gordano:ntmail:6.0 + cpe:/a:gordano:ntmail:5.0 + + CVE-2000-0859 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:02.920-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1640 + + + BUGTRAQ + 20000904 VIGILANTE-2000008: NTMail Configuration Service DoS + + + XF + ntmail-incomplete-http-requests + + The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/a:php:php:2.0 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:3.0 + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:2.0b10 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:1.0 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2000-0860 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:03.077-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1649 + + + BUGTRAQ + 20000903 (SRADV00001) Arbitrary file disclosure through PHP file upload + + + XF + php-file-upload + + + CONFIRM + http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u + + + MANDRAKE + MDKSA-2000:048 + + + BUGTRAQ + 20000904 Re: [PHP-DEV] RE: (SRADV00001) Arbitrary file disclosure through PHP file upload + + The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. + + + + + + + + + cpe:/a:gnu:mailman:1.1 + + CVE-2000-0861 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:03.247-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1667 + + + FREEBSD + FreeBSD-SA-00:51 + + + BUGTRAQ + 20000907 Mailman 1.1 + external archiver vulnerability + + + XF + mailman-execute-external-commands(5493) + + Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. + + + + + + + + + cpe:/a:allaire:spectra:1.0.1 + + CVE-2000-0862 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:06:01.570-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB00-23 + + + XF + allaire-spectra-admin-access + + Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information. + + + + + + + + + + + + + + + + + + cpe:/a:listmanager:linux:2.97 + cpe:/a:listmanager:linux:2.96 + cpe:/a:listmanager:linux:2.99 + cpe:/a:listmanager:linux:2.98 + cpe:/a:listmanager:linux:2.105.1 + cpe:/a:listmanager:linux:2.104 + cpe:/a:listmanager:linux:2.102 + cpe:/a:listmanager:linux:2.103 + cpe:/a:listmanager:linux:2.100 + cpe:/a:listmanager:linux:2.101 + + CVE-2000-0863 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:03.547-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-00:50 + + + XF + listmanager-port-bo + + Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges. + + + + + + + + + cpe:/a:gnome:esound:0.2.19 + + CVE-2000-0864 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 1659 + + + REDHAT + RHSA-2000:077 + + + SUSE + 20001012 esound daemon race condition + + + DEBIAN + 20001008 esound: race condition + + + FREEBSD + FreeBSD-SA-00:45 + + + BUGTRAQ + 20001006 Immunix OS Security Update for esound + + + BUGTRAQ + 20000911 Patch for esound-0.2.19 + + Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack. + + + + + + + + + cpe:/a:tridia:doublevision:3.07.00 + + CVE-2000-0865 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:03.843-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1697 + + + BUGTRAQ + 20000916 Advisory: Tridia DoubleVision / SCO UnixWare + + + XF + doublevision-dvtermtype-bo + + Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument. + + + + + + + + + cpe:/a:borland_software:interbase_superserver:6.0 + + CVE-2000-0866 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:03.983-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + interbase-query-dos + + + BID + 1654 + + + BUGTRAQ + 20000907 SEGFAULTING Interbase 6 SS Linux + + Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes. + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:slackware:slackware_linux + cpe:/o:debian:debian_linux:2.1::slink + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.2::potato + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:redhat:linux:5.2 + + CVE-2000-0867 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T15:06:01.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + klogd-format-string + + + BUGTRAQ + 20000917 klogd format bug + + + TURBO + TLSA2000022-2 + + + REDHAT + RHSA-2000:061 + + + OSVDB + 5824 + + + SUSE + 20000920 syslogd + klogd format string parsing error + + + BUGTRAQ + 20000918 Conectiva Linux Security Announcement - sysklogd + + + MANDRAKE + MDKSA-2000:050 + + + CALDERA + CSSA-2000-032.0 + + Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/a:apache:http_server:1.3.12 + + CVE-2000-0868 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:04.297-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1658 + + + ATSTAKE + A090700-2 + + + SUSE + 20000907 + + + XF + suse-apache-cgi-source-code + + The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:6.3::ppc + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.3:alpha + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.1:alpha + cpe:/o:suse:suse_linux:6.4:alpha + cpe:/o:suse:suse_linux:6.0 + cpe:/a:apache:http_server:1.3.12 + + CVE-2000-0869 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:04.437-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1656 + + + ATSTAKE + A090700-3 + + + SUSE + 20000907 + + + XF + apache-webdav-directory-listings + + The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.4.281 + + CVE-2000-0870 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:04.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1675 + + + BUGTRAQ + 20000911[EXPL] EFTP vulnerable to two DoS attacks + + + XF + eftp-bo + + + OSVDB + 1555 + + Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.4.281 + + CVE-2000-0871 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:04.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1677 + + + BUGTRAQ + 20000911[EXPL] EFTP vulnerable to two DoS attacks + + + XF + eftp-newline-dos + + + OSVDB + 409 + + Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server. + + + + + + + + + cpe:/a:nathan_purciful:phpphotoalbum:0.9.9 + + CVE-2000-0872 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:04.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phpphoto-dir-traverse + + + BID + 1650 + + + BUGTRAQ + 20000906 PhotoAlbum 0.9.9 explorer.php Vulnerability + + explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.2.1 + + CVE-2000-0873 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.047-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1660 + + + BUGTRAQ + 20000903 aix allows clearing the interface stats + + + XF + aix-clear-netstat + + netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities. + + + + + + + + + + cpe:/a:qualcomm:eudora:4.3 + cpe:/a:qualcomm:eudora:4.2 + + CVE-2000-0874 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eudora-path-disclosure + + + BID + 1653 + + + BUGTRAQ + 20000907 Eudora disclosure + + + OSVDB + 1545 + + Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF). + + + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc12 + cpe:/a:texas_imperial_software:wftpd_pro:2.41_rc12 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0875 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.343-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wftpd-long-string-dos + + + CONFIRM + http://www.wftpd.com/bug_gpf.htm + + + BUGTRAQ + 20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities + + WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters. + + + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc12 + cpe:/a:texas_imperial_software:wftpd_pro:2.41_rc12 + cpe:/a:texas_imperial_software:wftpd:2.34 + + CVE-2000-0876 + 2000-11-14T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + OSVDB + 5829 + + + BUGTRAQ + 20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities + + WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname. + + + + + + + + + cpe:/a:ranson_johnson:mailform:2.0 + + CVE-2000-0877 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.653-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1670 + + + BUGTRAQ + 20000911 Unsafe passing of variables to mailform.pl in MailForm V2.0 + + + XF + mailform-attach-file + + mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker. + + + + + + + + + cpe:/a:ranson_johnson:mailto_cgi_script:1.9 + + CVE-2000-0878 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.797-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1669 + + + BUGTRAQ + 20000911 Fwd: Poor variable checking in mailto.cgi + + + XF + mailto-piped-address + + The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field. + + + + + + + + + + cpe:/a:plus_technologies:lpplus:3.3 + cpe:/a:plus_technologies:lpplus:3.2.2 + + CVE-2000-0879 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:05.937-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lpplus-permissions-dos + + + BID + 1643 + + + BUGTRAQ + 20000906 Multiple Security Holes in LPPlus + + LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services. + + + + + + + + + + cpe:/a:plus_technologies:lpplus:3.3 + cpe:/a:plus_technologies:lpplus:3.2.2 + + CVE-2000-0880 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:06.077-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lpplus-process-perms-dos + + + BID + 1643 + + + BUGTRAQ + 20000906 Multiple Security Holes in LPPlus + + LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file. + + + + + + + + + + cpe:/a:plus_technologies:lpplus:3.3 + cpe:/a:plus_technologies:lpplus:3.2.2 + + CVE-2000-0881 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:06.233-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lpplus-dccscan-file-read + + + BID + 1644 + + + BUGTRAQ + 20000906 Multiple Security Holes in LPPlus + + The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files. + + + + + + + + + + + + + + + + cpe:/h:intel:express_550t:2.64 + cpe:/h:intel:express_550t:2.63 + cpe:/h:intel:express_520t:2.64 + cpe:/h:intel:express_520t:2.63 + cpe:/h:intel:express_510t:2.64 + cpe:/h:intel:express_510t:2.63 + cpe:/h:intel:express_550f:2.63 + cpe:/h:intel:express_550f:2.64 + + CVE-2000-0882 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:06.373-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1647 + + + BUGTRAQ + 20000906 VIGILANTE-2000010: Intel Express Switch series 500 DoS #2 + + Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash. + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + + CVE-2000-0883 + 2000-11-14T00:00:00.000-05:00 + 2008-09-05T16:22:06.530-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-mod-perl + + + BID + 1678 + + + MANDRAKE + MDKSA-2000:046 + + The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0884 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:04.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS00-078 + + + XF + iis-unicode-translation + + + BID + 1806 + + + OSVDB + 436 + + + + + IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_2000:::server + cpe:/a:microsoft:systems_management_server:1.2 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/a:microsoft:systems_management_server:2.0 + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-0885 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:06.827-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS00-083 + + Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0886 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:04.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS00-086 + + + BUGTRAQ + 20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability + + + XF + iis-invalid-filename-passing(5470) + + + BID + 1912 + + + + + IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. + + + + + + + + + cpe:/a:isc:bind:8.2.2:p5 + + CVE-2000-0887 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:07.137-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-20 + + + BID + 1923 + + + CONECTIVA + CLSA-2000:339 + + + XF + bind-zxfr-dos(5540) + + + BUGTRAQ + 20001107 BIND 8.2.2-P5 Possible DOS + + + REDHAT + RHSA-2000:107 + + + DEBIAN + 20001112 bind: remote Denial of Service + + + MANDRAKE + MDKSA-2000:067 + + + CONECTIVA + CLSA-2000:338 + + + SUSE + SuSE-SA:2000:45 + + + BUGTRAQ + 20001115 Trustix Security Advisory - bind and openssh (and modutils) + + named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug." + + + CVE-2000-0888 + 2000-12-19T00:00:00.000-05:00 + 2005-10-12T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-20 + + + CONECTIVA + CLSA-2000:339 + + + XF + bind-srv-dos(5814) + + + REDHAT + RHSA-2000:107 + + + DEBIAN + 20001112 bind: remote Denial of Service + + + MANDRAKE + MDKSA-2000:067 + + + CONECTIVA + CLSA-2000:338 + + + SUSE + SuSE-SA:2000:45 + + named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug." + + + CVE-2000-0889 + 2001-02-12T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2000-19 + + + SUN + 00198 + + Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun. + + + + + + + + + cpe:/o:freebsd:freebsd:6.2:stable + + CVE-2000-0890 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:22:07.467-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#626919 + + + XF + periodic-temp-file-symlink(6047) + + + BID + 2325 + + + OSVDB + 1754 + + periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:ibm:lotus_notes:5.02 + + CVE-2000-0891 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:06:07.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#5962 + + + CONFIRM + http://www.notes.net/R5FixList.nsf/Search!SearchView&Query=CBAT45TU9S + + + XF + lotus-notes-bypass-ecl(5045) + + A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email. + + + + + + + + + + + + + + cpe:/o:caldera:openlinux + cpe:/a:u_win:u_win + + CVE-2000-0892 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:22:07.763-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#22404 + + + XF + telnet-obtain-env-variable(6644) + + Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL. + + + + + + + + + cpe:/o:sgi:irix + + CVE-2000-0893 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:22:07.903-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#28027 + + The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system. + + + + + + + + + + cpe:/h:watchguard:soho_firewall:2.1.3 + cpe:/h:watchguard:soho_firewall:1.6 + + CVE-2000-0894 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:22:08.047-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ISS + 20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall + + + BID + 2119 + + + XF + watchguard-soho-web-auth(5554) + + + OSVDB + 4404 + + HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities. + + + + + + + + + + cpe:/h:watchguard:soho_firewall:2.1.3 + cpe:/h:watchguard:soho_firewall:1.6 + + CVE-2000-0895 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:22:08.200-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ISS + 20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall + + + BID + 2114 + + + XF + watchguard-soho-web-dos(5218) + + + OSVDB + 4403 + + Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request. + + + + + + + + + cpe:/h:watchguard:soho_firewall:1.6 + + CVE-2000-0896 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:22:08.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + watchguard-soho-fragmented-packets + + + ISS + 20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall + + + BID + 2113 + + + OSVDB + 1690 + + WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets. + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:2.01 + + CVE-2000-0897 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:08.483-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1941 + + + BUGTRAQ + 20001114 Vulnerabilites in SmallHTTP Server + + + CONFIRM + http://home.lanck.net/mf/srv/index.htm + + + XF + small-http-nofile-dos(5524) + + Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed. + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:2.01 + + CVE-2000-0898 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:08.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001114 Vulnerabilites in SmallHTTP Server + + Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file. + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:2.01 + + CVE-2000-0899 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:08.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1942 + + + BUGTRAQ + 20001114 Vulnerabilites in SmallHTTP Server + + Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests. + + + + + + + + + + + + cpe:/a:acme_labs:thttpd:2.18 + cpe:/a:acme_labs:thttpd:2.19 + cpe:/a:acme_labs:thttpd:2.16 + cpe:/a:acme_labs:thttpd:2.17 + + CVE-2000-0900 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:08.920-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + acme-thttpd-ssi + + + BID + 1737 + + + BUGTRAQ + 20001002 thttpd ssi: retrieval of arbitrary world-readable files + + + FREEBSD + FreeBSD-SA-00:73 + + Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. + + + + + + + + + + + cpe:/a:juergen:weigert_screen:3.9.3 + cpe:/a:juergen:weigert_screen:3.9.5 + cpe:/a:juergen:weigert_screen:3.9.4 + + CVE-2000-0901 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.077-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + screen-format-string + + + BID + 1641 + + + BUGTRAQ + 20000905 screen 3.9.5 root vulnerability + + + REDHAT + RHSA-2000:058 + + + SUSE + 20000906 screen format string parsing security problem + + + MANDRAKE + MDKSA-2000:044 + + + BUGTRAQ + 20000906 Screen-3.7.6 local compromise + + + FREEBSD + FreeBSD-SA-00:46 + + Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable. + + + + + + + + + cpe:/a:nathan_purciful:phpphotoalbum:0.9.9 + + CVE-2000-0902 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:08.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phpphotoalbum-getalbum-directory-traversal + + + BUGTRAQ + 20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability + + getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:qnx:voyager:2.01b + + CVE-2000-0903 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1648 + + + BUGTRAQ + 20000901 Multiple QNX Voyager Issues + + Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:qnx:voyager:2.01b + + CVE-2000-0904 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.513-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1648 + + + BUGTRAQ + 20000901 Multiple QNX Voyager Issues + + Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. + + + + + + + + + cpe:/a:qnx:voyager:2.01b + + CVE-2000-0905 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.653-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1648 + + + BUGTRAQ + 20000901 Multiple QNX Voyager Issues + + QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. + + + + + + + + + cpe:/a:moreover.com:cached_feed.cgi_script:1.0 + + CVE-2000-0906 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.793-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + moreover-cgi-dir-traverse + + + BID + 1762 + + + BUGTRAQ + 20001002 Moreover Cached_Feed CGI Vulnerability + + Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters. + + + + + + + + + cpe:/a:etype:eserv:2.92 + + CVE-2000-0907 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:09.950-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + WIN2KSEC + 20000925 DST2K0030: DoS in EServ 2.92 Build 2982 + + EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands. + + + + + + + + + cpe:/a:netcplus:browsegate:2.80 + + CVE-2000-0908 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.090-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + browsegate-http-dos + + + BID + 1702 + + + CONFIRM + http://www.netcplus.com/browsegate.htm#BGLatest + + + BUGTRAQ + 20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H) + + + WIN2KSEC + 20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H) + + BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request. + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.10 + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.0.4 + + CVE-2000-0909 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.247-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1709 + + + XF + pine-check-mail-bo + + + BUGTRAQ + 20000922 [ no subject ] + + + REDHAT + RHSA-2000:102 + + + MANDRAKE + MDKSA-2000:073 + + + BUGTRAQ + 20001031 FW: Pine 4.30 now available + + + FREEBSD + FreeBSD-SA-00:59 + + Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header. + + + + + + + + + cpe:/a:horde:horde:1.2 + + CVE-2000-0910 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.387-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + horde-imp-sendmail-command + + + BID + 1674 + + + DEBIAN + 20000910 imp: remote compromise + + + CONFIRM + http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch + + + BUGTRAQ + 20000908 horde library bug - unchecked from-address + + Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address. + + + + + + + + + + cpe:/a:horde:imp:2.0 + cpe:/a:horde:imp:2.2 + + CVE-2000-0911 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.543-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + imp-attach-file + + + BID + 1679 + + + BUGTRAQ + 20000912 (SRADV00003) Arbitrary file disclosure through IMP + + IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment. + + + + + + + + + cpe:/a:jcs_web_works:multihtml + + CVE-2000-0912 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.687-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + http-cgi-multihtml + + + BUGTRAQ + 20000913 MultiHTML vulnerability + + MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter. + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.11::win32 + cpe:/a:apache:http_server:0.8.14 + cpe:/a:apache:http_server:1.0 + cpe:/a:apache:http_server:0.8.11 + cpe:/a:apache:http_server:1.1 + cpe:/a:apache:http_server:1.0.2 + cpe:/a:apache:http_server:1.0.5 + cpe:/a:apache:http_server:1.1.1 + cpe:/a:apache:http_server:1.0.3 + cpe:/a:apache:http_server:1.3.12 + + CVE-2000-0913 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.840-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + apache-rewrite-view-files + + + BID + 1728 + + + REDHAT + RHSA-2000:095 + + + REDHAT + RHSA-2000:088 + + + MANDRAKE + MDKSA-2000:060 + + + CALDERA + CSSA-2000-035.0 + + + HP + HPSBUX0010-126 + + + BUGTRAQ + 20001011 Conectiva Linux Security Announcement - apache + + + BUGTRAQ + 20000929 Security vulnerability in Apache mod_rewrite + + mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.6 + + CVE-2000-0914 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:10.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-arp-request-dos + + + BID + 1759 + + + BUGTRAQ + 20001005 obsd_fun.c + + + OSVDB + 1592 + + OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1:release + + CVE-2000-0915 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:11.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + freebsd-fingerd-files + + + BID + 1803 + + + OSVDB + 433 + + + BUGTRAQ + 20001002 [sa2c@and.or.jp: bin/21704: enabling fingerd makes files world readable] + + + FREEBSD + FreeBSD-SA-00:54 + + fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.0 + + CVE-2000-0916 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:11.310-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1766 + + + FREEBSD + FreeBSD-SA-00:52 + + FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:caldera:openlinux + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/a:caldera:openlinux_ebuilder:3.0 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:trustix:secure_linux:1.0 + cpe:/o:redhat:linux:7.0 + + CVE-2000-0917 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:11.513-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2000-22 + + + XF + lprng-format-string + + + BID + 1712 + + + REDHAT + RHSA-2000:065 + + + CALDERA + CSSA-2000-033.0 + + + BUGTRAQ + 20000925 Format strings: bug #2: LPRng + + + FREEBSD + FreeBSD-SA-00:56 + + Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:kde:kvt:1.1.2 + + CVE-2000-0918 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:11.687-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1700 + + + BUGTRAQ + 20000919 kvt format bug + + Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. + + + + + + + + + + + cpe:/a:phpix:phpix:1.0 + cpe:/a:phpix:phpix:1.0.2 + cpe:/a:phpix:phpix:1.0.1 + + CVE-2000-0919 + 2000-12-19T00:00:00.000-05:00 + 2013-08-19T00:11:17.677-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phpix-dir-traversal + + + BID + 1773 + + + OSVDB + 472 + + + BUGTRAQ + 20001007 PHPix advisory + + Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:boa:boa_webserver:0.94.8.2 + + CVE-2000-0920 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:11.983-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + boa-webserver-get-dir-traversal + + + BID + 1770 + + + DEBIAN + 20001009 boa: exposes contents of local files + + + BUGTRAQ + 20001006 Vulnerability in BOA web server v0.94.8.2 + + + FREEBSD + FreeBSD-SA-00:60 + + Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "." + + + + + + + + + cpe:/a:hassan_consulting:shopping_cart:1.18 + + CVE-2000-0921 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.123-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hassan-shopping-cart-dir-traversal + + + BID + 1777 + + + OSVDB + 1596 + + + BUGTRAQ + 20001007 Security Advisory: Hassan Consulting's shop.cgi Directory Traversal Vulnerability. + + Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. + + + + + + + + + + cpe:/a:bytes_interactive:web_shopper:1.0 + cpe:/a:bytes_interactive:web_shopper:2.0 + + CVE-2000-0922 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.280-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + web-shopper-directory-traversal + + + BID + 1776 + + + BUGTRAQ + 20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability + + Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter. + + + + + + + + + cpe:/a:aplio:aplio_phone:2.0.33_build1 + + CVE-2000-0923 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.420-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + uclinux-apliophone-bin-execute + + + BID + 1784 + + + BUGTRAQ + 20001006 Fwd: APlio PRO web shell + + authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter. + + + + + + + + + cpe:/a:armada_design:master_index:1.0 + + CVE-2000-0924 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1772 + + + BUGTRAQ + 20001009 Master Index traverse advisory + + + XF + master-index-directory-traversal + + + OSVDB + 461 + + Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter. + + + + + + + + + cpe:/a:smartwin_technology:cyberoffice_shopping_cart:2.0 + + CVE-2000-0925 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1734 + + + WIN2KSEC + 20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2 + + + XF + cyberoffice-world-readable-directory + + + BUGTRAQ + 20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2 + + The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information. + + + + + + + + + cpe:/a:smartwin_technology:cyberoffice_shopping_cart:2.0 + + CVE-2000-0926 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:12.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1733 + + + WIN2KSEC + 20001002 DST2K0036: Price modification possible in CyberOffice Shopping Ca rt + + + XF + cyberoffice-price-modification + + + BUGTRAQ + 20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart + + SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. + + + + + + + + + cpe:/a:wquinn:quotaadvisor:4.1 + + CVE-2000-0927 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.013-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + quotaadvisor-quota-bypass + + + BID + 1724 + + + NTBUGTRAQ + 20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas. + + + BUGTRAQ + 20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas. + + WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions. + + + + + + + + + cpe:/a:wquinn:diskadvisor:4.1 + + CVE-2000-0928 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.153-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1765 + + + BUGTRAQ + 20001006 DST2K0040: QuotaAdvisor 4.1 by WQuinn susceptible to any user bei ng able to list (not read) all files on any server running QuotaAdvisor. + + + XF + quotaadvisor-list-files + + WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares. + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + + CVE-2000-0929 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.310-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mediaplayer-outlook-dos + + + BID + 1714 + + + MS + MS00-068 + + + BUGTRAQ + 20000929 Malformed Embedded Windows Media Player 7 "OCX Attachment" + + Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability. + + + + + + + + + cpe:/a:david_harris:pegasus_mail:3.12 + + CVE-2000-0930 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.450-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1738 + + + XF + pegasus-file-forwarding + + + BUGTRAQ + 20001030 Pegasus Mail file reading vulnerability + + + BUGTRAQ + 20001003 Pegasus mail file reading vulnerability + + Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. + + + + + + + + + cpe:/a:david_harris:pegasus_mail:3.11 + + CVE-2000-0931 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1750 + + + BUGTRAQ + 20001004 Another Pegasus Mail vulnerability + + Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data. + + + + + + + + + cpe:/a:clearswift:mailsweeper_for_smtp:3.x + + CVE-2000-0932 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20000926 FW: DOS for Content Technologies' MAILsweeper for SMTP. + + + XF + mailsweeper-smtp-dos + + MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-0933 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:13.903-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + win2k-simplified-chinese-ime + + + BID + 1729 + + + MS + MS00-069 + + The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability. + + + + + + + + + cpe:/o:redhat:linux:5.2 + + CVE-2000-0934 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:11.397-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + glint-symlink + + + BID + 1703 + + + REDHAT + RHSA-2000:062 + + Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2000-0935 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.200-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1872 + + + BUGTRAQ + 20001030 Samba 2.0.7 SWAT vulnerabilities + + + XF + samba-swat-logging-sym-link + + Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2000-0936 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.340-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1874 + + + BUGTRAQ + 20001030 Samba 2.0.7 SWAT vulnerabilities + + + XF + samba-swat-logfile-info + + Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2000-0937 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.497-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001030 Samba 2.0.7 SWAT vulnerabilities + + + XF + samba-swat-brute-force + + + BID + 1873 + + Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2000-0938 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.637-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001030 Samba 2.0.7 SWAT vulnerabilities + + + XF + samba-swat-brute-force(5442) + + Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2000-0939 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.793-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001030 Samba 2.0.7 SWAT vulnerabilities + + + XF + samba-swat-url-filename-dos + + Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart. + + + + + + + + + cpe:/a:metertek:pagelog.cgi:1.0 + + CVE-2000-0940 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:14.937-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pagelog-cgi-dir-traverse + + + BID + 1864 + + + BUGTRAQ + 20001029 Minor bug in Pagelog.cgi + + Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter. + + + + + + + + + cpe:/a:kootenay_web_inc:kootenay_web_inc_whois:1.0 + + CVE-2000-0941 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.077-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + kw-whois-meta + + + BID + 1883 + + + BUGTRAQ + 20001029 Re: Remote command execution via KW Whois 1.0 (addition) + + + MISC + http://www.kootenayweb.bc.ca/scripts/whois.txt + + + BUGTRAQ + 20001029 Remote command execution via KW Whois 1.0 + + Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. + + + + + + + + + cpe:/a:microsoft:indexing_service + + CVE-2000-0942 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.233-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1861 + + + MS + MS00-084 + + + XF + iis-htw-cross-scripting + + + BUGTRAQ + 20001028 IIS 5.0 cross site scripting vulnerability - using .htw + + The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. + + + + + + + + + cpe:/a:max-wilhelm_bruker:bftpd:1.0.11 + + CVE-2000-0943 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.373-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001027 Potential Security Problem in bftpd-1.0.11 + + + XF + bftpd-user-bo + + + BID + 1858 + + Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command. + + + + + + + + + cpe:/a:cgi_script_center:news_update:1.1 + + CVE-2000-0944 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.513-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + news-update-bypass-password + + + BID + 1881 + + + BUGTRAQ + 20001027 CGI-Bug: News Update 1.1 administration password bug + + CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password. + + + + + + + + + cpe:/h:cisco:catalyst_3500_xl + + CVE-2000-0945 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.670-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1846 + + + XF + cisco-catalyst-remote-commands(5415) + + + BUGTRAQ + 20001026 Advisory def-2000-02: Cisco Catalyst remote command execution + + + OSVDB + 444 + + + BUGTRAQ + 20001113 Re: 3500XL + + The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. + + + + + + + + + cpe:/a:compaq:easy_access_keyboard_software:1.3 + + CVE-2000-0946 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.810-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + NTBUGTRAQ + 20001012 Security issue with Compaq Easy Access Keyboard software + + + CONFIRM + http://www5.compaq.com/support/files/desktops/us/revision/1723.html + + + XF + compaq-ea-elevate-privileges + + + OSVDB + 5831 + + Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization. + + + + + + + + + + + cpe:/a:gnu:cfengine:1.6:a10 + cpe:/a:gnu:cfengine:1.5.3-4 + cpe:/a:gnu:cfengine:1.5 + + CVE-2000-0947 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:15.950-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1757 + + + MANDRAKE + MDKSA-2000:061 + + + XF + cfengine-cfd-format-string + + + BUGTRAQ + 20001002 Very probable remote root vulnerability in cfengine + + + NETBSD + NetBSD-SA2000-013 + + Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command. + + + + + + + + + cpe:/a:gnome:gnorpm:0.94 + + CVE-2000-0948 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.107-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + gnorpm-temp-symlink + + + BID + 1761 + + + BUGTRAQ + 20001002 GnoRPM local /tmp vulnerability + + + REDHAT + RHSA-2000:072 + + + MANDRAKE + MDKSA-2000:055 + + + BUGTRAQ + 20001011 Immunix OS Security Update for gnorpm package + + + BUGTRAQ + 20001003 Conectiva Linux Security Announcement - gnorpm + + GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack. + + + + + + + + + + + + + + cpe:/a:lbl:lbl_traceroute:1.4a5 + cpe:/o:sun:solaris:2.5.1 + + CVE-2000-0949 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.247-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + traceroute-heap-overflow + + + BID + 1739 + + + TURBO + TLSA2000023-1 + + + REDHAT + RHSA-2000:078 + + + MANDRAKE + MDKSA-2000:053 + + + DEBIAN + 20001013 traceroute: local root exploit + + + CALDERA + CSSA-2000-034.0 + + + BUGTRAQ + 20000930 Conectiva Linux Security Announcement - traceroute + + + BUGTRAQ + 20000928 Very interesting traceroute flaw + + Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option. + + + + + + + + + cpe:/a:tis:internet_firewall_toolkit:2.1 + + CVE-2000-0950 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.403-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + tisfwtk-xgw-execute-code + + + BUGTRAQ + 20001026 FWTK x-gw Security Advisory [GSA2000-01] + + Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2000-0951 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.543-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-index-dir-traverse + + + BID + 1756 + + + MSKB + Q272079 + + + ATSTAKE + A100400-1 + + A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. + + + + + + + + + cpe:/a:shigio_yamaguchi:global:3.55 + + CVE-2000-0952 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:13.460-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + global-execute-remote-commands + + + NETBSD + NetBSD-SA2000-014 + + + OSVDB + 6486 + + global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:evolvable_corporation:shambala_server:4.5 + + CVE-2000-0953 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.840-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + shambala-connection-dos + + + BID + 1778 + + + BUGTRAQ + 20001009 Shambala 4.5 vulnerability + + Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection. + + + + + + + + + cpe:/a:evolvable_corporation:shambala_server:4.5 + + CVE-2000-0954 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:16.997-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + shambala-password-plaintext + + + BID + 1771 + + + BUGTRAQ + 20001009 Shambala 4.5 vulnerability + + Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server. + + + + + + + + + cpe:/a:cisco:virtual_central_office_4000:5.1.3 + + CVE-2000-0955 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:17.137-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-vco-snmp-passwords + + + BID + 1885 + + + ATSTAKE + A102600-1 + + Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges. + + + + + + + + + cpe:/a:carnegie_mellon_university:cyrus-sasl:1.5.24 + + CVE-2000-0956 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:17.277-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cyrus-sasl-gain-access + + + BID + 1875 + + + REDHAT + RHSA-2000:094 + + cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions. + + + + + + + + + + + + cpe:/a:pam_mysql:pam_mysql:0.4 + cpe:/a:pam_mysql:pam_mysql:0.2 + cpe:/a:pam_mysql:pam_mysql:0.3 + cpe:/a:pam_mysql:pam_mysql:0.1 + + CVE-2000-0957 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:13.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + pammysql-auth-input + + + BUGTRAQ + 20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql + + The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes. + + + + + + + + + cpe:/a:sun:hotjava_browser:3.0 + + CVE-2000-0958 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:17.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hotjava-browser-dom-access + + + BUGTRAQ + 20001025 HotJava Browser 3.0 JavaScript security vulnerability + + HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window. + + + + + + + + + cpe:/a:gnu:glibc:2.1.3.10 + + CVE-2000-0959 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:17.730-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + glibc-unset-symlink + + + BID + 1719 + + + BUGTRAQ + 20000926 ld.so bug - LD_DEBUG_OUTPUT follows symlinks + + glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack. + + + + + + + + + + + cpe:/a:netscape:messaging_server:4.15:patch1 + cpe:/a:netscape:messaging_server:4.15 + cpe:/a:netscape:messaging_server:4.15:patch2 + + CVE-2000-0960 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:17.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-messaging-email-verify + + + BID + 1787 + + + BUGTRAQ + 20001011 Netscape Messaging server 4.15 poor error strings + + The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse. + + + + + + + + + + cpe:/a:netscape:messaging_server:4.0 + cpe:/a:netscape:netscape_messaging_server_multiplexor:4.0 + + CVE-2000-0961 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.027-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + netscape-messaging-list-dos + + + BID + 1721 + + + BUGTRAQ + 20000928 commercial products and security [ + new bug ] + + Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command. + + + + + + + + + cpe:/o:openbsd:openbsd:2.7 + + CVE-2000-0962 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1723 + + + BUGTRAQ + 20000925 Nmap Protocol Scanning DoS against OpenBSD IPSEC + + + XF + openbsd-nmap-dos + + + OSVDB + 1574 + + The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0 + + CVE-2000-0963 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.327-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1142 + + + CALDERA + CSSA-2000-036.0 + + + BUGTRAQ + 20001009 ncurses buffer overflows + + + XF + gnu-ncurses-term-terminfodirs-bo(44487) + + Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. + + + + + + + + + cpe:/h:siemens:hinet_lp:5100.0 + + CVE-2000-0964 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.497-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hinet-ipphone-get-bo + + + BID + 1727 + + + BUGTRAQ + 20000928 Another thingy. + + Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. + + + + + + + + + + cpe:/o:hp:vvos:11.04 + cpe:/o:hp:vvos:10.24 + + CVE-2000-0965 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.653-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-virtualvault-nsapi-dos + + + HP + HPSBUX0010-124 + + + + + The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization). + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0966 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.793-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-lpspooler-bo + + + HP + HPSBUX0010-125 + + + OSVDB + 7244 + + + + + Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges. + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/a:php:php:3.0 + + CVE-2000-0967 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:18.950-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + php-logging-format-string + + + BID + 1786 + + + REDHAT + RHSA-2000:095 + + + REDHAT + RHSA-2000:088 + + + MANDRAKE + MDKSA-2000:062 + + + CALDERA + CSSA-2000-037.0 + + + ATSTAKE + A101200-1 + + + BUGTRAQ + 20001012 Conectiva Linux Security Announcement - mod_php3 + + + FREEBSD + FreeBSD-SA-00:75 + + PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. + + + + + + + + + cpe:/a:valve_software:half-life_dedicated_server:3.1 + + CVE-2000-0968 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:19.107-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + halflife-server-changelevel-bo + + + BID + 1799 + + + BUGTRAQ + 20001024 Tamandua Sekure Labs Security Advisory 2000-01 + + + BUGTRAQ + 20001027 Re: Half Life dedicated server Patch + + + BUGTRAQ + 20001016 Half-Life Dedicated Server Vulnerability + + Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command. + + + + + + + + + cpe:/a:valve_software:half-life_dedicated_server:3.1.3 + + CVE-2000-0969 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:15.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + halflife-rcon-format-string + + + BUGTRAQ + 20001024 Tamandua Sekure Labs Security Advisory 2000-01 + + + OSVDB + 6983 + + + BUGTRAQ + 20001027 Re: Half Life dedicated server Patch + + + BUGTRAQ + 20001016 Half-Life Dedicated Server Vulnerability + + Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-0970 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:19.387-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + session-cookie-remote-retrieval + + + MS + MS00-080 + + + OSVDB + 7265 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt + + IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability. + + + + + + + + + + cpe:/a:avirt:avirt_mail_server:4.0 + cpe:/a:avirt:avirt_mail_server:4.2 + + CVE-2000-0971 + 2000-12-19T00:00:00.000-05:00 + 2009-04-03T00:06:51.750-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + avirt-rcpt-to-dos + + + XF + avirt-mail-from-dos + + + BUGTRAQ + 20001023 Avirt Mail 4.x DoS + + Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command. + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + + CVE-2000-0972 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:19.700-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-crontab-read-files + + + BUGTRAQ + 20001020 [ Hackerslab bug_paper ] HP-UX crontab temporary file symbolic link vulnerability + + HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:daniel_stenberg:curl:6.0 + cpe:/a:daniel_stenberg:curl:6.1 + cpe:/a:daniel_stenberg:curl:6.1beta + cpe:/a:daniel_stenberg:curl:7.1.1 + cpe:/a:daniel_stenberg:curl:7.2.1 + cpe:/a:daniel_stenberg:curl:7.2 + cpe:/a:daniel_stenberg:curl:7.1 + cpe:/a:daniel_stenberg:curl:7.4 + cpe:/a:daniel_stenberg:curl:7.3 + cpe:/a:daniel_stenberg:curl:6.5 + cpe:/a:daniel_stenberg:curl:6.4 + cpe:/a:daniel_stenberg:curl:6.5.1 + cpe:/a:daniel_stenberg:curl:6.3 + cpe:/a:daniel_stenberg:curl:6.5.2 + + CVE-2000-0973 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:19.840-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + curl-error-bo + + + BID + 1804 + + + REDHAT + RHBA-2000:092-01 + + + FREEBSD + FreeBSD-SA-00:72 + + Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated. + + + + + + + + + + + + cpe:/a:gnu:privacy_guard:1.0.3 + cpe:/a:gnu:privacy_guard:1.0.1 + cpe:/a:gnu:privacy_guard:1.0.2 + cpe:/a:gnu:privacy_guard:1.0 + + CVE-2000-0974 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.013-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + gnupg-message-modify + + + BID + 1797 + + + REDHAT + RHSA-2000:089 + + + OSVDB + 1608 + + + DEBIAN + 20001111 gnupg: incorrect signature verification + + + CONECTIVA + CLSA-2000:334 + + + BUGTRAQ + 20001025 Immunix OS Security Update for gnupg package + + + BUGTRAQ + 20001011 GPG 1.0.3 doesn't detect modifications to files with multiple signatures + + + FREEBSD + FreeBSD-SA-00:67 + + + CALDERA + CSSA-2000-038.0 + + GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection. + + + + + + + + + cpe:/a:anaconda_partners:foundation_directory + + CVE-2000-0975 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001012 Anaconda Advisory + + + XF + anaconda-apexec-directory-traversal + + + OSVDB + 435 + + Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:xfree86_project:xlib:3.3x + + CVE-2000-0976 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.310-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1805 + + + BUGTRAQ + 20001012 another Xlib buffer overflow + + + XF + xfree-xlib-bo(5751) + + + SGI + 20020502-01-I + + Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter. + + + + + + + + + cpe:/a:oatmeal_studios:mail_file:1.10 + + CVE-2000-0977 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1807 + + + BUGTRAQ + 20001011 Mail File POST Vulnerability + + + XF + mailfile-post-file-read + + mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter. + + + + + + + + + cpe:/a:bb4:big_brother_network_monitor:1.5c2 + + CVE-2000-0978 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1779 + + + BUGTRAQ + 20001010 Big Brother Systems and Network Monitor vulnerability + + + XF + bb4-netmon-execute-commands + + bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter. + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_me + + CVE-2000-0979 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.763-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + win9x-share-level-password + + + BID + 1780 + + + MS + MS00-072 + + + BUGTRAQ + 20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password + + + + + File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability. + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_me + + CVE-2000-0980 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:20.920-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win-nmpi-packet-dos + + + BID + 1781 + + + MS + MS00-073 + + NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23 + cpe:/a:mysql:mysql:3.20 + cpe:/a:mysql:mysql:3.21 + cpe:/a:mysql:mysql:3.22 + + CVE-2000-0981 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:16.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + mysql-authentication + + + CONFIRM + http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security + + + BUGTRAQ + 20001023 [CORE SDI ADVISORY] MySQL weak authentication + + MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password. + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.01 + + CVE-2000-0982 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:21.230-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-cache-info + + + BID + 1793 + + + MS + MS00-076 + + + MISC + http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt + + Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability. + + + + + + + + + cpe:/a:microsoft:netmeeting:3.0.1 + + CVE-2000-0983 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:16.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netmeeting-desktop-sharing-dos + + + BID + 1798 + + + MSKB + Q273854 + + + BUGTRAQ + 20001018 Denial of Service attack against computers running Microsoft NetMeeting + + + MS + MS00-077 + + Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.0w5 + cpe:/o:cisco:ios:12.1xl + cpe:/o:cisco:ios:12.1xj + cpe:/o:cisco:ios:12.1xi + cpe:/o:cisco:ios:12.1xh + cpe:/o:cisco:ios:12.0xa + cpe:/o:cisco:ios:12.0xe + cpe:/o:cisco:ios:12.0xh + cpe:/o:cisco:ios:12.1xp + cpe:/o:cisco:ios:12.1aa + cpe:/o:cisco:ios:12.0xj + cpe:/o:cisco:ios:12.1db + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.1dc + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.1da + cpe:/o:cisco:ios:12.1xf + cpe:/o:cisco:ios:12.1xg + cpe:/o:cisco:ios:12.1xd + cpe:/o:cisco:ios:12.1xe + cpe:/o:cisco:ios:12.1ec + cpe:/o:cisco:ios:12.1xb + cpe:/o:cisco:ios:12.1xc + cpe:/o:cisco:ios:12.1xa + + CVE-2000-0984 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:16.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1838 + + + CISCO + 20001025 Cisco IOS HTTP Server Query Vulnerability + + + XF + cisco-ios-query-dos(5412) + + + + + The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. + + + + + + + + + cpe:/a:nevis_systems:all-mail:1.1 + + CVE-2000-0985 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:21.793-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1789 + + + ATSTAKE + A101200-2 + + Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.5 + + CVE-2000-0986 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:21.933-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + oracle-home-bo + + + BUGTRAQ + 20001020 [ Hackerslab bug_paper ] Linux ORACLE 8.1.5 vulnerability + + Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable. + + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.6 + cpe:/a:oracle:internet_directory:2.0.6 + + CVE-2000-0987 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:16.993-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + oracle-oidldap-bo + + + BUGTRAQ + 20001020 In response to posting 10/18/2000 vulnerability in Oracle Internet Directory in Oracle 8.1.6 + + + BUGTRAQ + 20001018 vulnerability in Oracle Internet Directory in Oracle 8.1.6 + + Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter. + + + + + + + + + cpe:/a:bardon_data_systems:winu:5.1 + + CVE-2000-0988 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:22.230-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + winu-backdoor + + + BID + 1801 + + + CONFIRM + http://www.bardon.com/pwdcrack.htm + + + BUGTRAQ + 20001013 WinU Backdoor passwords!!!! + + WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration. + + + + + + + + + cpe:/a:intel:inbusiness_email_station:1.4.87 + + CVE-2000-0989 + 2000-12-19T00:00:00.000-05:00 + 2008-09-10T15:06:17.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + intel-email-username-bo + + + BUGTRAQ + 20001020 DoS in Intel corporation 'InBusiness eMail Station' + + + OSVDB + 6488 + + Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username. + + + + + + + + + + cpe:/a:krzysztof_dabrowski:cmd5checkpw:0.20 + cpe:/a:krzysztof_dabrowski:cmd5checkpw:0.21 + + CVE-2000-0990 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:22.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cmd5checkpw-qmail-bypass-authentication + + + BID + 1809 + + + CONFIRM + http://members.elysium.pl/brush/cmd5checkpw/changes.html + + + BUGTRAQ + 20001016 Authentication failure in cmd5checkpw 0.21 + + cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username. + + + + + + + + + cpe:/a:hilgraeve:hyperterminal:6.0 + + CVE-2000-0991 + 2000-12-19T00:00:00.000-05:00 + 2013-08-20T00:10:27.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + win-hyperterminal-telnet-bo + + + BID + 1815 + + + MS + MS00-079 + + Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.19 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:ssh:ssh:1.2.18 + cpe:/a:ssh:ssh:1.2.20 + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:openbsd:openssh:1.2 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.16 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.17 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.14 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.15 + cpe:/a:ssh:ssh:1.2.21 + cpe:/a:ssh:ssh:1.2.22 + cpe:/a:ssh:ssh:1.2.23 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2000-0992 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:22.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1742 + + + BUGTRAQ + 20000930 scp file transfer hole + + + XF + scp-overwrite-files + + + MANDRAKE + MDKSA-2000:057 + + Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-0993 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:23.013-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-libutil-format + + + BID + 1744 + + + OPENBSD + 20001003 A format string vulnerability exists in the pw_error(3) function. + + + BUGTRAQ + 20001004 Re: OpenBSD Security Advisory + + + NETBSD + NetBSD-SA2000-015 + + + FREEBSD + FreeBSD-SA-00:58 + + Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + + CVE-2000-0994 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:23.183-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-fstat-format + + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + + BID + 1746 + + + BUGTRAQ + 20001004 Re: OpenBSD Security Advisory + + Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable. + + + + + + + + + cpe:/o:openbsd:openbsd + + CVE-2000-0995 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:23.340-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + + XF + bsd-yp-passwd-format + + + OSVDB + 6125 + + Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name. + + + + + + + + + cpe:/o:openbsd:openbsd + + CVE-2000-0996 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:23.480-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + + XF + bsd-su-format + + + OSVDB + 6124 + + Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell. + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-0997 + 2000-12-19T00:00:00.000-05:00 + 2008-09-05T16:22:23.637-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-eeprom-format + + + BID + 1752 + + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges. + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:3.5.1:stable + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.5:stable + cpe:/o:freebsd:freebsd:3.5.1:release + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-0998 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:23.793-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1895 + + + FREEBSD + FreeBSD-SA-00:62 + + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. + + + + + + + + + cpe:/a:openbsd:openssh:4.5 + + CVE-2000-0999 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:23.967-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch + + Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges. + + + + + + + + + cpe:/a:aol:instant_messenger:4.1.2010 + + CVE-2000-1000 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.107-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aim-file-transfer-dos + + + BID + 1747 + + + BUGTRAQ + 20001003 AOL Instant Messenger DoS + + Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters. + + + + + + + + + cpe:/a:element_n.v:element_instantshop:1.0 + + CVE-2000-1001 + 2000-12-11T00:00:00.000-05:00 + 2008-09-10T15:06:20.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001024 Price modification in Element InstantShop + + + XF + instantshop-modify-price + + + OSVDB + 6487 + + add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable. + + + + + + + + + cpe:/a:stalker:communigate_pro:3.3.2 + + CVE-2000-1002 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.403-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + communigate-email-verify + + + BID + 1792 + + + BUGTRAQ + 20001012 Re: Netscape Messaging server 4.15 poor error strings + + POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + + CVE-2000-1003 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.543-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win-netbios-driver-type-dos + + + BID + 1794 + + + BUGTRAQ + 20001012 NSFOCUS SA2000-04: Microsoft Win9x client driver type comparing vulnerability + + NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash. + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + + CVE-2000-1004 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.700-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-photurisd-format + + + BUGTRAQ + 20001004 Re: OpenBSD Security Advisory + + + OSVDB + 6123 + + Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters. + + + + + + + + + + cpe:/a:extropia:extropia_webstore:2.0 + cpe:/a:extropia:extropia_webstore:1.0 + + CVE-2000-1005 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.857-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + extropia-webstore-fileread + + + BID + 1774 + + + BUGTRAQ + 20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability + + Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + + CVE-2000-1006 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:24.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ms-exchange-mime-dos + + + BID + 1869 + + + MS + MS00-082 + + Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability. + + + + + + + + + + cpe:/a:symantec:i-gear:3.5.7 + cpe:/a:symantec:i-gear:3.5 + + CVE-2000-1007 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.153-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20001025 I-gear 3.5.x for Microsoft Proxy logging vulnerability + temporary fix. + + + XF + igear-invalid-log(5791) + + I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors. + + + + + + + + + cpe:/o:palm:palm_os:3.5.2 + + CVE-2000-1008 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.293-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1715 + + + ATSTAKE + A092600-1 + + PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device. + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:trustix:secure_linux:1.1 + + CVE-2000-1009 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.450-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1871 + + + XF + linux-dump-execute-code + + + BUGTRAQ + 20001030 Redhat 6.2 dump command executes external program with suid priviledge. + + dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program. + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:5.2::alpha + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:redhat:linux:5.1 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:redhat:linux:5.2::sparc + cpe:/o:redhat:linux:5.0 + + CVE-2000-1010 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.607-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-talkd-overwrite-root + + + BID + 1764 + + + BUGTRAQ + 20001006 talkd [WAS: Re: OpenBSD Security Advisory] + + Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters. + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-1011 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.777-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-00:53 + + + XF + freebsd-catopen-bo + + + OSVDB + 6070 + + Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable. + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-1012 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:25.950-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-00:53 + + The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-1013 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.123-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-00:53 + + The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. + + + + + + + + + cpe:/o:sco:unixware:7.0 + + CVE-2000-1014 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + unixware-scohelp-format + + + BID + 1717 + + + OSVDB + 3240 + + + BUGTRAQ + 20000927 Unixware SCOhelp http server format string vulnerability + + Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter. + + + + + + + + + cpe:/a:open_source_development_network:slashcode:1.0.8 + + CVE-2000-1015 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.450-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + slashcode-default-admin-passwords + + + BID + 1731 + + + BUGTRAQ + 20000929 Default admin password with Slashcode. + + The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode priviliges and possibly execute arbitrary commands. + + + + + + + + + + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-1016 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + suse-installed-packages-exposed + + + BID + 1707 + + + BUGTRAQ + 20000921 httpd.conf in Suse 6.4 + + The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL. + + + + + + + + + cpe:/a:webteacher:webdata:2.2 + + CVE-2000-1017 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1732 + + + BUGTRAQ + 20001003 Update to DST2K0039: Webteachers Webdata: Importing files lower t han web root possible in to database + + + BUGTRAQ + 20001002 DST2K0039: Webteachers Webdata: Importing files lower than web ro ot possible in to database + + Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database. + + + + + + + + + cpe:/a:mendel_cooper:shred:1.0 + + CVE-2000-1018 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:26.903-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1788 + + + BUGTRAQ + 20001011 Shred v1.0 Fix + + + XF + shred-recover-files + + + BUGTRAQ + 20001010 Shred 1.0 Bug Report + + shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file. + + + + + + + + + + cpe:/a:inktomi:search_software:3.0 + cpe:/a:inktomi:search_software:3.1.10 + + CVE-2000-1019 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ultraseek-malformed-url-dos + + + BID + 1866 + + + BUGTRAQ + 20001030 Ultraseek 3.1.x Remote DoS Vulnerability + + Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL. + + + + + + + + + cpe:/a:alt-n:mdaemon:3.1.1 + + CVE-2000-1020 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.183-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mdaemon-url-dos + + + BID + 1689 + + + BUGTRAQ + 20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS + + Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. + + + + + + + + + cpe:/a:alt-n:mdaemon:3.1.1 + + CVE-2000-1021 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.310-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1689 + + + XF + mdaemon-url-dos + + + BUGTRAQ + 20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS + + Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. + + + + + + + + + + + + + + + + cpe:/o:cisco:pix_firewall:4.2%285%29 + cpe:/o:cisco:pix_firewall:4.4%284%29 + cpe:/o:cisco:pix_firewall:4.2%282%29 + cpe:/o:cisco:pix_firewall:4.2%281%29 + cpe:/o:cisco:pix_firewall:5.1 + cpe:/o:cisco:pix_firewall:5.0 + cpe:/o:cisco:pix_firewall:5.2 + cpe:/o:cisco:pix_firewall:4.3 + + CVE-2000-1022 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.467-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-pix-smtp-filtering + + + BID + 1698 + + + CISCO + 20001005 Cisco Secure PIX Firewall Mailguard Vulnerability + + + BUGTRAQ + 20000920 Re: Cisco PIX Firewall (smtp content filtering hack) - Version 4.2(1) not exploitable + + + BUGTRAQ + 20000919 Cisco PIX Firewall (smtp content filtering hack) + + The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands. + + + + + + + + + cpe:/a:alabanza:control_panel:3.0 + + CVE-2000-1023 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1710 + + + XF + alabanza-unauthorized-access + + + BUGTRAQ + 20000924 Major Vulnerability in Alabanza Control Panel + + The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program. + + + + + + + + + cpe:/a:unify:ewave_servletexec:3.0c + + CVE-2000-1024 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.793-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1876 + + + XF + ewave-servletexec-file-upload + + + BUGTRAQ + 20001101 Unify eWave ServletExec upload + + eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands. + + + + + + + + + cpe:/a:unify:ewave_servletexec:3.0c + + CVE-2000-1025 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:27.933-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1868 + + + BUGTRAQ + 20001030 Unify eWave ServletExec DoS + + + XF + ewave-servletexec-dos + + eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running. + + + + + + + + + + + + cpe:/a:lbl:tcpdump:3.5 + cpe:/a:lbl:tcpdump:3.4 + cpe:/a:lbl:tcpdump:3.5_alpha + cpe:/a:lbl:tcpdump:3.4a6 + + CVE-2000-1026 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:28.090-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1870 + + + XF + tcpdump-afs-packet-overflow(5480) + + + SUSE + SuSE-SA:2000:46 + + + FREEBSD + FreeBSD-SA-00:61 + + Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/o:cisco:pix_firewall:5.2 + + CVE-2000-1027 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:28.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1877 + + + BUGTRAQ + 20001003 Cisco PIX Firewall allow external users to discover internal IPs + + + XF + cisco-pix-reveal-address + + + OSVDB + 1623 + + Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established. + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:9.00 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:9.04 + cpe:/o:hp:hp-ux:9.01 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:9.07 + cpe:/o:hp:hp-ux:9.10 + cpe:/o:hp:hp-ux:9.08 + cpe:/o:hp:hp-ux:9.05 + cpe:/o:hp:hp-ux:9.06 + cpe:/o:hp:hp-ux:9.09 + + CVE-2000-1028 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:28.387-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1886 + + + BUGTRAQ + 20001102 HPUX cu -l option buffer overflow vulnerabilit + + Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument. + + + + + + + + + cpe:/a:isc:bind:8.1 + + CVE-2000-1029 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:28.577-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1887 + + + BUGTRAQ + 20001027 old version of host command vulnearbility + + Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query. + + + + + + + + + cpe:/a:csandt:corporatetime_for_the_web:2.1.2 + + CVE-2000-1030 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:28.730-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1888 + + + BUGTRAQ + 20001031 Re: Samba 2.0.7 SWAT vulnerabilities + + CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server. + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:tru64:4.0f:pk8 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.4 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:4.0g:pk4 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2000-1031 + 2000-12-11T00:00:00.000-05:00 + 2011-03-07T21:04:10.313-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#320067 + + + BID + 1889 + + + HP + HPSBUX0011-128 + + + XF + hp-dtterm(5461) + + + BUGTRAQ + 20000810 Re: Possible vulnerability in HPUX ( Add vulnerability List ) + + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + HP + SSRT2275 + + + FULLDISC + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-1032 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1890 + + + BUGTRAQ + 20001101 Re: Samba 2.0.7 SWAT vulnerabilities + + + XF + fw1-login-response(5816) + + + OSVDB + 1632 + + The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall. + + + + + + + + + cpe:/a:cat_soft:serv-u:2.5x + + CVE-2000-1033 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.153-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + ftp-servu-brute-force + + + BID + 1860 + + + BUGTRAQ + 20001029 Brute Forcing FTP Servers with enabled anti-hammering (anti brute-force) modus + + Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-1034 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.293-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1899 + + + MS + MS00-085 + + + XF + system-monitor-activex-bo(5467) + + + BUGTRAQ + 20001106 System Monitor ActiveX Buffer Overflow Vulnerability + + Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. + + + + + + + + + cpe:/a:typsoft:typsoft:0.7x + + CVE-2000-1035 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.450-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt + + + BID + 1690 + + + BUGTRAQ + 20000912 TYPSoft FTP Server remote DoS Problem + + Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command. + + + + + + + + + cpe:/a:extent_technologies:rbs_isp:2.5 + + CVE-2000-1036 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rbs-isp-directory-traversal + + + BID + 1704 + + + BUGTRAQ + 20000920 Extent RBS directory Transversal. + + Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2000-1037 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.730-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1662 + + + BUGTRAQ + 20000815 Firewall-1 session agent 3.0 -> 4.1, dictionnary and brute force attack + + Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack. + + + + + + + + + cpe:/a:ibm:as400_firewall:r440 + + CVE-2000-1038 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:29.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument + + + XF + as400-firewall-dos + + + AIXAPAR + SA90544 + + The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request. + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-1039 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:30.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2000-21 + + + BID + 2022 + + + MS + MS00-091 + + + BINDVIEW + 20001130 The NAPTHA DoS vulnerabilities + + + WIN2KSEC + 20001204 NAPTHA Advisory Updated - BindView RAZOR + + Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE. + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-1040 + 2000-12-11T00:00:00.000-05:00 + 2008-09-10T15:06:26.947-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1820 + + + XF + ypbind-printf-format-string + + + REDHAT + RHSA-2000:086 + + + MANDRAKE + MDKSA-2000:064 + + + DEBIAN + 20001014 nis: local exploit + + + CALDERA + CSSA-2000-039.0 + + + SUSE + SuSE-SA:2000:042 + + + BUGTRAQ + 20001030 Trustix Security Advisory - ping gnupg ypbind + + + BUGTRAQ + 20001025 Immunix OS Security Update for ypbind package + + Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. + + + + + + + + + cpe:/a:swen_thuemmler:ypbind:3.3 + + CVE-2000-1041 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:30.340-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2000:064 + + + CALDERA + CSSA-2000-039.0 + + + SUSE + SuSE-SA:2000:042 + + + XF + ypbind-remote-bo + + Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges. + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + + CVE-2000-1042 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:30.497-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2000:064 + + + XF + linux-ypserv-bo + + Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function. + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + + CVE-2000-1043 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:30.637-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2000:064 + + + XF + linux-ypserv-format-string + + Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function. + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2000-1044 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:30.793-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1820 + + + SUSE + SuSE-SA:2000:042 + + + XF + ypbind-printf-format-string + + Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges. + + + + + + + + + + + cpe:/a:padl_software:nss_ldap:build_113 + cpe:/a:padl_software:nss_ldap:build_105 + cpe:/a:padl_software:nss_ldap:build_85 + + CVE-2000-1045 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:30.950-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1863 + + + REDHAT + RHSA-2000:024 + + + MANDRAKE + MDKSA-2000-066 + + + XF + nssldap-nscd-dos + + nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests. + + + + + + + + + + cpe:/a:lotus:domino:5.0.2c + cpe:/a:lotus:domino:5.0.2a + + CVE-2000-1046 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.107-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20000911 Advisory Code: VIGILANTE-2000011 Lotus Domino ESMTP Service Buffer overflow + + Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands. + + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino_mail_server:5.0.1 + cpe:/a:lotus:domino_mail_server:5.0.3 + cpe:/a:lotus:domino_mail_server:5.0.2 + cpe:/a:lotus:domino_mail_server:5.0.4 + cpe:/a:lotus:domino_mail_server:5.0.2b + cpe:/a:lotus:domino_enterprise_server:5.0.1 + cpe:/a:lotus:domino_enterprise_server:5.0.2 + cpe:/a:lotus:domino_enterprise_server:5.0.3 + cpe:/a:lotus:domino_enterprise_server:5.0.2b + cpe:/a:lotus:domino_enterprise_server:5.0.4 + + CVE-2000-1047 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.247-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1905 + + + BUGTRAQ + 20001103 [SAFER] Buffer overflow in Lotus Domino SMTP Server + + + XF + lotus-domino-smtp-envid(5488) + + + OSVDB + 442 + + Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the "MAIL FROM" command. + + + + + + + + + + + + cpe:/a:qbik:wingate:2.1 + cpe:/a:qbik:wingate:4.0.1 + cpe:/a:qbik:wingate:4.1_beta_a + cpe:/a:qbik:wingate:3.0 + + CVE-2000-1048 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wingate-view-files + + + BUGTRAQ + 20001016 Wingate 4.1 Beta A vulnerability + + Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL. + + + + + + + + + + cpe:/a:macromedia:jrun:3.0 + cpe:/a:macromedia:jrun:3.0:sp1 + + CVE-2000-1049 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.560-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + allaire-jrun-servlet-dos + + + ALLAIRE + ASB00-030 + + + BUGTRAQ + 20001101 Allaire's JRUN DoS + + Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters. + + + + + + + + + + cpe:/a:macromedia:jrun:3.0 + cpe:/a:macromedia:jrun:3.0:sp1 + + CVE-2000-1050 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + allaire-jrun-webinf-access + + + ALLAIRE + ASB00-027 + + + OSVDB + 500 + + + BUGTRAQ + 20001023 Allaire's JRUN Unauthenticated Access to WEB-INF directory + + Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash"). + + + + + + + + + cpe:/a:macromedia:jrun:2.3.x + + CVE-2000-1051 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:31.903-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + allaire-jrun-ssifilter-url + + + ALLAIRE + ASB00-028 + + + BUGTRAQ + 20001023 Allaire JRUN 2.3 Arbitrary File Retrieval + + Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet. + + + + + + + + + cpe:/a:macromedia:jrun:2.3.x + + CVE-2000-1052 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.073-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001023 Allaire JRUN 2.3 Arbitrary File Retrieval + + Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet. + + + + + + + + + cpe:/a:macromedia:jrun:2.3.x + + CVE-2000-1053 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.230-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + allaire-jrun-jsp-execute + + + ALLAIRE + ASB00-029 + + + BUGTRAQ + 20001023 Allaire JRUN 2.3 Remote command execution + + Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet. + + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:2.3%283%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.4%282%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.1::windows_nt + + CVE-2000-1054 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.370-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ciscosecure-csadmin-bo + + + BID + 1705 + + + CISCO + 20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server + + Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet. + + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:2.3%283%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.4%282%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.1::windows_nt + + CVE-2000-1055 + 2000-12-11T00:00:00.000-05:00 + 2013-08-14T00:10:49.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ciscosecure-tacacs-dos + + + BID + 1706 + + + CISCO + 20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server + + + OSVDB + 1569 + + Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. + + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:2.3%283%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.4%282%29::windows_nt + cpe:/a:cisco:secure_access_control_server:2.1::windows_nt + + CVE-2000-1056 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.683-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ciscosecure-ldap-bypass-authentication + + + BID + 1708 + + + CISCO + 20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server + + CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords. + + + + + + + + + + + + + + + cpe:/a:hp:openview_network_node_manager:4.11::hp_ux + cpe:/a:hp:openview_network_node_manager:6.1::solaris + cpe:/a:hp:openview_network_node_manager:5.01::solaris + cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_11.x + cpe:/a:hp:openview_network_node_manager:5.01::hp_ux + cpe:/a:hp:openview_network_node_manager:4.11::solaris + cpe:/a:hp:openview_network_node_manager:6.1::hp_ux_10.x + + CVE-2000-1057 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.840-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-openview-nnm-scripts + + + BID + 1682 + + + HP + HPSBUX0009-120 + + Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions. + + + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.1 + cpe:/a:hp:openview_network_node_manager:4.11 + cpe:/a:hp:openview_network_node_manager:5.01 + + CVE-2000-1058 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:32.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + openview-nmm-snmp-bo + + + BUGTRAQ + 20000926 DST2K0014: BufferOverrun in HP Openview Network Node Manager v6.1 (Round2) + + + HP + HPSBUX0009-121 + + Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem." + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + + CVE-2000-1059 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.153-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xinitrc-bypass-xauthority + + + BID + 1735 + + + BUGTRAQ + 20000929 Mandrake 7.1 bypasses Xauthority X session security. + + + MANDRAKE + MDKSA-2000:052 + + The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges. + + + + + + + + + cpe:/a:xfree86_project:xfce:3.5.1 + + CVE-2000-1060 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.293-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xinitrc-bypass-xauthority + + + BID + 1736 + + + BUGTRAQ + 20001002 Local vulnerability in XFCE 3.5.1 + + The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges. + + + + + + + + + + cpe:/a:microsoft:ie:5.x + cpe:/a:microsoft:ie:4.x + + CVE-2000-1061 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.450-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-075 + + + XF + java-vm-applet + + Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability. + + + + + + + + + + + cpe:/h:hp:jetdirect:x.08.20 + cpe:/h:hp:jetdirect:x.08.04 + cpe:/h:hp:jetdirect:x.08.05 + + CVE-2000-1062 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.607-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-jetdirect-firmware-dos + + + BID + 1775 + + + BUGTRAQ + 20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS + + Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service. + + + + + + + + + + + cpe:/h:hp:jetdirect:x.08.20 + cpe:/h:hp:jetdirect:x.08.04 + cpe:/h:hp:jetdirect:x.08.05 + + CVE-2000-1063 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-jetdirect-firmware-dos + + + BID + 1775 + + + BUGTRAQ + 20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS + + Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service. + + + + + + + + + + + cpe:/h:hp:jetdirect:x.08.20 + cpe:/h:hp:jetdirect:x.08.04 + cpe:/h:hp:jetdirect:x.08.05 + + CVE-2000-1064 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:33.903-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-jetdirect-firmware-dos + + + BID + 1775 + + + BUGTRAQ + 20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS + + Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service. + + + + + + + + + + + cpe:/h:hp:jetdirect:x.08.20 + cpe:/h:hp:jetdirect:x.08.04 + cpe:/h:hp:jetdirect:x.08.05 + + CVE-2000-1065 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.060-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-jetdirect-ip-implementation + + + BID + 1775 + + + BUGTRAQ + 20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS + + Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:4.1.1:release + + CVE-2000-1066 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.217-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1894 + + + FREEBSD + FreeBSD-SA-00:63 + + The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname. + + + + + + + + + + cpe:/a:cgi-world:poll_it_pro:1.6 + cpe:/a:cgi-world:poll_it:2.0 + + CVE-2000-1068 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.370-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001023 Re: Poll It v2.0 cgi (again) + + + CONFIRM + http://www.cgi-world.com/pollit.html + + + XF + pollit-polloptions-execute-commands + + pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter. + + + + + + + + + + + cpe:/a:cgi-world:poll_it_pro:1.6 + cpe:/a:cgi-world:poll_it:2.0 + cpe:/a:cgi-world:poll_it:2.01 + + CVE-2000-1069 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.527-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pollit-admin-password-var + + + BUGTRAQ + 20001023 Re: Poll It v2.0 cgi (again) + + pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters. + + + + + + + + + + + cpe:/a:cgi-world:poll_it_pro:1.6 + cpe:/a:cgi-world:poll_it:2.0 + cpe:/a:cgi-world:poll_it:2.01 + + CVE-2000-1070 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.683-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001023 Re: Poll It v2.0 cgi (again) + + + XF + pollit-webroot-gain-access + + pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information. + + + + + + + + + cpe:/a:netscape:iplanet_ical:2.1:patch2 + + CVE-2000-1071 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.823-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A100900-1 + + + BID + 1767 + + + XF + ical-xhost-gain-privileges + + + OSVDB + 7213 + + The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges. + + + + + + + + + cpe:/a:netscape:iplanet_ical:2.1:patch2 + + CVE-2000-1072 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:34.967-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1768 + + + ATSTAKE + A100900-1 + + + XF + ical-iplncal-gain-access + + + OSVDB + 7212 + + iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse. + + + + + + + + + cpe:/a:netscape:iplanet_ical:2.1:patch2 + + CVE-2000-1073 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:35.120-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1769 + + + ATSTAKE + A100900-1 + + + XF + ical-csstart-gain-access + + + OSVDB + 7210 + + csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory. + + + + + + + + + cpe:/a:netscape:iplanet_ical:2.1:patch2 + + CVE-2000-1074 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:35.277-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1769 + + + ATSTAKE + A100900-1 + + + XF + ical-csstart-gain-access + + + OSVDB + 7209 + + csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory. + + + + + + + + + + cpe:/a:sun:iplanet_certificate_management_system:4.2 + cpe:/a:netscape:directory_server:4.12 + + CVE-2000-1075 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:35.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1839 + + + XF + iplanet-netscape-directory-traversal + + + CONFIRM + http://www.iplanet.com/downloads/patches/0122.html + + + OSVDB + 486 + + + OSVDB + 4086 + + + BUGTRAQ + 20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug + + Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services. + + + + + + + + + + cpe:/a:sun:iplanet_certificate_management_system:4.2 + cpe:/a:netscape:directory_server:4.12 + + CVE-2000-1076 + 2000-12-11T00:00:00.000-05:00 + 2008-09-10T15:06:32.243-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + iplanet-netscape-plaintext-password + + + BUGTRAQ + 20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug + + Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.x + + CVE-2000-1077 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:35.730-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module + + + XF + iplanet-web-server-shtml-bo + + Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension. + + + + + + + + + cpe:/a:mirabilis:icq_web_front:windows_9x + + CVE-2000-1078 + 2000-12-11T00:00:00.000-05:00 + 2008-09-05T16:22:35.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + icq-webfront-url-dos + + + BUGTRAQ + 20001007 ICQ WebFront HTTPd DoS + + ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-1079 + 2000-08-29T00:00:00.000-04:00 + 2008-09-10T15:06:32.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + XF + win-netbios-corrupt-cache + + + BID + 1620 + + + NAI + 20000829 Windows NetBIOS Unsolicited Cache Corruption + + + NTBUGTRAQ + 20000829 Re: [COVERT-2000-10] Windows NetBIOS Unsolicited Cache Corruption + + + + + Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. + + + + + + + + + + cpe:/a:id_software:quake:1.9 + cpe:/a:j._p._grossman:proquake:1.0 + + CVE-2000-1080 + 2000-11-01T00:00:00.000-05:00 + 2008-09-05T16:22:36.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1900 + + + CONFIRM + http://proquake.ai.mit.edu/ + + + BUGTRAQ + 20001102 dos on quake1 servers + + + XF + quake-empty-udp-dos(5527) + + Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1081 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:32.897-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 2030 + + + MS + MS00-092 + + + ATSTAKE + 20001201 Microsoft SQL Server extended stored procedure vulnerability + + + + + The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1082 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:36.480-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2031 + + + MS + MS00-092 + + + ATSTAKE + 20001201 Microsoft SQL Server extended stored procedure vulnerability + + The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1083 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:36.637-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2038 + + + MS + MS00-092 + + + ATSTAKE + 20001201 Microsoft SQL Server extended stored procedure vulnerability + + The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1084 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:36.793-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2039 + + + MS + MS00-092 + + + ATSTAKE + 20001201 Microsoft SQL Server extended stored procedure vulnerability + + The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1085 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:36.950-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2040 + + + MS + MS00-092 + + + ATSTAKE + 20001201 SQL Server 2000 Extended Stored Procedure Vulnerability + + The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1086 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:37.107-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2041 + + + MS + MS00-092 + + + ATSTAKE + 20001201 SQL Server 2000 Extended Stored Procedure Vulnerability + + The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1087 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:37.263-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2042 + + + MS + MS00-092 + + + ATSTAKE + 20001201 SQL Server 2000 Extended Stored Procedure Vulnerability + + The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2000-1088 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:37.417-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2043 + + + MS + MS00-092 + + + ATSTAKE + 20001201 SQL Server 2000 Extended Stored Procedure Vulnerability + + The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-1089 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:37.573-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A120400-1 + + + BID + 2048 + + + MS + MS00-094 + + + XF + phone-book-service-bo(5623) + + Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0:::far_east + cpe:/a:microsoft:internet_information_server:4.0:::far_east + + CVE-2000-1090 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:22:37.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2100 + + + XF + microsoft-iis-file-disclosure + + + MISC + http://www.nsfocus.com/english/homepage/sa_08.htm + + Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character. + + + + + + + + + + cpe:/a:alex_heiphetz_group:ezshopper:3.0 + cpe:/a:alex_heiphetz_group:ezshopper:2.0 + + CVE-2000-1092 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:36.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ezshopper-cgi-file-disclosure(5740) + + + BID + 2109 + + + BUGTRAQ + 20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List + + loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter. + + + + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:2.5.1598 + cpe:/a:aol:instant_messenger:3.0.1470 + cpe:/a:aol:instant_messenger:4.2.1193 + cpe:/a:aol:instant_messenger:2.5.1366 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:aol:instant_messenger:3.5.1808 + cpe:/a:aol:instant_messenger:3.0_n + cpe:/a:aol:instant_messenger:3.5.1856 + cpe:/a:aol:instant_messenger:3.5.1670 + cpe:/a:aol:instant_messenger:3.5.1635 + cpe:/a:aol:instant_messenger:2.0_n + cpe:/a:aol:instant_messenger:4.1.2010 + + CVE-2000-1093 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:38.027-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A121200-1 + + Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. + + + + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:2.5.1598 + cpe:/a:aol:instant_messenger:3.0.1470 + cpe:/a:aol:instant_messenger:4.2.1193 + cpe:/a:aol:instant_messenger:2.5.1366 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:aol:instant_messenger:3.5.1808 + cpe:/a:aol:instant_messenger:3.0_n + cpe:/a:aol:instant_messenger:3.5.1856 + cpe:/a:aol:instant_messenger:3.5.1670 + cpe:/a:aol:instant_messenger:3.5.1635 + cpe:/a:aol:instant_messenger:2.0_n + cpe:/a:aol:instant_messenger:4.1.2010 + + CVE-2000-1094 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:38.217-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A121200-1 + + + OSVDB + 1692 + + + BUGTRAQ + 20001214 Re: AIM & @stake's advisory + + + BUGTRAQ + 20001213 Administrivia & AOL IM Advisory + + Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument. + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:redhat:linux:7.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2000-1095 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:38.403-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1936 + + + REDHAT + RHSA-2000:108 + + + XF + linux-modprobe-execute-code + + + MANDRAKE + MDKSA-2000:071 + + + DEBIAN + 20001120 modutils: local exploit + + + CONECTIVA + CLSA-2000:340 + + + SUSE + SuSE-SA:2000:44 + + + BUGTRAQ + 20001112 RedHat 7.0 (and SuSE): modutils + netkit = root compromise. (fwd) + + modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:paul_vixie:vixie_cron:3.0_pl1 + + CVE-2000-1096 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:36.837-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1960 + + + XF + vixie-cron-execute-commands(5543) + + + BUGTRAQ + 20001116 vixie cron... + + crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file. + + + + + + + + + + cpe:/h:sonicwall:soho_firewall:4.0.0 + cpe:/h:sonicwall:soho_firewall:5.0.0 + + CVE-2000-1097 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:38.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2013 + + + BUGTRAQ + 20001129 DoS in Sonicwall SOHO firewall + + + XF + sonicwall-soho-dos(5596) + + + OSVDB + 1667 + + + BUGTRAQ + 20001201 FW: SonicWALL SOHO Vulnerability (fwd) + + The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page. + + + + + + + + + + cpe:/h:sonicwall:soho_firewall:4.0.0 + cpe:/h:sonicwall:soho_firewall:5.0.0 + + CVE-2000-1098 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:38.857-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001201 FW: SonicWALL SOHO Vulnerability (fwd) + + + BUGTRAQ + 20001201 Re: DoS in Sonicwall SOHO firewall + + The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request. + + + + + + + + + + + + + + + + + + cpe:/a:sun:jdk:1.2.2:update5 + cpe:/a:sun:jdk:1.1.7b + cpe:/a:sun:jdk:1.1.7b:update5 + cpe:/a:sun:jdk:1.1.6:update7 + cpe:/a:sun:jdk:1.1.8:update2 + cpe:/a:sun:jdk:1.1.8:update10 + cpe:/a:sun:jdk:1.1.6 + cpe:/a:sun:jdk:1.2.2:update4 + cpe:/a:sun:jdk:1.2.1:update3 + cpe:/a:sun:jdk:1.2.1 + + CVE-2000-1099 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:37.993-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SUN + 00199 + + + XF + jdk-untrusted-java-class(5605) + + + HP + HPSBUX0011-132 + + + OSVDB + 7255 + + Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities. + + + + + + + + + cpe:/a:trlinux:postaci_webmail:1.1.3 + + CVE-2000-1100 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2029 + + + BUGTRAQ + 20001130 PostACI Webmail Vulnerability + + The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request. + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:2.41_rc14::pro + cpe:/a:texas_imperial_software:wftpd:2.41_rc14 + cpe:/a:texas_imperial_software:wftpd:3.0::pro + + CVE-2000-1101 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2005 + + + BUGTRAQ + 20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro) + + + XF + wftpd-dir-traverse(5608) + + Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack. + + + + + + + + + + cpe:/a:ptlink:ptlink_irc_services:1.8.1 + cpe:/a:ptlink:ptlink_ircd:3.5.3 + + CVE-2000-1102 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2008 + + + BUGTRAQ + 20001126 Vulnerablity in PTlink3.5.3ircd + PTlink.Services.1.8.1... + + PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands. + + + + + + + + + + + + cpe:/o:bsdi:bsd_os:4.0 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:bsdi:bsd_os:3.1 + cpe:/o:bsdi:bsd_os:4.0.1 + + CVE-2000-1103 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.620-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2009 + + + BUGTRAQ + 20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package) + + rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-1104 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS00-060 + + Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site. + + + + + + + + + cpe:/a:microsoft:indexing_service:::windows_2000 + + CVE-2000-1105 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:39.933-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1933 + + + WIN2KSEC + 20001110 IE 5.x Win2000 Indexing service vulnerability + + + BUGTRAQ + 20001110 IE 5.x Win2000 Indexing service vulnerability + + The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.4 + + CVE-2000-1106 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.073-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2014 + + + BUGTRAQ + 20001128 TrendMicro InterScan VirusWall shared folder problem + + + XF + interscan-viruswall-unauth-access + + + BUGTRAQ + 20001201 Responding to BugTraq ID 2014 - "Trend Micro InterScan VirusWall Shared Directory Vulnerability" + + Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs. + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.0 + + CVE-2000-1107 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.230-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2015 + + + BUGTRAQ + 20001128 SuSE Linux 6.x 7.0 Ident buffer overflow + + + XF + linux-ident-bo + + in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash. + + + + + + + + + cpe:/a:midnight_commander:midnight_commander:4.5.42 + + CVE-2000-1108 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.370-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1945 + + + DEBIAN + 20001125 mc: local DoS + + + XF + midnight-commander-conssaver-symlink(5519) + + + MANDRAKE + MDKSA-2000:078 + + + BUGTRAQ + 20001113 Problems with cons.saver + + cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument. + + + + + + + + + + + + + + + + + + + + cpe:/a:midnight_commander:midnight_commander:4.5.46 + cpe:/a:midnight_commander:midnight_commander:4.5.45 + cpe:/a:midnight_commander:midnight_commander:4.5.44 + cpe:/a:midnight_commander:midnight_commander:4.5.43 + cpe:/a:midnight_commander:midnight_commander:4.5.42 + cpe:/a:midnight_commander:midnight_commander:4.5.41 + cpe:/a:midnight_commander:midnight_commander:4.5.40 + cpe:/a:midnight_commander:midnight_commander:4.5.49 + cpe:/a:midnight_commander:midnight_commander:4.5.50 + cpe:/a:midnight_commander:midnight_commander:4.5.48 + cpe:/a:midnight_commander:midnight_commander:4.5.51 + cpe:/a:midnight_commander:midnight_commander:4.5.47 + + CVE-2000-1109 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.527-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2016 + + + BUGTRAQ + 20001127 Midnight Commander + + + XF + midnight-commander-elevate-privileges(5929) + + + SUSE + SuSE-SA:2001:11 + + + DEBIAN + DSA-036 + + Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed. + + + + + + + + + cpe:/a:ibm:net.data:7.0 + + CVE-2000-1110 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.700-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2017 + + + BUGTRAQ + 20001128 IBM Net.Data Local Path Disclosure Vulnerability? + + document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2000-1111 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.857-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2018 + + + BUGTRAQ + 20001129 Windows 2000 Telnet Service DoS + + + XF + win2k-telnet-dos(5598) + + Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input. + + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2000-1112 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:40.997-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1976 + + + MS + MS00-090 + + + XF + mediaplayer-wms-script-exe + + Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. + + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2000-1113 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:41.153-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1980 + + + MS + MS00-090 + + + XF + mediaplayer-asx-bo + + + ATSTAKE + A112300-1 + + Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability. + + + + + + + + + + cpe:/a:unify:ewave_servletexec:3.0 + cpe:/a:unify:ewave_servletexec:3.0c + + CVE-2000-1114 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:41.293-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1970 + + + BUGTRAQ + 20001121 Disclosure of JSP source code with ServletExec AS v3.0c + web ins tance + + Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2000a_2000.0.1.32 + + CVE-2000-1115 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:41.450-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1979 + + + BUGTRAQ + 20001122 602Pro Lan Suite Web Admin Overflow + + + CONFIRM + http://www.software602.com/products/ls/support/newbuild.html + + + XF + software602-lan-suite-bo + + Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. + + + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:4.0 + cpe:/a:transsoft:broker_ftp_server:3.0 + cpe:/a:transsoft:broker_ftp_server:3.0_build_1 + + CVE-2000-1116 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:41.590-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + broker-ftp-username-dos + + + WIN2KSEC + 20001018 TransSoft's Broker FTP Server 3.x & 4.x Remote DoS attack Vulnerability + + Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command. + + + + + + + + + cpe:/a:ibm:lotus_notes:r5 + + CVE-2000-1117 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:39.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1994 + + + BUGTRAQ + 20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5 + + The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method. + + + + + + + + + cpe:/a:24link:24link:1.06 + + CVE-2000-1118 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:41.887-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001127 24Link Webserver + + 24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:ibm:aix:4.2.1 + + CVE-2000-1119 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.057-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2032 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + XF + aix-setsenv-bo(5621) + + + OSVDB + 1676 + + + AIXAPAR + IY10721 + + + AIXAPAR + IY08812 + + Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:ibm:aix:4.2.1 + + CVE-2000-1120 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.260-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2033 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + XF + aix-digest-bo(5620) + + + AIXAPAR + IY08287 + + + AIXAPAR + IY08143 + + Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:ibm:aix:4.2.1 + + CVE-2000-1121 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.403-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2034 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + XF + aix-enq-bo(5619) + + + AIXAPAR + IY08287 + + + AIXAPAR + IY08143 + + Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.2 + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:ibm:aix:4.2.1 + + CVE-2000-1122 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.573-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2035 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + AIXAPAR + IY07831 + + + AIXAPAR + IY07790 + + Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument. + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + + CVE-2000-1123 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.730-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2036 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + XF + aix-pioout-bo + + + AIXAPAR + IY12638 + + Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands. + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + + CVE-2000-1124 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:42.887-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2037 + + + BUGTRAQ + 20001201 Fixed local AIX V43 vulnerabilities + + + XF + aix-piobe-bo(5616) + + + AIXAPAR + IY12638 + + Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables. + + + + + + + + + + cpe:/o:redhat:linux:6.2e + cpe:/o:redhat:linux:6.2 + + CVE-2000-1125 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.043-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1914 + + + BUGTRAQ + 20001104 Redhat 6.2 restore exploit + + restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.4 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.24 + + CVE-2000-1126 + 2001-01-09T00:00:00.000-05:00 + 2009-03-04T00:06:50.297-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 1954 + + + HP + HPSBUX0011-130 + + + + + Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service. + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + + CVE-2000-1127 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.340-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1919 + + + BUGTRAQ + 20001108 HP-UX 10.20 resource monitor service + + registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable. + + + + + + + + + cpe:/a:mcafee:virusscan:4.5 + + CVE-2000-1128 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.480-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1920 + + + NTBUGTRAQ + 20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5 + + The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory. + + + + + + + + + cpe:/a:network_associates:webshield_smtp:4.5 + + CVE-2000-1129 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1999 + + + BUGTRAQ + 20001123 McAfee WebShield SMTP vulnerabilities + + McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. + + + + + + + + + cpe:/a:network_associates:webshield_smtp:4.5 + + CVE-2000-1130 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1993 + + + BUGTRAQ + 20001123 McAfee WebShield SMTP vulnerabilities + + McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment. + + + + + + + + + cpe:/a:bill_kendrick:gbook.cgi:1.0 + + CVE-2000-1131 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:43.917-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1940 + + + BUGTRAQ + 20001110 [hacksware] gbook.cgi remote command execution vulnerability + + + XF + gbook-cgi-remote-execution + + Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable. + + + + + + + + + + + + + + cpe:/a:dcscripts:dcforum:3.0 + cpe:/a:dcscripts:dcforum:1.0 + cpe:/a:dcscripts:dcforum:5.0 + cpe:/a:dcscripts:dcforum:2.0 + cpe:/a:dcscripts:dcforum:4.0 + cpe:/a:dcscripts:dcforum:6.0 + + CVE-2000-1132 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:44.057-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1951 + + + BUGTRAQ + 20001114 Cgisecurity.com advisory on dcforum + + + CONFIRM + http://www.dcscripts.com/dcforum/dcfNews/124.html#1 + + + XF + dcforum-cgi-view-files(5533) + + + OSVDB + 1646 + + DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. + + + + + + + + + cpe:/a:flicks_software:authentix:5.1c + + CVE-2000-1133 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:44.213-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1907 + + + BUGTRAQ + 20001107 Explanation Authentix Input Validation Error + + + BUGTRAQ + 20001106 Authentix Security Advisory + + Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux + cpe:/o:suse:suse_linux:7.0 + cpe:/o:redhat:linux:6.2e + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:conectiva:linux:4.0es + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:conectiva:linux:4.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:redhat:linux:6.0 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/a:immunix:immunix:6.2 + + CVE-2000-1134 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:40.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#10277 + + + BID + 2006 + + + FREEBSD + FreeBSD-SA-00:76 + + + BID + 1926 + + + BUGTRAQ + 20001128 /bin/sh creates insecure tmp files + + + REDHAT + RHSA-2000:121 + + + REDHAT + RHSA-2000:117 + + + MANDRAKE + MDKSA-2000:075 + + + MANDRAKE + MDKSA-2000-069 + + + DEBIAN + 20001111a + + + CALDERA + CSSA-2000-043.0 + + + CALDERA + CSSA-2000-042.0 + + + BUGTRAQ + 20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MORE + + + CONECTIVA + CLSA-2000:354 + + + CONECTIVA + CLA-2000:350 + + + COMPAQ + SSRT1-41U + + + BUGTRAQ + 20001028 tcsh: unsafe tempfile in << redirects + + + SGI + 20011103-02-P + + + + + Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. + + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + cpe:/o:debian:debian_linux:2.2 + + CVE-2000-1135 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:44.590-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + 20001130 DSA-002-1 fsh: symlink attack + + + XF + linux-fsh-symlink(5633) + + + OSVDB + 7208 + + fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack. + + + + + + + + + cpe:/a:debian:elvis_tiny:1.4.9 + + CVE-2000-1136 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:44.730-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1984 + + + BUGTRAQ + 20001122 New version of elvis-tiny released + + + XF + linux-tinyelvis-tmpfiles + + elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack. + + + + + + + + + + + + cpe:/a:gnu:ed:2.15 + cpe:/a:gnu:ed:2.16tr + cpe:/a:gnu:ed:2.18 + cpe:/a:gnu:ed:2.18.0 + + CVE-2000-1137 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:41.210-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2000:123 + + + XF + gnu-ed-symlink(5723) + + + OSVDB + 6491 + + + MANDRAKE + MDKSA-2000:076 + + + DEBIAN + 20001129 DSA-001-1 ed: symlink attack + + + CONECTIVA + CLA-2000:359-2 + + GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack. + + + + + + + + + + + + + + cpe:/a:ibm:lotus_notes:5.0.2 + cpe:/a:ibm:lotus_notes:5.0.3 + cpe:/a:ibm:lotus_notes:5.0.4 + cpe:/a:ibm:lotus_notes:5.0.5 + cpe:/a:ibm:lotus_notes:5.0.1 + cpe:/a:ibm:lotus_notes:5.0 + + CVE-2000-1138 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.027-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1925 + + + BUGTRAQ + 20001108 Lotus Notes R5 clients - no warning for broken signature or encryption + + Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected. + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + + CVE-2000-1139 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.183-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1958 + + + MS + MS00-088 + + + XF + ms-exchange-username-pwd(5537) + + The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1140 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.340-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1908 + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + + XF + mantrap-hidden-processes + + Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1141 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.480-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + XF + mantrap-hidden-processes + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1142 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.620-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + XF + mantrap-pwd-reveal-information + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1143 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.760-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + + XF + mantrap-hidden-processes + + Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1144 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:45.917-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1909 + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + XF + mantrap-inode-disclosure + + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1145 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:46.057-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + XF + mantrap-identify-processes + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files. + + + + + + + + + cpe:/a:recourse_technologies:mantrap:1.6.1 + + CVE-2000-1146 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:46.200-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1913 + + + BUGTRAQ + 20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs + + + XF + mantrap-dir-dos + + + BUGTRAQ + 20001105 Mantrap Advisory Vendor Followup - Fate Research Labs + + + BUGTRAQ + 20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00) + + Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2000-1147 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:46.357-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1911 + + + BUGTRAQ + 20001103 IIS ASP $19.95 hack - IISHack 1.5 + + + XF + iis-isapi-asp-bo + + Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. + + + + + + + + + cpe:/a:volano_llc:volanochatpro:2.1 + + CVE-2000-1148 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:46.497-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1906 + + + BUGTRAQ + 20001106 Re: FW: Filesystem Access + VolanoChat = VChat admin (fwd) + + + BUGTRAQ + 20001104 Filesystem Access + VolanoChat = VChat admin (fwd) + + + XF + volanochatpro-plaintext-password + + The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server. + + + + + + + + + cpe:/o:microsoft:windows_nt:terminal_server + + CVE-2000-1149 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:46.637-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1924 + + + BUGTRAQ + 20001108 [CORE SDI ADVISORY] MS NT4.0 Terminal Server Edition GINA buffer overflow + + + MS + MS00-087 + + + XF + nt-termserv-gina-bo + + Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability. + + + + + + + + + cpe:/a:xavier_ducrohet:felix:2.3 + + CVE-2000-1150 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:42.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. + + + + + + + + + + cpe:/a:abisoft:baxter:y + cpe:/a:abisoft:baxter:x + + CVE-2000-1151 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:42.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. + + + + + + + + + + cpe:/o:be:beos:5 + cpe:/o:be:beos:4.5 + + CVE-2000-1152 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:47.073-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. + + + + + + + + + cpe:/a:kenny_carruthers:postmaster:1.0 + + CVE-2000-1153 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:43.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. + + + + + + + + + cpe:/a:joe_kloss:robinhood:1.1 + + CVE-2000-1154 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:43.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request. + + + + + + + + + cpe:/a:joe_kloss:robinhood:1.1 + + CVE-2000-1155 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:43.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001113 beos vulnerabilities + + RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request. + + + + + + + + + cpe:/a:sun:staroffice:5.2 + + CVE-2000-1156 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:47.667-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1922 + + + XF + staroffice-tmp-sym-link + + + BUGTRAQ + 20001108 StarOffice 5.2 Temporary Dir Vulnerability + + StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice. + + + + + + + + + cpe:/a:network_associates:sniffer_agent:3.0.10 + + CVE-2000-1157 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:47.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1901 + + + BUGTRAQ + 20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent + + Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name. + + + + + + + + + cpe:/a:network_associates:sniffer_agent:3.0.10 + + CVE-2000-1158 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:47.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent + + NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords. + + + + + + + + + cpe:/a:network_associates:sniffer_agent:3.0.10 + + CVE-2000-1159 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.090-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1902 + + + BUGTRAQ + 20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent + + NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands. + + + + + + + + + cpe:/a:network_associates:sniffer_agent:3.0.10 + + CVE-2000-1160 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1903 + + + BUGTRAQ + 20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent + + NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests. + + + + + + + + + cpe:/a:adcycle:adcycle:0.77b + + CVE-2000-1161 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.387-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1969 + + + BUGTRAQ + 20001120 security problem in AdCycle installation + + The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases. + + + + + + + + + + + + cpe:/a:aladdin_enterprises:ghostscript:5.10.10 + cpe:/a:aladdin_enterprises:ghostscript:5.50 + cpe:/a:aladdin_enterprises:ghostscript:4.3 + cpe:/a:aladdin_enterprises:ghostscript:5.10.15 + + CVE-2000-1162 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.543-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1990 + + + CALDERA + CSSA-2000-041 + + + XF + ghostscript-sym-link + + + REDHAT + RHSA-2000:114 + + + MANDRAKE + MDKSA-2000:074 + + + DEBIAN + 20001123 ghostscript: symlink attack + + + CONECTIVA + CLSA-2000:343 + + ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack. + + + + + + + + + + + + + cpe:/a:aladdin_enterprises:ghostscript:5.10.10 + cpe:/a:aladdin_enterprises:ghostscript:5.50 + cpe:/a:aladdin_enterprises:ghostscript:4.3 + cpe:/a:aladdin_enterprises:ghostscript:5.10cl + cpe:/a:aladdin_enterprises:ghostscript:5.10.15 + + CVE-2000-1163 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.683-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1991 + + + DEBIAN + 20001123 ghostscript: symlink attack + + + XF + ghostscript-env-variable + + + MANDRAKE + MDKSA-2000:074 + + + CALDERA + CSSA-2000-041 + + + CONECTIVA + CLSA-2000:343 + + ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript. + + + + + + + + + + cpe:/a:att:winvnc:3.3.3 + cpe:/a:att:winvnc:3.3.3r7 + + CVE-2000-1164 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:48.840-04:00 + + + 9.0 + NETWORK + LOW + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1961 + + + BUGTRAQ + 20001118 WinVNC 3.3.x + + + XF + winvnc-modify-registry(5545) + + WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system. + + + + + + + + + + + cpe:/a:balabit:syslog-ng:1.4.6 + cpe:/a:balabit:syslog-ng:1.4.8 + cpe:/a:balabit:syslog-ng:1.4.7 + + CVE-2000-1165 + 2001-01-09T00:00:00.000-05:00 + 2011-02-04T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1981 + + + BUGTRAQ + 20001122 DoS possibility in syslog-ng + + + XF + balabit-syslog-ng-dos(5576) + + + CONFIRM + http://www.balabit.hu/products/syslog-ng/ + + + FREEBSD + FreeBSD-SA-01:02 + + Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier. + + + + + + + + + cpe:/a:twig_development_team:twig:2.5.1 + + CVE-2000-1166 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.137-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 1998 + + + CONFIRM + http://twig.screwdriver.net/file.php3?file=CHANGELOG + + + BUGTRAQ + 20001124 Security problems with TWIG webmail system + + + XF + twig-php3-script-execute(5581) + + Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2000-1167 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1974 + + + XF + freebsd-ppp-bypass-gateway(5584) + + + OSVDB + 1655 + + + FREEBSD + FreeBSD-SA-00:70 + + ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system. + + + + + + + + + cpe:/a:ibm:http_server:1.3.6.3 + + CVE-2000-1168 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001123 IBM HTTP Server 1.3.6 Remote Overflow + + + BID + 1988 + + IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:openbsd:openssh:2.2 + + CVE-2000-1169 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.590-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1949 + + + BUGTRAQ + 20001123 OpenSSH Security Advisory (adv.fwd) + + + XF + openssh-unauthorized-access(5517) + + + REDHAT + RHSA-2000:111 + + + OSVDB + 6248 + + + OSVDB + 2114 + + + MANDRAKE + MDKSA-2000:068 + + + DEBIAN + 20001118 openssh: possible remote exploit + + + SUSE + SuSE-SA:2000:47 + + + CONECTIVA + CLSA-2000:345 + + + BUGTRAQ + 20001115 Trustix Security Advisory - bind and openssh (and modutils) + + OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent. + + + + + + + + + cpe:/a:pelesoft:netsnap:1.2 + + CVE-2000-1170 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.730-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1956 + + + BUGTRAQ + 20001115 Netsnap Webcam Software Remote Overflow + + + CONFIRM + http://www.netsnap.com/new.htm + + + XF + netsnap-remote-bo(5534) + + Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request. + + + + + + + + + cpe:/a:markus_triska:cgiforum:1.0 + + CVE-2000-1171 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:49.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1963 + + + BUGTRAQ + 20001120 CGIForum 1.0 Vulnerability + + + XF + cgiforum-view-files(5553) + + Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter. + + + + + + + + + + cpe:/a:rob_flynn:gaim:0.10 + cpe:/a:rob_flynn:gaim:0.10.3 + + CVE-2000-1172 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.027-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1948 + + + BUGTRAQ + 20001110 Advisory: Gaim remote vulnerability + + Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag. + + + + + + + + + + cpe:/a:microsys:cyberpatrol:4.04.005 + cpe:/a:microsys:cyberpatrol:4.04.003 + + CVE-2000-1173 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1977 + + + BUGTRAQ + 20001122 CyberPatrol - poor credit card protection + + Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information. + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.8.13 + + CVE-2000-1174 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.323-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1972 + + + XF + ethereal-afs-bo(5557) + + + REDHAT + RHSA-2000:116 + + + DEBIAN + 20001121 ethereal: remote exploit + + + CONECTIVA + CLSA-2000:342 + + + BUGTRAQ + 20001118 [hacksware] Ethereal 0.8.13 AFS ACL parsing buffer overflow bug + + + FREEBSD + FreeBSD-SA-00:81 + + Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username. + + + + + + + + + cpe:/a:jan_hubicka:koules:1.4 + + CVE-2000-1175 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.463-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 1967 + + + BUGTRAQ + 20001120 local exploit for linux's Koules1.4 package + + Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument. + + + + + + + + + cpe:/a:yabb:yabb:2000-09-11 + + CVE-2000-1176 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1921 + + + BUGTRAQ + 20001107 Insecure input balidation in YaBB Search.pl + + Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field. + + + + + + + + + cpe:/a:bb4:big_brother_network_monitor:1.5d2 + + CVE-2000-1177 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.760-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1971 + + + BUGTRAQ + 20001121 Big Brother Advisory - Fate Research Labs + + + CONFIRM + http://bb4.com/incident.nov21 + + bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter. + + + + + + + + + cpe:/a:joseph_allen:joe:2.8 + + CVE-2000-1178 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:50.900-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1959 + + + BUGTRAQ + 20001116 Joe's Own Editor File Link Vulnerability + + + XF + joe-symlink-corruption(5546) + + + REDHAT + RHSA-2000:110 + + + MANDRAKE + MDKSA-2000:072 + + + DEBIAN + 20001201 DSA-003-1 joe: symlink attack + + + BUGTRAQ + 20001121 Immunix OS Security update for joe + + + CONECTIVA + CLA-2000:356 + + Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes. + + + + + + + + + cpe:/h:netopia:650-st_isdn_router:3.3.2_firmware + + CVE-2000-1179 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1952 + + + BUGTRAQ + 20001115 Netopia ISDN Router 650-ST: Viewing of all system logs without login + + + XF + netopia-view-system-log(5536) + + Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.5 + + CVE-2000-1180 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.183-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 1968 + + + XF + oracle-cmctl-bo(5551) + + + BUGTRAQ + 20001120 vulnerability in Connection Manager Control binary in Oracle + + Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument. + + + + + + + + + + + cpe:/a:realnetworks:realserver:5.0 + cpe:/a:realnetworks:realserver:6.0 + cpe:/a:realnetworks:realserver:7.0 + + CVE-2000-1181 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1957 + + + BUGTRAQ + 20001116 [CORE SDI ADVISORY] RealServer memory contents disclosure + + + CONFIRM + http://service.real.com/help/faq/security/memory.html + + + XF + realserver-gain-access(5538) + + Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL. + + + + + + + + + + cpe:/h:watchguard:firebox_ii:4.5 + cpe:/h:watchguard:firebox_ii:4.1 + + CVE-2000-1182 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.480-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1953 + + + BUGTRAQ + 20001116 Possible Watchguard Firebox II DoS + + + CONFIRM + https://www.watchguard.com/support/patches.html + + + XF + watchguard-firebox-ftp-dos(5535) + + WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling. + + + + + + + + + cpe:/a:nec:socks_5:1.0r5 + + CVE-2000-1183 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:46.397-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001115 socks5 remote exploit / linux x86 + + Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:3.5.1:stable + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + + CVE-2000-1184 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.777-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-00:69 + + + XF + telnetd-termcap-dos(5959) + + + OSVDB + 6083 + + telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file. + + + + + + + + + cpe:/a:itserv_incorporated:ridewaypn:6.22 + + CVE-2000-1185 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:51.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1938 + + + BUGTRAQ + 20001113 Rideway PN Telnet DoS + + The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests. + + + + + + + + + cpe:/a:phf:phf + + CVE-2000-1186 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:52.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001115 Exploit: phf buffer overflow (CGI) + + + XF + phf-cgi-bo(5970) + + Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header. + + + + + + + + + + cpe:/a:netscape:navigator:4.75 + cpe:/a:netscape:communicator:4.75 + + CVE-2000-1187 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:52.260-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2000:109 + + + FREEBSD + FreeBSD-SA-00:66 + + + XF + netscape-client-html-bo + + + OSVDB + 7207 + + + BUGTRAQ + 20001121 Immunix OS Security update for netscape + + + SUSE + SuSE-SA:2000:48 + + + CONECTIVA + CLSA-2000:344 + + Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. + + + + + + + + + + + cpe:/a:i-soft:quikstore:2.0 + cpe:/a:i-soft:quikstore:2.9.5 + cpe:/a:i-soft:quikstore:2.9.10 + + CVE-2000-1188 + 2001-01-09T00:00:00.000-05:00 + 2008-09-10T15:06:46.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001120 Cgisecurity Quickstore Shopping cart + + Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter. + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.1::i386 + + CVE-2000-1189 + 2001-01-09T00:00:00.000-05:00 + 2008-09-05T16:22:52.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2000:120 + + + XF + pam-localuser-bo(5747) + + + MANDRAKE + MDKSA-2000:082-1 + + + CONECTIVA + CLA-2000:358 + + Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges. + + + + + + + + + cpe:/a:jon_atkins:imwheel + + CVE-2000-1190 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:06:47.397-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2000:016 + + + XF + linux-imwheel-symlink(4941) + + + BUGTRAQ + 20000531 Re: strike#2 + + imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file. + + + CVE-2000-1191 + 2001-08-31T00:00:00.000-04:00 + 2010-08-21T00:05:12.343-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MISC + http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html + + + XF + htdig-htsearch-path-disclosure(7367) + + + BID + 4366 + + + + + htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path. + + + + + + + + + cpe:/a:btt_software:snmp_trap_watcher:1.16 + + CVE-2000-1192 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:06:47.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html + + + BID + 985 + + + MISC + http://www.bttsoftware.co.uk/snmptrap.html + + Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap. + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + + CVE-2000-1193 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:53.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + irix-pcp-pmcd-dos(4284) + + + BUGTRAQ + 20000412 Performance Copilot for IRIX 6.5 + + + SGI + 20020407-01-I + + Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port. + + + + + + + + + cpe:/a:argosoft:ftp_server:1.0 + + CVE-2000-1194 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:53.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1227 + + + MISC + http://www.mdma.za.net/fk/FK9.zip + + Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands. + + + + + + + + + + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/o:caldera:openlinux_edesktop:2.3 + + CVE-2000-1195 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:53.433-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2000-008.0 + + + XF + telnetd-login-bypass(4225) + + telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option. + + + + + + + + + cpe:/a:netscape:publishingxpert:2.5 + + CVE-2000-1196 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:53.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html + + + MISC + http://packetstormsecurity.org/0004-exploits/ooo1.txt + + + XF + publishingxpert-pscoerrpage-url(7362) + + PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter. + + + + + + + + + cpe:/a:university_of_washington:imap:4.5 + + CVE-2000-1197 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:06:50.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1132 + + + BUGTRAQ + 20000420 pop3d/imap DOS (while we're on the subject) + + + FREEBSD + FreeBSD-SA-00:15 + + POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes. + + + + + + + + + + cpe:/a:qualcomm:qpopper:2.53 + cpe:/a:qualcomm:qpopper:3.0 + + CVE-2000-1198 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:06:50.820-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 1132 + + + BUGTRAQ + 20000420 pop3 + + + BUGTRAQ + 20000420 pop3d/imap DOS (while we're on the subject) + + qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + + CVE-2000-1199 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:54.010-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + postgresql-plaintext-passwords(4364) + + + BID + 1139 + + + BUGTRAQ + 20000423 Postgresql cleartext password storage + + PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases. + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2000-1200 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:54.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nt-lsa-domain-sid(4015) + + + BID + 959 + + + BUGTRAQ + 20000201 Windows NT and account list leak ! A new SID usage + + Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. + + + + + + + + + cpe:/a:checkpoint:firewall-1 + + CVE-2000-1201 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:54.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20000707 Re: CheckPoint FW1 BUG + + Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264. + + + + + + + + + cpe:/a:ibm:http_server_ssl_module_common:1.0 + + CVE-2000-1202 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:22:54.463-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ibm-ikeyman(4235) + + + BID + 1092 + + + BUGTRAQ + 20000405 minor issue with IBM HTTPD and /usr/bin/ikeyman + + ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class. + + + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:4.6.1 + cpe:/a:lotus:domino:5.0.5 + cpe:/a:lotus:domino:5.0.4 + cpe:/a:lotus:domino:5.0.7 + cpe:/a:lotus:domino:4.6.3 + cpe:/a:lotus:domino:5.0.6 + cpe:/a:lotus:domino:4.6.4 + cpe:/a:lotus:domino:5.0.1 + cpe:/a:lotus:domino:5.0.3 + cpe:/a:lotus:domino:5.0.2 + + CVE-2000-1203 + 2001-08-20T00:00:00.000-04:00 + 2008-09-05T16:22:54.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3212 + + + XF + lotus-domino-bounced-message-dos(7012) + + + VULN-DEV + 20000520 Infinite loop in LOTUS NOTE 5.0.3. SMTP SERVER + + + BUGTRAQ + 20010820 Lotus Domino DoS + + + BUGTRAQ + 20010823 Lotus Domino DoS solution + + Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop. + + + + + + + + + + + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.12 + + CVE-2000-1204 + 2000-10-13T00:00:00.000-04:00 + 2008-09-05T16:22:54.777-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.apacheweek.com/issues/00-10-13 + + Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root. + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.10 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3.8 + cpe:/a:apache:http_server:1.3.6 + cpe:/a:apache:http_server:1.3.7 + cpe:/a:apache:http_server:1.3.4 + cpe:/a:apache:http_server:1.3.5 + cpe:/a:apache:http_server:1.3.2 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.0 + cpe:/a:apache:http_server:1.3.1 + + CVE-2000-1205 + 2000-02-01T00:00:00.000-05:00 + 2008-09-05T16:22:54.933-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CONFIRM + http://httpd.apache.org/info/css-security/apache_specific.html + + + XF + apache-printenv-acuparam-xss(35597) + + + XF + apache-printenv-xss(10938) + + + BUGTRAQ + 20070724 printenv.pl(all versions) cross site scripting Vulnerability + + + BUGTRAQ + 20021222 'printenv' XSS vulnerability + + + BUGTRAQ + 20021223 Re: 'printenv' XSS vulnerability + + Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant. + + + + + + + + + + cpe:/a:apache:http_server:1.3.10 + cpe:/a:apache:http_server:1.3.9 + + CVE-2000-1206 + 1999-08-20T00:00:00.000-04:00 + 2008-09-10T15:06:52.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.apacheweek.com/issues/00-01-07#status + + Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. + + + + + + + + + cpe:/o:redhat:linux + + CVE-2000-1207 + 2000-09-30T00:00:00.000-04:00 + 2008-09-05T16:22:55.247-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2000:075 + + + MANDRAKE + MDKSA-2000:059 + + + BUGTRAQ + 20000930 glibc and userhelper - local root + + + BUGTRAQ + 20001003 SuSE: userhelper/usermode + + userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844). + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4 + cpe:/a:immunix:immunix:6.2 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:redhat:linux:7.0 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2000-1208 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:06:53.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2000:066 + + + XF + lpr-checkremote-format-string(5286) + + + BID + 1711 + + + BUGTRAQ + 20001004 Immunix OS Security Update for lpr + + + BUGTRAQ + 20000925 Format strings: bug #1: BSD-lpr + + Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call. + + + + + + + + + + + + + + + + + + cpe:/a:compaq:insight_manager_xe:1.21 + cpe:/a:microsoft:msde:2000 + cpe:/a:compaq:insight_manager:7.0 + cpe:/a:compaq:insight_manager_xe:2.1b + cpe:/a:compaq:insight_manager_xe:2.1c + cpe:/a:compaq:insight_manager:7.0:sp1 + cpe:/a:compaq:insight_manager_xe:1.1 + cpe:/a:microsoft:data_engine:1.0 + cpe:/a:compaq:insight_manager_xe:2.2 + cpe:/a:compaq:insight_manager_xe:2.1 + + CVE-2000-1209 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:06:53.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#635463 + + + XF + mssql-no-sapassword(1459) + + + CONFIRM + http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp + + + MSKB + Q321081 + + + MSKB + Q313418 + + + BUGTRAQ + 20000815 MS-SQL 'sa' user exploit code + + + BID + 4797 + + + OSVDB + 3570 + + + BUGTRAQ + 20020522 Opty-Way Enterprise includes MSDE with sa <blank> + + + BUGTRAQ + 20000816 Released Patch: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password + + + BUGTRAQ + 20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password + + + BUGTRAQ + 20000710 MSDE / Re: Default Password Database + + The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida. + + + + + + + + + cpe:/a:apache:tomcat:3.1 + + CVE-2000-1210 + 2002-03-22T00:00:00.000-05:00 + 2008-09-05T16:22:55.713-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + apache-tomcat-file-contents(4205) + + + BUGTRAQ + 20000322 Security bug in Apache project: Jakarta Tomcat + + Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp. + + + + + + + + + + + + + + + + + + + cpe:/a:zope:zope:2.2.4 + cpe:/a:zope:zope:2.2.1b1 + cpe:/a:zope:zope:2.2.1 + cpe:/a:zope:zope:2.2.0a1 + cpe:/a:zope:zope:2.2.0b1 + cpe:/a:zope:zope:2.2.0 + cpe:/a:zope:zope:2.2.3 + cpe:/a:zope:zope:2.2.2 + cpe:/a:zope:zope:2.2.0b4 + cpe:/a:zope:zope:2.2.0b2 + cpe:/a:zope:zope:2.2.0b3 + + CVE-2000-1211 + 2000-12-16T00:00:00.000-05:00 + 2008-09-05T16:22:55.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert + + + MANDRAKE + MDKSA-2000:083 + + + REDHAT + RHSA-2000:125 + + + OSVDB + 6282 + + + XF + zope-legacy-names(5824) + + Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities. + + + + + + + + + + + + + + + + + + + cpe:/a:zope:zope:2.2.4 + cpe:/a:zope:zope:2.2.1b1 + cpe:/a:zope:zope:2.2.1 + cpe:/a:zope:zope:2.2.0a1 + cpe:/a:zope:zope:2.2.0b1 + cpe:/a:zope:zope:2.2.0 + cpe:/a:zope:zope:2.2.3 + cpe:/a:zope:zope:2.2.2 + cpe:/a:zope:zope:2.2.0b4 + cpe:/a:zope:zope:2.2.0b2 + cpe:/a:zope:zope:2.2.0b3 + + CVE-2000-1212 + 2000-12-18T00:00:00.000-05:00 + 2008-09-10T15:06:53.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert + + + XF + zope-image-file(5778) + + + REDHAT + RHSA-2000:135 + + + OSVDB + 6283 + + + DEBIAN + DSA-007 + + + MANDRAKE + MDKSA-2000:086 + + + CONECTIVA + CLA-2000:365 + + Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects. + + + + + + + + + + + + + + + + + + cpe:/a:iputils:iputils:2000-10-10 + cpe:/a:immunix:immunix:6.2 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0 + + CVE-2000-1213 + 2000-10-18T00:00:00.000-04:00 + 2008-09-10T15:06:53.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2000:087 + + + BUGTRAQ + 20001025 Immunix OS Security Update for ping package + + + BUGTRAQ + 20001030 Trustix Security Advisory - ping gnupg ypbind + + ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges. + + + + + + + + + + + + + + + + + + cpe:/a:iputils:iputils:2000-10-10 + cpe:/a:immunix:immunix:6.2 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0 + + CVE-2000-1214 + 2000-10-18T00:00:00.000-04:00 + 2008-09-10T15:06:53.587-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2000:087 + + + XF + ping-buf-bo(5431) + + + BUGTRAQ + 20001025 Immunix OS Security Update for ping package + + + BID + 1813 + + + BUGTRAQ + 20001020 Re: [RHSA-2000:087-02] Potential security problems in ping fixed. + + + BUGTRAQ + 20001030 Trustix Security Advisory - ping gnupg ypbind + + Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges. + + + + + + + + + cpe:/a:ibm:lotus_domino:5.0.8 + + CVE-2000-1215 + 2001-09-19T00:00:00.000-04:00 + 2008-09-10T15:06:53.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#984555 + + + XF + lotus-domino-information-disclosure(10685) + + + CONFIRM + http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&Highlight=0,AWHN4A8QWM + + + BUGTRAQ + 20010919 lotus domino server 5.08 is very gabby + + The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information. + + + CVE-2000-1216 + 2000-01-27T00:00:00.000-05:00 + 2005-10-20T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#433499 + + + XF + aix-portmir-echoerror-bo(7929) + + + AIXAPAR + IY07832 + + Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine. + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2000-1217 + 2000-11-21T00:00:00.000-05:00 + 2008-09-05T16:22:56.747-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#818496 + + + XF + win2k-brute-force(5585) + + + BID + 1973 + + + MS + MS00-089 + + Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::sp2:media_center + cpe:/o:microsoft:windows_xp::sp1:media_center + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp5:alpha + cpe:/o:microsoft:windows_nt:4.0:sp6a + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp6:alpha + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp4:professional + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0:sp3:alpha + cpe:/o:microsoft:windows_xp:::media_center + cpe:/o:microsoft:windows_nt:4.0:sp4:alpha + cpe:/o:microsoft:windows_nt:4.0:sp1:alpha + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_nt:4.0:sp2:alpha + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha + cpe:/o:microsoft:windows_nt:4.0::alpha + cpe:/o:microsoft:windows_xp::sp2:home + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2000-1218 + 2000-04-14T00:00:00.000-04:00 + 2008-09-05T16:22:56.900-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#458659 + + + XF + win2k-dns-resolver(4280) + + The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache. + + + + + + + + + + cpe:/a:gnu:gcc:3.3.3 + cpe:/a:gnu:g%2b%2b:3.3.3 + + CVE-2000-1219 + 2000-11-01T00:00:00.000-05:00 + 2008-09-05T16:22:57.120-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#540517 + + + MLIST + [gcc-bugs] 20020506 c/6586: -ftrapv doesn't catch multiplication overflow + + The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:redhat:linux:6.1::i386 + cpe:/o:sgi:irix:6.5.17m + cpe:/o:sgi:irix:6.5.15f + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.18f + cpe:/o:sgi:irix:6.5.16f + cpe:/o:sgi:irix:6.5.18m + cpe:/o:redhat:linux:4.0 + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + cpe:/o:sgi:irix:6.5.16m + + CVE-2000-1220 + 2000-01-08T00:00:00.000-05:00 + 2011-03-07T21:04:27.297-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#39001 + + + XF + redhat-lpd-print-control(3841) + + + BID + 927 + + + REDHAT + RHSA-2000:002 + + + DEBIAN + DSA-20000109 + + + L0PHT + 20000108 Quadruple Inverted Backflip + + + BUGTRAQ + 20000108 L0pht Advisory: LPD, RH 4.x,5.x,6.x + + + SGI + 20021104-01-P + + The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:redhat:linux:6.1::i386 + cpe:/o:sgi:irix:6.5.17m + cpe:/o:sgi:irix:6.5.15f + cpe:/o:redhat:linux:5.2::i386 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:5.0 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.18f + cpe:/o:debian:debian_linux:2.1 + cpe:/o:sgi:irix:6.5.16f + cpe:/o:sgi:irix:6.5.18m + cpe:/o:redhat:linux:4.1 + cpe:/o:redhat:linux:4.2 + cpe:/o:sgi:irix:6.5.16m + + CVE-2000-1221 + 2000-01-08T00:00:00.000-05:00 + 2009-02-28T00:10:48.843-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#30308 + + + DEBIAN + 20000109 lpr -- access control problem and root exploit + + + SGI + 20021104-01-P + + + XF + redhat-lpd-auth(3840) + + + BID + 927 + + + ATSTAKE + A010800-v + + + REDHAT + RHSA-2000:002 + + The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP. + + + + + + + + + cpe:/o:ibm:aix:4.2.1.12 + + CVE-2000-1222 + 2000-12-10T00:00:00.000-05:00 + 2008-09-05T16:22:57.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#17566 + + + XF + aix-sysback-elevate-privileges(6432) + + AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program. + + + + + + + + + cpe:/a:i-soft:quikstore + + CVE-2000-1223 + 2000-11-20T00:00:00.000-05:00 + 2008-09-05T16:22:57.840-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#671444 + + quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request. + + + + + + + + + + cpe:/a:caucho_technology:resin:1.1.5 + cpe:/a:caucho_technology:resin:1.2 + + CVE-2000-1224 + 2000-11-23T00:00:00.000-05:00 + 2008-09-05T16:22:57.980-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-20T09:32:00.000-04:00 + + + + XF + resin-jsp-source-disclosure(5568) + + + BID + 1986 + + + BUGTRAQ + 20001123 Re: RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k)) + + + BUGTRAQ + 20001123 RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k)) + + Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others. + + + + + + + + + cpe:/a:imatix:xitami:2.5_b + + CVE-2000-1225 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.137-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-24T08:01:00.000-04:00 + + + + MISC + http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html + + Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program. + + + + + + + + + cpe:/a:snort:snort:1.6 + + CVE-2000-1226 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.277-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-10-03T09:21:00.000-04:00 + + + + BUGTRAQ + 20000614 Re: Snort 1.6 and nmap 2.54beta1 + + + BUGTRAQ + 20000614 Snort 1.6 and nmap 2.54beta1 + + Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2000-1227 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-10-03T09:27:00.000-04:00 + + + + BID + 1301 + + Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1228 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-10-03T09:33:00.000-04:00 + + + + BID + 2271 + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1229 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.793-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-03T09:39:00.000-04:00 + + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1230 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:58.933-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-03T09:43:00.000-04:00 + + + + MISC + http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + + BID + 2274 + + Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman". + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1231 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.073-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-03T09:48:00.000-04:00 + + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1232 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.230-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-10-03T09:52:00.000-04:00 + + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1233 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.370-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-10-04T08:03:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter. + + + + + + + + + cpe:/a:phorum:phorum:3.0.7 + + CVE-2000-1234 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.510-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-10-04T08:08:00.000-04:00 + + + + BID + 2272 + + + BUGTRAQ + 20000106 Phorum 3.0.7 exploits and IDS signatures + + violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters. + + + + + + + + + cpe:/a:oracle:application_server:3.0.7 + + CVE-2000-1235 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.667-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-04T08:15:00.000-04:00 + + + + BID + 2150 + + + XF + oracle-webdb-admin-access(5818) + + + BUGTRAQ + 20001223 Potential Vulnerabilities in Oracle Internet Application Server + + + BUGTRAQ + 20001221 Re: Oracle WebDb engine brain-damagse + + + BUGTRAQ + 20001219 Oracle WebDb engine brain-damagse + + The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files. + + + + + + + + + cpe:/a:oracle:application_server:3.0.7 + + CVE-2000-1236 + 2000-12-31T00:00:00.000-05:00 + 2008-09-10T15:06:56.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-10-04T08:27:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2150 + + + XF + oracle-execute-plsql(5817) + + + BUGTRAQ + 20001223 Potential Vulnerabilities in Oracle Internet Application Server + + + BUGTRAQ + 20001221 Re: Oracle WebDb engine brain-damagse + + + BUGTRAQ + 20001219 Oracle WebDb engine brain-damagse + + SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL. + + + + + + + + + cpe:/a:floosietek:ftgate + + CVE-2000-1237 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:22:59.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-04T08:32:00.000-04:00 + + + + XF + ftgate-invalid-user-requests(4793) + + + BUGTRAQ + 20000626 Problems with FTGate + + The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:5.1:sp2:express + cpe:/a:bea:weblogic_server:5.1:sp4 + cpe:/a:bea:weblogic_server:5.1:sp3 + cpe:/a:bea:weblogic_server:5.1:sp3:express + cpe:/a:bea:weblogic_server:5.1:sp2 + cpe:/a:bea:weblogic_server:5.1:sp4:express + cpe:/a:bea:weblogic_server:5.1:sp1 + cpe:/a:bea:weblogic_server:5.1:sp1:express + cpe:/a:bea:weblogic_server:5.1:sp5:express + cpe:/a:bea:weblogic_server:5.1 + cpe:/a:bea:weblogic_server:5.1:sp5 + cpe:/a:bea:weblogic_server:5.1:sp6 + cpe:/a:bea:weblogic_server:5.1:sp6:express + cpe:/a:bea:weblogic_server:5.1::express + + CVE-2000-1238 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:00.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-05-01T16:25:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + weblogic-bypass-auth(5588) + + + BID + 5089 + + + CONFIRM + ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip + + BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. + + + + + + + + + cpe:/a:ibm:tivoli_management_framework:3.7.1 + + CVE-2000-1239 + 2000-03-13T00:00:00.000-05:00 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:00.293-04:00 + + + 9.0 + NETWORK + LOW + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-05-01T16:30:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + tivoli-lcf-file-read(3927) + + + BID + 17085 + + The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files. + + + + + + + + + cpe:/a:anyportal_php:anyportal_php:2000-04-18 + + CVE-2000-1240 + 2000-04-22T00:00:00.000-04:00 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:00.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-05-01T16:33:00.000-04:00 + + + + XF + anyportalphp-siteman-information-disclosure(25441) + + + OSVDB + 23983 + + Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the details are obtained from third party information. + + + + + + + + + cpe:/a:sips:sips + + CVE-2000-1241 + 2000-12-31T00:00:00.000-05:00 + 2009-10-14T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-09-22T12:35:00.000-04:00 + + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=25971 + + Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault." + + + + + + + + + cpe:/a:apc:powerchute + + CVE-2000-1242 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:00.747-04:00 + + + 9.0 + NETWORK + LOW + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-12-11T17:04:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 30768 + + + MISC + http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php + + The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access. + + + + + + + + + cpe:/a:dansie:shopping_cart:3.04 + + CVE-2000-1243 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:00.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-06-26T11:57:00.000-04:00 + + + + BUGTRAQ + 20070603 Dansie Cart Script Exploit Reported + + + BUGTRAQ + 20000413 Re: Back Door in Commercial Shopping Cart [RESOLVED] + + + BUGTRAQ + 20000413 Re: Back Door in Commercial Shopping Cart + + + BUGTRAQ + 20000413 Re: Back Door in Commercial Shopping Cart [Stormer Hosting] + + + BUGTRAQ + 20000411 Back Door in Commercial Shopping Cart + + Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers. + + + + + + + + + cpe:/a:ca:inoculateit_agent_for_exchange + + CVE-2000-1244 + 2000-12-31T00:00:00.000-05:00 + 2008-09-05T16:23:01.027-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2008-01-02T13:31:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20001110 CA's InoculateIT Agent for Exchange Server + + Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection. + + + + + + + + + + + + + + cpe:/o:novell:netware:5.1:sp3 + cpe:/a:novell:netware_ftp_server:5.01i + + CVE-2000-1245 + 2010-04-05T11:30:00.437-04:00 + 2010-04-05T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2010-04-05T13:25:00.000-04:00 + + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors. + + + + + + + + + + + + + + cpe:/o:novell:netware:5.1:sp3 + cpe:/a:novell:netware_ftp_server:5.01i + + CVE-2000-1246 + 2010-04-05T11:30:00.467-04:00 + 2010-04-05T15:28:07.717-04:00 + + + 3.5 + NETWORK + MEDIUM + SINGLE_INSTANCE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2010-04-05T13:30:00.000-04:00 + + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command. + + + + + + + + + cpe:/a:apache:jserv:1.1.2 + + CVE-2000-1247 + 2011-10-04T22:56:24.427-04:00 + 2012-02-13T21:07:17.257-05:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2011-10-05T10:26:00.000-04:00 + + + + + CONFIRM + http://archive.apache.org/dist/java/java.apache.org-www.tar.gz + + + XF + apache-jserv-env-information-disclosure(51946) + + + SREASON + 8412 + + + MLIST + [java-apache-users] 20000929 jserv wrapper error + + The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.4 + + CVE-2001-0001 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:01.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010213 RFP2101: RFPlutonium to fuel your PHP-Nuke + + + XF + php-nuke-elevate-privileges(6183) + + cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie. + + + + + + + + + + + + cpe:/a:microsoft:windows_script_host:5.1 + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:windows_script_host:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0002 + 2001-07-21T00:00:00.000-04:00 + 2013-08-31T00:11:38.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + OSVDB + 7823 + + + XF + ie-chm-execute-files(5567) + + + BID + 2456 + + + MS + MS01-015 + + + MISC + http://www.guninski.com/chmtempmain.html + + + + + Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + cpe:/a:microsoft:office:2000 + + CVE-2001-0003 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:01.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2199 + + + MS + MS01-001 + + + XF + wec-ntlm-authentication + + Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0004 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:01.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-004 + + + BUGTRAQ + 20010108 IIS 5.0 allows viewing files using %3F+.htr + + + XF + iis-read-files(5903) + + + BID + 2313 + + IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability. + + + + + + + + + cpe:/a:microsoft:powerpoint:2000 + + CVE-2001-0005 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:00.853-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS01-002 + + + ATSTAKE + A012301-1 + + + XF + powerpoint-execute-code(5996) + + Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0006 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:00.960-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-003 + + + BUGTRAQ + 20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below + + + XF + winnt-mutex-dos(6006) + + The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability. + + + + + + + + + + + + cpe:/o:netscreen:screen_os:2.10r3 + cpe:/o:netscreen:screen_os:1.73r + cpe:/o:netscreen:screen_os:2.5r1 + cpe:/o:netscreen:screen_os:2.1r6 + + CVE-2001-0007 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:02.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2176 + + + BUGTRAQ + 20010109 NSFOCUS SA2001-01: NetScreen Firewall WebUI Buffer Overflow vulnerability + + + XF + netscreen-webui-bo(5908) + + + OSVDB + 1707 + + Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface. + + + + + + + + + + + + cpe:/a:borland_software:interbase:6.0 + cpe:/a:firebirdsql:firebird:0.9.3 + cpe:/a:borland_software:interbase:4.0 + cpe:/a:borland_software:interbase:5.0 + + CVE-2001-0008 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:02.213-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-01 + + + BID + 2192 + + + XF + interbase-backdoor-account(5911) + + Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. + + + + + + + + + + + + cpe:/a:lotus:domino_server:5.0.6 + cpe:/a:lotus:domino_server:5.0.5 + cpe:/a:lotus:domino_server:5.0.3 + cpe:/a:lotus:domino_server:5.0.2 + + CVE-2001-0009 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:02.370-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2173 + + + BUGTRAQ + 20010109 bugtraq id 2173 Lotus Domino Server + + + BUGTRAQ + 20010105 Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root + + + XF + lotus-domino-directory-traversal(5899) + + + OSVDB + 1703 + + Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. + + + + + + + + + + + + + + + + + + cpe:/a:isc:bind:8.2.2:p5 + cpe:/a:isc:bind:8.2.2:p4 + cpe:/a:isc:bind:8.2.2:p7 + cpe:/a:isc:bind:8.2.2:p6 + cpe:/a:isc:bind:8.2.2:p1 + cpe:/a:isc:bind:8.2.2:p2 + cpe:/a:isc:bind:8.2.2:p3 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.2 + + CVE-2001-0010 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:01.307-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-02 + + + BID + 2302 + + + REDHAT + RHSA-2001:007 + + + NAI + 20010129 Vulnerabilities in BIND 4 and 8 + + + DEBIAN + DSA-026 + + Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. + + + + + + + + + + + + + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + + CVE-2001-0011 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:01.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-02 + + + BID + 2307 + + + REDHAT + RHSA-2001:007 + + + NAI + 20010129 Vulnerabilities in BIND 4 and 8 + + Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:8.2.2:p5 + cpe:/a:isc:bind:8.2.2:p4 + cpe:/a:isc:bind:8.2.2:p7 + cpe:/a:isc:bind:8.2.2:p6 + cpe:/a:isc:bind:8.2.2:p1 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:8.2.2:p2 + cpe:/a:isc:bind:8.2.2:p3 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:8.2.2 + cpe:/a:isc:bind:4.9.5 + + CVE-2001-0012 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:01.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2001-02 + + + BID + 2321 + + + REDHAT + RHSA-2001:007 + + + NAI + 20010129 Vulnerabilities in BIND 4 and 8 + + + DEBIAN + DSA-026 + + BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables. + + + + + + + + + + + + + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + + CVE-2001-0013 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:01.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-02 + + + BID + 2309 + + + REDHAT + RHSA-2001:007 + + + NAI + 20010129 Vulnerabilities in BIND 4 and 8 + + Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + + CVE-2001-0014 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:03.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2326 + + + MS + MS01-006 + + Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0015 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:03.387-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS01-007 + + + ATSTAKE + A020501-1 + + + XF + win-dde-elevate-privileges(6062) + + + BID + 2341 + + Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0016 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:03.540-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS01-008 + + + BINDVIEW + 20010207 Local promotion vulnerability in NT4's NTLM Security Support Provider + + + XF + ntlm-ssp-elevate-privileges(6076) + + + BID + 2348 + + NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0017 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:03.683-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-009 + + + XF + winnt-pptp-dos(6103) + + + BID + 2368 + + Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2001-0018 + 2001-07-21T00:00:00.000-04:00 + 2011-03-07T21:04:31.017-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-011 + + + XF + win2k-domain-controller-dos(6136) + + + CIAC + L-049 + + + VULN-DEV + 20001202 UDP Ping-pong in Win2k + + Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests. + + + + + + + + + + cpe:/h:cisco:arrowpoint + cpe:/h:cisco:content_services_switch + + CVE-2001-0019 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:03.980-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010131 Cisco Content Services Switch Vulnerability + + + ATSTAKE + A013101-1 + + Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. + + + + + + + + + + cpe:/h:cisco:arrowpoint + cpe:/h:cisco:content_services_switch + + CVE-2001-0020 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:04.120-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010131 Cisco Content Services Switch Vulnerability + + + ATSTAKE + A013101-1 + + + XF + cisco-ccs-file-access(6031) + + + BID + 2331 + + + OSVDB + 1757 + + Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:endymion:mailman_webmail:3.0.20 + cpe:/a:endymion:mailman_webmail:3.0.14 + cpe:/a:endymion:mailman_webmail:3.0.15 + cpe:/a:endymion:mailman_webmail:3.0.25 + cpe:/a:endymion:mailman_webmail:3.0 + cpe:/a:endymion:mailman_webmail:3.0.16 + cpe:/a:endymion:mailman_webmail:3.0.23 + cpe:/a:endymion:mailman_webmail:3.0.10 + cpe:/a:endymion:mailman_webmail:3.0.24 + cpe:/a:endymion:mailman_webmail:3.0.11 + cpe:/a:endymion:mailman_webmail:3.0.21 + cpe:/a:endymion:mailman_webmail:3.0.12 + cpe:/a:endymion:mailman_webmail:3.0.22 + cpe:/a:endymion:mailman_webmail:3.0.13 + cpe:/a:endymion:mailman_webmail:3.0.1 + cpe:/a:endymion:mailman_webmail:3.0.19 + cpe:/a:endymion:mailman_webmail:3.0.18 + + CVE-2001-0021 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:04.277-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2063 + + + BUGTRAQ + 20001206 (SRADV00005) Remote command execution vulnerabilities in MailMan Webmail + + + XF + mailman-alternate-templates + + + CONFIRM + http://www.endymion.com/products/mailman/history.htm + + MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. + + + + + + + + + cpe:/a:leif_m._wright:simplestguest.cgi:2.0 + + CVE-2001-0022 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:04.447-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-simplestguest + + + BID + 2106 + + + BUGTRAQ + 20001213 Re: Insecure input validation in simplestmail.cgi + + simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter. + + + + + + + + + cpe:/a:leif_m._wright:everythingform.cgi:2.0 + + CVE-2001-0023 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:04.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-everythingform + + + BID + 2101 + + + BUGTRAQ + 20001211 Insecure input validation in everythingform.cgi (remote command execution) + + everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. + + + + + + + + + cpe:/a:leif_m._wright:simplestmail.cgi:1.0 + + CVE-2001-0024 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:04.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-simplestmail + + + BID + 2102 + + + BUGTRAQ + 20001211 Insecure input validation in simplestmail.cgi (remote command execution) + + simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter. + + + + + + + + + cpe:/a:leif_m._wright:ad.cgi:1.0 + + CVE-2001-0025 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:04.900-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + http-cgi-ad + + + BID + 2103 + + + BUGTRAQ + 20001211 Insecure input validation in ad.cgi + + ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter. + + + + + + + + + + + + + cpe:/a:roaring_penguin:pppoe:2.0 + cpe:/a:roaring_penguin:pppoe:2.2 + cpe:/a:roaring_penguin:pppoe:2.1 + cpe:/a:roaring_penguin:pppoe:2.4 + cpe:/a:roaring_penguin:pppoe:2.3 + + CVE-2001-0026 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:05.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2098 + + + REDHAT + RHSA-2000:130 + + + BUGTRAQ + 20001211 DoS vulnerability in rp-pppoe versions <= 2.4 + + + XF + rppppoe-zero-length-dos + + + MANDRAKE + MDKSA-2000:084 + + + CONECTIVA + CLA-2000:357 + + rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option. + + + + + + + + + cpe:/a:proftpd_project:proftpd + + CVE-2001-0027 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:05.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + proftpd-modsqlpw-unauth-access + + + BUGTRAQ + 20001211 mod_sqlpw Password Caching Bug + + mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users. + + + + + + + + + cpe:/a:igor_khasilev:oops_proxy_server:1.4.22 + + CVE-2001-0028 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:05.337-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2099 + + + FREEBSD + FreeBSD-SA-00:79 + + + BUGTRAQ + 20001211 [pkc] remote heap buffer overflow in oops + + + XF + oops-ftputils-bo + + Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters. + + + + + + + + + cpe:/a:igor_khasilev:oops_proxy_server:1.4.22 + + CVE-2001-0029 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:05.493-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2099 + + + MISC + http://zipper.paco.net/~igor/oops/ChangeLog + + + XF + oops-dns-bo(6122) + + + BUGTRAQ + 20001212 Stack too ;) Re: [pkc] remote heap buffer overflow in oops + + Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup. + + + + + + + + + cpe:/a:smartstuff:foolproof_security:3.9 + + CVE-2001-0030 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:05.637-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + foolproof-security-bypass + + + BID + 2089 + + FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them. + + + + + + + + + cpe:/a:broadvision:one-to-one_enterprise_server:1.0 + + CVE-2001-0031 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:05.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + broadvision-bv1to1-reveal-path + + + BUGTRAQ + 20001207 BroadVision One-To-One Enterprise Path Disclosure Vulnerability + + BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist. + + + + + + + + + cpe:/a:eric_rescorla:ssldump:0.9b1 + + CVE-2001-0032 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:05.933-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ssldump-format-strings + + + BID + 2096 + + + BUGTRAQ + 20001208 format string in ssl dump + + Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL. + + + + + + + + + + + + + + cpe:/a:kth:kth_kerberos:4 + cpe:/o:netbsd:netbsd:1.5 + + CVE-2001-0033 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.073-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001210 KTH upgrade and FIX + + + BUGTRAQ + 20001208 Vulnerabilities in KTH Kerberos IV + + + XF + kerberos4-user-config + + KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges. + + + + + + + + + cpe:/a:kth:kth_kerberos:4.1.0.3 + + CVE-2001-0034 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.230-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001210 KTH upgrade and FIX + + + BUGTRAQ + 20001208 Vulnerabilities in KTH Kerberos IV + + + XF + kerberos4-arbitrary-proxy + + KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges. + + + + + + + + + cpe:/a:kth:kth_kerberos:4 + + CVE-2001-0035 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.370-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001210 KTH upgrade and FIX + + + BUGTRAQ + 20001208 Vulnerabilities in KTH Kerberos IV + + + XF + kerberos4-auth-packet-overflow + + + BUGTRAQ + 20010130 Buffer overflow in old ssh-1.2.2x-afs-kerberosv4 patches + + Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request. + + + + + + + + + cpe:/a:kth:kth_kerberos:4 + + CVE-2001-0036 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.510-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001210 KTH upgrade and FIX + + + BUGTRAQ + 20001208 Vulnerabilities in KTH Kerberos IV + + + XF + kerberos4-tmpfile-dos + + + REDHAT + RHSA-2001:025 + + KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file. + + + + + + + + + cpe:/a:keware_technologies:homeseer:1.4 + + CVE-2001-0037 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2085 + + + XF + homeseer-directory-traversal + + + MISC + http://www.keware.com/hsbetachanges.htm + + + BUGTRAQ + 20001207 HomeSeer Directory Traversal Vulnerability + + Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers. + + + + + + + + + + + + cpe:/a:metaproducts:offline_explorer:1.0x + cpe:/a:metaproducts:offline_explorer:1.3x + cpe:/a:metaproducts:offline_explorer:1.1x + cpe:/a:metaproducts:offline_explorer:1.2x + + CVE-2001-0038 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2084 + + + XF + offline-explorer-reveal-files + + + BUGTRAQ + 20001207 MetaProducts Offline Explorer + + Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL. + + + + + + + + + cpe:/a:ipswitch:imail:6.0.5 + + CVE-2001-0039 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:06.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2083 + + + XF + imail-smtp-auth-dos + + + CONFIRM + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20001206 DoS by SMTP AUTH command in IPSwitch IMail server + + IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes. + + + + + + + + + cpe:/a:apc:apcupsd:3.7.2 + + CVE-2001-0040 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:07.103-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2070 + + + XF + apc-apcupsd-dos + + + BUGTRAQ + 20001206 apcupsd 3.7.2 Denial of Service + + + MANDRAKE + MDKSA-2000:077 + + APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:catos:5.2%284%29 + cpe:/o:cisco:catos:5.5%281%29 + cpe:/o:cisco:catos:5.2%286%29 + cpe:/o:cisco:catos:4.5%282%29 + cpe:/o:cisco:catos:5.5%284a%29 + cpe:/o:cisco:catos:5.4%281%29 + cpe:/o:cisco:catos:5.1%281%29 + cpe:/o:cisco:catos:5.5%283%29 + cpe:/o:cisco:catos:5.3%281a%29csx + cpe:/o:cisco:catos:4.5%288%29 + cpe:/o:cisco:catos:5.2%282%29 + cpe:/o:cisco:catos:5.4%283%29 + cpe:/o:cisco:catos:5.3%283%29csx + cpe:/o:cisco:catos:4.5%284%29 + cpe:/o:cisco:catos:5.2%281a%29 + cpe:/o:cisco:catos:5.3%286%29csx + cpe:/o:cisco:catos:4.5%286%29 + cpe:/o:cisco:catos:4.5%283%29 + cpe:/o:cisco:catos:5.2%287%29 + cpe:/o:cisco:catos:5.5%282%29 + cpe:/o:cisco:catos:5.3%285a%29csx + cpe:/o:cisco:catos:5.3%284%29csx + cpe:/o:cisco:catos:5.2%285%29 + cpe:/o:cisco:catos:5.2%281%29 + cpe:/o:cisco:catos:5.2 + cpe:/o:cisco:catos:5.5%284%29 + cpe:/o:cisco:catos:5.3%285%29csx + cpe:/o:cisco:catos:5.1%282a%29 + cpe:/o:cisco:catos:5.1 + cpe:/o:cisco:catos:5.2%283%29 + cpe:/o:cisco:catos:4.5%289%29 + cpe:/o:cisco:catos:5.4 + cpe:/o:cisco:catos:5.3%282%29csx + cpe:/o:cisco:catos:5.5 + cpe:/o:cisco:catos:5.4%284%29 + cpe:/o:cisco:catos:5.4%282%29 + cpe:/o:cisco:catos:4.5%285%29 + cpe:/o:cisco:catos:5.3%281%29csx + cpe:/o:cisco:catos:5.1%281a%29 + cpe:/o:cisco:catos:4.5%287%29 + + CVE-2001-0041 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:07.243-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 2072 + + + CISCO + 20001206 Cisco Catalyst Memory Leak Vulnerability + + + XF + cisco-catalyst-telnet-dos + + + OSVDB + 801 + + Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. + + + + + + + + + cpe:/a:apache:http_server:1.3 + + CVE-2001-0042 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:07.480-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + apache-php-disclose-files + + + BID + 2060 + + + BUGTRAQ + 20001206 CHINANSL Security Advisory(CSA-200011) + + PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences. + + + + + + + + + cpe:/a:phpgroupware:phpgroupware:0.9.6 + + CVE-2001-0043 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:07.620-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2069 + + + MISC + http://sourceforge.net/project/shownotes.php?release_id=17604 + + + BUGTRAQ + 20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare + + + XF + phpgroupware-include-files + + + OSVDB + 1682 + + phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program. + + + + + + + + + cpe:/a:lexmark:markvision:4.3 + + CVE-2001-0044 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:07.777-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2075 + + + BUGTRAQ + 20001206 (SRADV00007) Local root compromise through Lexmark MarkVision printer drivers + + + XF + markvision-printer-driver-bo + + Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands. + + + + + + + + + + cpe:/o:microsoft:windows_nt:terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0045 + 2001-02-16T00:00:00.000-05:00 + 2008-09-10T15:07:04.493-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 2064 + + + MS + MS00-095 + + + XF + nt-ras-reg-perms + + + + + The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0046 + 2001-02-16T00:00:00.000-05:00 + 2008-09-10T15:07:05.007-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 2066 + + + MS + MS00-095 + + + XF + nt-snmp-reg-perms + + + + + The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities. + + + + + + + + + + cpe:/o:microsoft:windows_nt:terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0047 + 2001-02-16T00:00:00.000-05:00 + 2008-09-10T15:07:05.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS00-095 + + + XF + nt-mts-reg-perms + + + BID + 2065 + + + + + The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities. + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + + CVE-2001-0048 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:08.370-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2133 + + + MS + MS00-099 + + The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability. + + + + + + + + + cpe:/h:watchguard:soho_firewall:2.2.1 + + CVE-2001-0049 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:08.510-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + watchguard-soho-get-dos + + + BID + 2082 + + + BUGTRAQ + 20001207 WatchGuard SOHO v2.2.1 DoS + + WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests. + + + + + + + + + cpe:/a:colten_edwards:bitchx:1.0c17 + + CVE-2001-0050 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:08.650-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2087 + + + XF + irc-bitchx-dns-bo + + + BUGTRAQ + 20001207 bitchx/ircd DNS overflow demonstration + + + BUGTRAQ + 20001207 BitchX DNS Overflow Patch + + + REDHAT + RHSA-2000:126 + + + MANDRAKE + MDKSA-2000:079 + + + CONECTIVA + CLA-2000:364 + + + FREEBSD + FreeBSD-SA-00:78 + + Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name. + + + + + + + + + + cpe:/a:ibm:db2_universal_database:6.1::windows_nt + cpe:/a:ibm:db2_universal_database:6.1::linux + + CVE-2001-0051 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:08.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ibm-db2-gain-access + + + BID + 2068 + + + BUGTRAQ + 20001205 IBM DB2 default account and password Vulnerability + + IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the databasse. + + + + + + + + + + cpe:/a:ibm:db2_universal_database:6.1::windows_nt + cpe:/a:ibm:db2_universal_database:7.1::windows_nt + + CVE-2001-0052 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:08.947-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ibm-db2-dos + + + BID + 2067 + + + BUGTRAQ + 20001205 IBM DB2 SQL DOS + + IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:openbsd:openbsd:2.8 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + cpe:/a:david_madore:ftpd-bsd:0.2.3 + + CVE-2001-0053 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:09.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-ftpd-replydirname-bo + + + BID + 2124 + + + OPENBSD + 20001218 + + + BUGTRAQ + 20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSD + + + NETBSD + NetBSD-SA2000-018 + + One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges. + + + + + + + + + cpe:/a:serv-u:serv-u:3.0.0.16 + + CVE-2001-0054 + 2001-02-16T00:00:00.000-05:00 + 2010-04-28T09:27:12.267-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 2052 + + + BUGTRAQ + 20001205 Serv-U FTP directory traversal vunerability (all versions) + + + BUGTRAQ + 20001205 (no subject) + + + XF + ftp-servu-homedir-travers + + + OSVDB + 464 + + Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack. + + + + + + + + + + + + + + cpe:/o:cisco:broadband_operating_system:2.3.8 + cpe:/h:cisco:cisco_6xx_routers + + CVE-2001-0055 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:09.433-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-syn-packets + + + CISCO + 20001204 Multiple Vulnerabilities in CBOS + + CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. + + + + + + + + + cpe:/o:cisco:broadband_operating_system:2.4.1 + + CVE-2001-0056 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:09.573-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-invalid-login + + + CISCO + 20001204 Multiple Vulnerabilities in CBOS + + The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. + + + + + + + + + + + + + + cpe:/o:cisco:broadband_operating_system:2.4.1 + cpe:/h:cisco:cisco_6xx_routers + + CVE-2001-0057 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:09.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-icmp-echo + + + CISCO + 20001204 Multiple Vulnerabilities in CBOS + + Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. + + + + + + + + + + + + + + cpe:/o:cisco:broadband_operating_system:2.4.1 + cpe:/h:cisco:cisco_6xx_routers + + CVE-2001-0058 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:09.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-web-access + + + CISCO + 20001204 Multiple Vulnerabilities in CBOS + + + OSVDB + 460 + + The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. + + + + + + + + + cpe:/o:sun:solaris:7.0 + + CVE-2001-0059 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.027-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + solaris-patchadd-symlink + + + BID + 2127 + + + BUGTRAQ + 20001218 Solaris patchadd(1) (3) symlink vulnerabilty + + patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/a:stunnel:stunnel:3.8 + cpe:/a:stunnel:stunnel:3.7 + cpe:/a:stunnel:stunnel:3.4a + cpe:/a:stunnel:stunnel:3.3 + + CVE-2001-0060 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.167-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2128 + + + BUGTRAQ + 20001218 Stunnel format bug + + + BUGTRAQ + 20001209 Trustix Security Advisory - stunnel + + + XF + stunnel-format-logfile + + + REDHAT + RHSA-2000:129 + + + DEBIAN + DSA-009 + + + CONECTIVA + CLA-2000:363 + + Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:3.5.1 + + CVE-2001-0061 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.323-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2130 + + + FREEBSD + FreeBSD-SA-00:77 + + + XF + procfs-elevate-privileges(6106) + + + OSVDB + 1697 + + procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:3.5.1 + + CVE-2001-0062 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2131 + + + FREEBSD + FreeBSD-SA-00:77 + + + XF + procfs-mmap-dos(6107) + + + OSVDB + 6082 + + + OSVDB + 1698 + + procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:3.5.1 + + CVE-2001-0063 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.637-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2132 + + + FREEBSD + FreeBSD-SA-00:77 + + + XF + procfs-access-control-bo(6108) + + + OSVDB + 1691 + + procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges. + + + + + + + + + cpe:/a:alt-n:mdaemon:3.5.0 + + CVE-2001-0064 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2134 + + + BUGTRAQ + 20001219 def-2000-03: MDaemon 3.5.0 DoS + + Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string. + + + + + + + + + cpe:/a:max-wilhelm_bruker:bftpd:1.0.13 + + CVE-2001-0065 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:10.933-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bftpd-site-chown-bo + + + BUGTRAQ + 20001213 Potential Buffer Overflow vulnerability in bftpd-1.0.13 + + Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command. + + + + + + + + + + + + + + cpe:/a:kevin_lindsay:secure_locate:1.4 + cpe:/a:kevin_lindsay:secure_locate:2.1 + cpe:/a:kevin_lindsay:secure_locate:2.0 + cpe:/a:kevin_lindsay:secure_locate:1.6 + cpe:/a:kevin_lindsay:secure_locate:2.2 + cpe:/a:kevin_lindsay:secure_locate:1.5 + + CVE-2001-0066 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:11.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2004 + + + BUGTRAQ + 20001126 [MSY] S(ecure)Locate heap corruption vulnerability + + + XF + slocate-heap-execute-code(5594) + + + TURBO + TLSA2001002-1 + + + REDHAT + RHSA-2000:128 + + + MANDRAKE + MDKSA-2000:085 + + + DEBIAN + DSA-005-1 + + + CONECTIVA + CLA-2001:369 + + Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer. + + + + + + + + + cpe:/a:judd_montgomery:jpilot + + CVE-2001-0067 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:11.243-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2000:081 + + + XF + jpilot-perms + + + BUGTRAQ + 20001214 J-Pilot Permissions Vulnerability + + The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set. + + + + + + + + + cpe:/a:apple:mac_os_runtime_for_java:2.2.3::java + + CVE-2001-0068 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:11.387-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mrj-runtime-malicious-applets + + + BUGTRAQ + 20001215 Security Hole of MRJ 2.2.3 (Mac OS Runtime for Java) - Inconsistent Use of CODEBASE and ARCHIVE Attributes - + + Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter. + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2001-0069 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:11.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2151 + + + DEBIAN + DSA-008-1 + + + XF + dialog-symlink + + dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:upland_solutions:1st_up_mail_server:4.1 + + CVE-2001-0070 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:08.447-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20001226 1st Up Mail Server v4.1 Buffer Overflow Vulnerability + + + XF + 1stup-mail-server-bo + + + BID + 2152 + + Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command. + + + + + + + + + + + + + cpe:/a:gnu:privacy_guard:1.0.3b + cpe:/a:gnu:privacy_guard:1.0.3 + cpe:/a:gnu:privacy_guard:1.0.1 + cpe:/a:gnu:privacy_guard:1.0.2 + cpe:/a:gnu:privacy_guard:1.0 + + CVE-2001-0071 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:11.837-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2141 + + + BUGTRAQ + 20001220 Trustix Security Advisory - gnupg, ftpd-BSD + + + REDHAT + RHSA-2000:131 + + + XF + gnupg-detached-sig-modify + + + OSVDB + 1699 + + + MANDRAKE + MDKSA-2000-087 + + + DEBIAN + DSA-010-1 + + + CONECTIVA + CLA-2000:368 + + gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection. + + + + + + + + + + + + + cpe:/a:gnu:privacy_guard:1.0.3b + cpe:/a:gnu:privacy_guard:1.0.3 + cpe:/a:gnu:privacy_guard:1.0.1 + cpe:/a:gnu:privacy_guard:1.0.2 + cpe:/a:gnu:privacy_guard:1.0 + + CVE-2001-0072 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:11.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2153 + + + XF + gnupg-reveal-private + + + BUGTRAQ + 20001220 Trustix Security Advisory - gnupg, ftpd-BSD + + + REDHAT + RHSA-2000:131 + + + OSVDB + 1702 + + + MANDRAKE + MDKSA-2000-087 + + + DEBIAN + DSA-010-1 + + + CONECTIVA + CLA-2000:368 + + gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust. + + + + + + + + + cpe:/o:nsa:security-enhanced_linux:slinux_2000-12-18 + + CVE-2001-0073 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.150-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2154 + + + BUGTRAQ + 20001226 buffer overflow in libsecure (NSA Security-enhanced Linux) + + Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory. + + + + + + + + + + + cpe:/a:technote_inc:technote:pro + cpe:/a:technote_inc:technote:2001 + cpe:/a:technote_inc:technote:2000 + + CVE-2001-0074 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2155 + + + BUGTRAQ + 20001223 Technote + + Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter. + + + + + + + + + + + cpe:/a:technote_inc:technote:pro + cpe:/a:technote_inc:technote:2001 + cpe:/a:technote_inc:technote:2000 + + CVE-2001-0075 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2156 + + + BUGTRAQ + 20001227 [Ksecurity Advisory] main.cgi in technote + + Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter. + + + + + + + + + cpe:/a:ikonboard.com:ikonboard:2.1.7b + + CVE-2001-0076 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2157 + + + BUGTRAQ + 20001228 Remote vulnerability in Ikonboard upto version 2.1.7b + + + XF + http-cgi-ikonboard + + register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed. + + + + + + + + + cpe:/a:sun:cluster:2.0 + + CVE-2001-0077 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001212 Two Holes in Sun Cluster 2.x + + + XF + clustmon-no-authentication(6123) + + The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations. + + + + + + + + + cpe:/a:sun:cluster:2.0 + + CVE-2001-0078 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:12.947-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001212 Two Holes in Sun Cluster 2.x + + + XF + ha-nfs-symlink(6125) + + + OSVDB + 6437 + + in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS. + + + + + + + + + cpe:/a:hp:support_tools_manager:a.22.00 + + CVE-2001-0079 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:13.087-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001213 STM symlink Vulnerability + + Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file. + + + + + + + + + + + cpe:/h:cisco:catalyst_6000 + cpe:/h:cisco:catalyst_5000 + cpe:/h:cisco:catalyst_4000 + + CVE-2001-0080 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:13.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20001213 Cisco Catalyst SSH Protocol Mismatch Vulnerability + + + XF + cisco-catalyst-ssh-mismatch + + + BID + 2117 + + Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error. + + + + + + + + + cpe:/a:ncipher:ncipher + + CVE-2001-0081 + 2001-02-12T00:00:00.000-05:00 + 2011-03-07T21:04:35.847-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20001212 nCipher Security Advisory: Operator Cards unexpectedly recoverable + + + CONFIRM + http://active.ncipher.com/updates/advisory.txt + + + XF + ncipher-recover-operator-cards(5999) + + + OSVDB + 4849 + + swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys. + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1:sp2 + + CVE-2001-0082 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:13.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20001218 FireWall-1 Fastmode Vulnerability + + Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets. + + + + + + + + + + cpe:/a:microsoft:windows_media_services:4.1 + cpe:/a:microsoft:windows_media_services:4.0 + + CVE-2001-0083 + 2001-02-12T00:00:00.000-05:00 + 2008-09-10T15:07:10.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-097 + + + XF + mediaservices-dropped-connection-dos + + + MSKB + Q281256 + + Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability. + + + + + + + + + cpe:/a:gtk:gtk%2b:1.2.8 + + CVE-2001-0084 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:13.823-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2165 + + + MISC + http://www.gtk.org/setuid.html + + + BUGTRAQ + 20010103 Claimed vulnerability in GTK_MODULES + + + BUGTRAQ + 20010102 gtk+ security hole. + + GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-0085 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:13.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2170 + + + XF + hpux-kermit-bo + + + HP + HPSBUX0012-135 + + + + + Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands. + + + + + + + + + + cpe:/a:cgi_script_center:subscribe_me_lite:2.0 + cpe:/a:cgi_script_center:subscribe_me_lite:1.0 + + CVE-2001-0086 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:14.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + subscribemelite-gain-admin-access + + + BID + 2108 + + + BUGTRAQ + 20001212 Security Advisory: Subscribe Me Lite 1.0 - 2.0 Unix or 1.0 - 2.0 NT and below. + + CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. + + + + + + + + + + cpe:/a:michael_glickman:itetris:1.6.1 + cpe:/a:michael_glickman:itetris:1.6.2 + + CVE-2001-0087 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:14.277-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2139 + + + BUGTRAQ + 20001219 itetris[v1.6.2] local root exploit (system()+../ protection) + + + XF + itetris-svgalib-path + + itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. + + + + + + + + + cpe:/a:jason_hines:phpweblog:0.4.2 + + CVE-2001-0088 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:14.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + phpweblog-bypass-authentication + + + BID + 2047 + + + BUGTRAQ + 20001202 Bypassing admin authentication in phpWebLog + + common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0089 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:14.573-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-093 + + + XF + ie-form-file-upload + + Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability. + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0090 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:23:14.727-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2046 + + + MS + MS00-093 + + + XF + ie-print-template(5614) + + The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0091 + 2001-02-16T00:00:00.000-05:00 + 2008-09-10T15:07:11.853-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-093 + + + XF + ie-scriptlet-rendering-read-files(6085) + + + OSVDB + 7820 + + The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0092 + 2001-02-16T00:00:00.000-05:00 + 2008-09-10T15:07:11.993-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-093 + + + XF + ie-frame-verification-read-files(6086) + + + OSVDB + 7817 + + A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + cpe:/o:freebsd:freebsd:1.5 + + CVE-2001-0093 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.180-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NETBSD + NetBSD-SA2000-017 + + Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd. + + + + + + + + + cpe:/o:freebsd:freebsd:1.5 + + CVE-2001-0094 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.323-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + NETBSD + NetBSD-SA2000-017 + + + XF + kerberos4-auth-packet-overflow(5734) + + + FREEBSD + FreeBSD-SA-01:25 + + Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges. + + + + + + + + + + cpe:/o:sun:solaris:2.7 + cpe:/o:sun:solaris:2.8 + + CVE-2001-0095 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.463-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + solaris-catman-symlink(5788) + + + BUGTRAQ + 20001218 Catman file clobbering vulnerability Solaris 2.x + + + OSVDB + 6024 + + catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0096 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-100 + + + XF + iis-web-form-submit + + FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability. + + + + + + + + + cpe:/a:infinite:infinite_interchange:3.61 + + CVE-2001-0097 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.760-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + infinite-interchange-dos + + + BID + 2140 + + + BUGTRAQ + 20001221 Infinite InterChange DoS + + The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request. + + + + + + + + + cpe:/a:bea:weblogic_server:4.5.2:sp2 + + CVE-2001-0098 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:15.917-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + weblogic-dot-bo + + + BID + 2138 + + + BUGTRAQ + 20001219 def-2000-04: Bea WebLogic Server dotdot-overflow + + Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. + + + + + + + + + cpe:/a:brian_stanback:bsguest.cgi + + CVE-2001-0099 + 2001-02-12T00:00:00.000-05:00 + 2011-03-07T21:04:37.220-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsguest-cgi-execute-commands + + + MISC + http://www.stanback.net/ + + + BUGTRAQ + 20001221 BS Scripts Vulnerabilities + + bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. + + + + + + + + + cpe:/a:brian_stanback:bslist.cgi + + CVE-2001-0100 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:16.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bslist-cgi-execute-commands + + + MISC + http://www.stanback.net/ + + + BUGTRAQ + 20001221 BS Scripts Vulnerabilities + + bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + + CVE-2001-0101 + 2001-02-12T00:00:00.000-05:00 + 2011-02-16T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fetchmail-authenticate-gssapi(7455) + + + TURBO + TLSA2000024-1 + + + REDHAT + RHBA-2000:106-04 + + Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command. + + + + + + + + + cpe:/o:apple:mac_os + + CVE-2001-0102 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:16.510-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + macos-multiple-users + + + BUGTRAQ + 20001229 Mac OS 9 Multiple Users Control Panel Password Vulnerability + + "Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password. + + + + + + + + + + cpe:/a:coffeecup_software:coffeecup_free_ftp:1.0 + cpe:/a:coffeecup_software:coffeecup_direct_ftp:1.0 + + CVE-2001-0103 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:16.650-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + XF + coffeecup-ftp-weak-encryption + + + BID + 2107 + + CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords. + + + + + + + + + cpe:/a:alt-n:mdaemon:3.5.1 + + CVE-2001-0104 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:16.807-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + mdaemon-lock-bypass-password + + + BID + 2115 + + + BUGTRAQ + 20001214 Bypass MDaemon 3.5.1 "Lock Server" Protection + + MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key. + + + + + + + + + + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + + CVE-2001-0105 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:16.947-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX0012-134 + + + XF + hp-top-sys-files + + + + + Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group. + + + + + + + + + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-0106 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:23:17.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + HP + HPSBUX0101-136 + + + XF + hp-inetd-swait-dos(5904) + + + + + Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server. + + + + + + + + + cpe:/a:symantec_veritas:backup:4.5 + + CVE-2001-0107 + 2001-03-12T00:00:00.000-05:00 + 2011-03-07T21:04:37.767-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2204 + + + BUGTRAQ + 20010115 Veritas BackupExec (remote DoS) + + Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang. + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + + CVE-2001-0108 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:15.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2206 + + + XF + php-htaccess-unauth-access(5940) + + + REDHAT + RHSA-2000:136 + + + MANDRAKE + MDKSA-2001:013 + + + DEBIAN + DSA-020 + + + BUGTRAQ + 20010112 PHP Security Advisory - Apache Module bugs + + + CONECTIVA + CLA-2001:373 + + PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested. + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2001-0109 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:17.540-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2207 + + + BUGTRAQ + 20010113 Serious security flaw in SuSE rctab + + + XF + rctab-elevate-privileges(5945) + + + BUGTRAQ + 20010117 Re: Serious security flaw in SuSE rctab + + rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file. + + + + + + + + + cpe:/a:iomega:jazip:0.32.2 + + CVE-2001-0110 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:17.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-017 + + + BID + 2209 + + + BUGTRAQ + 20010114 Vulnerability in jaZip. + + + XF + jazip-display-bo(5942) + + Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable. + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/a:sam_lantinga:splitvt:1.6.4 + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2001-0111 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:17.853-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2210 + + + DEBIAN + DSA-014-1 + + + BUGTRAQ + 20010114 [MSY] Multiple vulnerabilities in splitvt + + + XF + splitvt-perserc-format-string(5948) + + Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument. + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/a:sam_lantinga:splitvt:1.6.4 + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2001-0112 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.010-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2210 + + + DEBIAN + DSA-014 + + + BUGTRAQ + 20010114 [MSY] Multiple vulnerabilities in splitvt + + Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands. + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.0.7 + + CVE-2001-0113 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.167-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2211 + + + BUGTRAQ + 20010116 Vulnerabilities in OmniHTTPd default installation + + statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script. + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.0.7 + + CVE-2001-0114 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2211 + + + BUGTRAQ + 20010116 Vulnerabilities in OmniHTTPd default installation + + statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter. + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0115 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.463-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2193 + + + SUN + 00200 + + + BUGTRAQ + 20010112 arp exploit + + + BUGTRAQ + 20010111 Solaris Arp Vulnerability + + + XF + solaris-arp-bo(5928) + + Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter. + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0116 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.633-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2188 + + + MANDRAKE + MDKSA-2001:006 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + + XF + linux-gpm-symlink(5917) + + gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0117 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.807-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#579928 + + + BID + 2191 + + + MANDRAKE + MDKSA-2001:008-1 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + + XF + linux-diffutils-sdiff-symlink(5914) + + + REDHAT + RHSA-2001:116 + + + IMMUNIX + IMNX-2000-70-028-01 + + sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack. + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0118 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:18.977-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2195 + + + MANDRAKE + MDKSA-2001-005 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + + XF + rdist-symlink(5925) + + rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0119 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:19.133-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2194 + + + MANDRAKE + MDKSA-2001:004 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + + XF + gettyps-symlink(5924) + + getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0120 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:19.307-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2196 + + + MANDRAKE + MDKSA-2001:007 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + + XF + shadow-utils-useradd-symlink(5927) + + useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:storagesoft:imagecast_ic3:4.1 + + CVE-2001-0121 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:19.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2174 + + + BUGTRAQ + 20010108 def-2001-01: ImageCast IC3 Control Center DoS + + + XF + storagesoft-imagecast-dos(5901) + + ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002. + + + + + + + + + + cpe:/a:ibm:http_server:1.3.12.2 + cpe:/a:ibm:websphere_application_server:3.52 + + CVE-2001-0122 + 2001-03-13T00:00:00.000-05:00 + 2008-09-05T16:23:19.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2175 + + + BUGTRAQ + 20010108 def-2001-02: IBM Websphere 3.52 Kernel Leak DoS + + + CONFIRM + http://www-4.ibm.com/software/webservers/security.html + + + XF + ibm-websphere-dos(5900) + + + BUGTRAQ + 20010307 def-2001-02: IBM HTTP Server Kernel Leak DoS (re-release) + + Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. + + + + + + + + + cpe:/a:extropia:bbs_forum.cgi:1.0 + + CVE-2001-0123 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:19.760-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2177 + + + BUGTRAQ + 20010107 Cgisecurity.com Advisory #3.1 + + + CONFIRM + http://www.extropia.com/hacks/bbs_security.html + + + XF + http-cgi-bbs-forum(5906) + + + OSVDB + 3546 + + Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter. + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0124 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:19.900-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2179 + + + BUGTRAQ + 20010109 Solaris /usr/lib/exrecover buffer overflow + + + XF + solaris-exrecover-bo(5913) + + Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument. + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/a:exmh:exmh:2.2 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + + CVE-2001-0125 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:20.057-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + exmh-error-symlink + + + MANDRAKE + MDKSA-2001:015 + + + CONFIRM + http://www.beedub.com/exmh/symlink.html + + + BUGTRAQ + 20010112 exmh security vulnerability + + + BUGTRAQ + 20001231 Advisory: exmh symlink vulnerability + + + DEBIAN + DSA-022 + + + FREEBSD + FreeBSD-SA-01:17 + + exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.7 + + CVE-2001-0126 + 2001-03-12T00:00:00.000-05:00 + 2011-03-07T21:04:39.297-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010109 Oracle XSQL servlet and xml-stylesheet allow executing java on the web server + + + XF + oracle-xsql-execute-code(5905) + + + BUGTRAQ + 20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet + + Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet. + + + + + + + + + cpe:/a:oliver_debon:flash:0.4.9 + + CVE-2001-0127 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:20.367-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#451096 + + + BID + 2214 + + + BUGTRAQ + 20010115 Flash plugin write-overflow + + Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:6.0 + cpe:/a:redhat:linux_powertools:6.1 + cpe:/a:redhat:linux_powertools:6.2 + cpe:/a:redhat:linux_powertools:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:conectiva:linux:4.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:conectiva:linux:5.0 + cpe:/o:redhat:linux:7.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/a:zope:zope:2.2.4 + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-0128 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:17.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2000-083 + + + DEBIAN + DSA-006-1 + + + FREEBSD + FreeBSD-SA-01:06 + + + XF + zope-calculate-roles + + + REDHAT + RHSA-2000:127 + + + OSVDB + 6284 + + + CONECTIVA + CLA-2000:365 + + Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. + + + + + + + + + + cpe:/a:tinyproxy:tinyproxy:1.3.2 + cpe:/a:tinyproxy:tinyproxy:1.3.3 + + CVE-2001-0129 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:20.713-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2217 + + + DEBIAN + DSA-018 + + + BUGTRAQ + 20010117 [pkc] remote heap overflow in tinyproxy + + + XF + tinyproxy-remote-bo(5954) + + Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request. + + + + + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.06 + cpe:/a:lotus:domino_r5_server:5.04 + cpe:/a:lotus:domino_r5_server:5.05 + cpe:/a:lotus:domino_r5_client:5.04 + cpe:/a:lotus:domino_r5_client:5.05 + + CVE-2001-0130 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:18.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html + + + XF + lotus-html-bo(6207) + + Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier. + + + + + + + + + + + + + + + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:apache:http_server + cpe:/o:redhat:linux:7.0 + + CVE-2001-0131 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.027-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2182 + + + DEBIAN + DSA-021 + + + XF + linux-apache-symlink(5926) + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.6 + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2001-0132 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.167-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2213 + + + BUGTRAQ + 20010114 Trend Micro's VirusWall: Multiple vunerabilities + + Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.6 + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2001-0133 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.323-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2212 + + + BUGTRAQ + 20010114 Trend Micro's VirusWall: Multiple vunerabilities + + The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:digital:unix:5.0 + cpe:/a:compaq:intelligent_cluster_administrator:1.0 + cpe:/a:compaq:foundation_agents:4.0 + cpe:/a:compaq:insight_manager_xe:1.21 + cpe:/a:compaq:foundation_agents:4.90 + cpe:/a:compaq:system_healthcheck:3.0 + cpe:/a:compaq:armada_insight_manager:4.20 + cpe:/a:compaq:management_agents:4.30j + cpe:/a:compaq:open_san_manager:1.0 + cpe:/a:compaq:foundation_agents:2.1 + cpe:/a:compaq:survey_utility:2.33 + cpe:/a:compaq:foundation_agents:1.0 + cpe:/a:compaq:sanworks_resource_monitor:1.0 + cpe:/a:compaq:management_agents:4.35j + cpe:/a:compaq:survey_utility:2.18 + cpe:/a:compaq:insight_manager_xe:1.0 + cpe:/a:compaq:survey_utility:2.17 + cpe:/a:compaq:intelligent_cluster_administrator:2.1 + cpe:/o:digital:unix:4.0g + cpe:/o:digital:unix:4.0f + cpe:/a:compaq:storage_allocation_reporter:1.0 + cpe:/a:compaq:management_agents:4.36j + cpe:/a:compaq:management_agents:4.36e + cpe:/a:compaq:insight_manager_lc:1.3c + cpe:/a:compaq:insight_management_agent:4.37e + cpe:/a:compaq:enterprise_volume_manager-command_scripter:1.0 + cpe:/a:compaq:armada_insight_manager:4.20j + cpe:/a:compaq:insight_manager_lc:1.50a + cpe:/a:compaq:enterprise_volume_manager-command_scripter:1.1 + cpe:/a:compaq:insight_management_desktop_web_agent:3.7 + + CVE-2001-0134 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.463-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + COMPAQ + SSRT0705 + + + BID + 2200 + + + BUGTRAQ + 20010116 iXsecurity.20001120.compaq-authbo.a + + Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. + + + + + + + + + cpe:/a:ultrascripts:ultraboard:2.11 + + CVE-2001-0135 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2197 + + + BUGTRAQ + 20010112 UltraBoard cgi directory permission problem + + The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. + + + + + + + + + + + + + + + + cpe:/a:proftpd_project:proftpd + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:conectiva:linux + + CVE-2001-0136 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.823-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + proftpd-size-memory-leak + + + BUGTRAQ + 20001220 ProFTPD 1.2.0 Memory leakage - denial of service + + + BUGTRAQ + 20010110 Re: Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) + + + BUGTRAQ + 20010109 Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) + + + MANDRAKE + MDKSA-2001:021 + + + DEBIAN + DSA-029 + + + CONECTIVA + CLA-2001:380 + + + BUGTRAQ + 20010213 Trustix Security Advisory - proftpd, kernel + + Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + + CVE-2001-0137 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:21.977-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2203 + + + BUGTRAQ + 20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs + + + XF + win-mediaplayer-arbitrary-code(5937) + + + MS + MS01-010 + + Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:redhat:linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2001-0138 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:18.837-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2189 + + + XF + linux-wuftpd-privatepw-symlink(5915) + + + MANDRAKE + MDKSA-2001-001 + + + DEBIAN + DSA-016 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:caldera:openlinux_eserver:2.3 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/a:caldera:openlinux_desktop:2.3 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0139 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:18.947-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2190 + + + MANDRAKE + MDKSA-2001:010 + + + CALDERA + CSSA-2001-001.0 + + + XF + linux-inn-symlink(5916) + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0140 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:19.057-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2183 + + + MANDRAKE + MDKSA-2001:002 + + + XF + tcpdump-arpwatch-symlink(5922) + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations. + + + + + + + + + cpe:/a:gert_doering:mgetty:1.1.22 + + CVE-2001-0141 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:19.163-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2187 + + + MANDRAKE + MDKSA-2001:009 + + + DEBIAN + DSA-011 + + + CALDERA + CSSA-2001-002.0 + + + XF + linux-mgetty-symlink(5918) + + + REDHAT + RHSA-2001:050 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/a:national_science_foundation:squid_web_proxy:2.3_stable4 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0142 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:19.243-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2184 + + + MANDRAKE + MDKSA-2001:003 + + + BUGTRAQ + 20010112 Trustix Security Advisory - diffutils squid + + + XF + squid-email-symlink(5921) + + + DEBIAN + DSA-019 + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations. + + + + + + + + + + + + + + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:redhat:linux:7.0 + + CVE-2001-0143 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:07:19.337-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2186 + + + MANDRAKE + MDKSA-2001:011 + + + XF + linuxconf-vpop3d-symlink(5923) + + + BUGTRAQ + 20010110 Immunix OS Security update for lots of temp file problems + + vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:openbsd:openssh:1.2.2 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-0144 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:23:23.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-35 + + + BID + 2347 + + + BINDVIEW + 20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector + + + BUGTRAQ + 20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector + + + XF + ssh-deattack-overwrite-memory(6083) + + + OSVDB + 795 + + + OSVDB + 503 + + + + + CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow. + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook:2000 + + CVE-2001-0145 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:23.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS01-012 + + + ATSTAKE + A022301-1 + + Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:exchange_server:2000 + + CVE-2001-0146 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:23.527-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#796584 + + + MS + MS01-014 + + + XF + exchange-malformed-url-dos(6172) + + + XF + iis-malformed-url-dos(6171) + + + BID + 2441 + + + BID + 2440 + + IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2001-0147 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:23.667-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS01-013 + + Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records. + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + + CVE-2001-0148 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:23.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-015 + + + BUGTRAQ + 20010101 Windows Media Player 7 and IE vulnerability - executing arbitrary programs + + + XF + media-player-execute-commands(6227) + + The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0149 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:23.963-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-015 + + + NTBUGTRAQ + 20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files + + + BUGTRAQ + 20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files + + + XF + ie-getobject-expose-files(5293) + + + BID + 1718 + + Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object. + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0150 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:24.103-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-015 + + + XF + ie-telnet-execute-commands(6230) + + + BID + 2463 + + + OSVDB + 7816 + + Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0151 + 2001-06-02T00:00:00.000-04:00 + 2008-09-10T15:07:20.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS01-016 + + + XF + iis-webdav-dos(6205) + + + + + IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests. + + + + + + + + + cpe:/a:microsoft:plus + + CVE-2001-0152 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:24.400-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-019 + + The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders. + + + + + + + + + + cpe:/a:microsoft:visual_basic:6.0::enterprise + cpe:/a:microsoft:visual_studio:6.0::enterprise + + CVE-2001-0153 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:24.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS01-018 + + + BINDVIEW + 20010327 Remote buffer overflow in DCOM VB T-SQL debugger + + Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0154 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:24.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT + CA-2001-06 + + + MS + MS01-020 + + + BUGTRAQ + 20010330 Incorrect MIME Header Can Cause IE to Execute E-mail Attachment + + + XF + ie-mime-execute-code(6306) + + + BID + 2524 + + + OSVDB + 7806 + + + CIAC + L-066 + + + SECTRACK + 1001197 + + + + + HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. + + + + + + + + + cpe:/a:van_dyke_technologies:vshell:1.0.1 + + CVE-2001-0155 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:24.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.vandyke.com/products/vshell/security102.html + + + ATSTAKE + A021601-1 + + Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers. + + + + + + + + + cpe:/a:van_dyke_technologies:vshell:1.0.1 + + CVE-2001-0156 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:24.993-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A021601-1 + + + CONFIRM + http://www.vandyke.com/products/vshell/security102.html + + + XF + vshell-port-forwarding-rule(6148) + + + BID + 2402 + + VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users conduct arbitrary port forwarding to other systems. + + + + + + + + + cpe:/o:palm:palm_os:3.5.2 + + CVE-2001-0157 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:25.150-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A030101-1 + + + XF + palm-debug-bypass-password(6196) + + Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled. + + + + + + + + + + cpe:/h:lucent:wavelan + cpe:/h:orinoco:orinoco_wavelan + + CVE-2001-0160 + 2001-01-01T00:00:00.000-05:00 + 2008-09-05T16:23:25.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.cs.jhu.edu/~seny/pubs/wince802.pdf + + Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages. + + + + + + + + + cpe:/h:cisco:aironet:340-series + + CVE-2001-0161 + 2001-01-01T00:00:00.000-05:00 + 2008-09-05T16:23:25.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.cs.jhu.edu/~seny/pubs/wince802.pdf + + Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. + + + + + + + + + cpe:/o:microsoft:windows_ce:3.0.9348 + + CVE-2001-0162 + 2001-01-01T00:00:00.000-05:00 + 2008-09-05T16:23:25.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.cs.jhu.edu/~seny/pubs/wince802.pdf + + WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. + + + + + + + + + cpe:/h:cisco:aironet_ap340 + + CVE-2001-0163 + 2001-01-01T00:00:00.000-05:00 + 2008-09-05T16:23:25.727-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.cs.jhu.edu/~seny/pubs/wince802.pdf + + Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. + + + + + + + + + cpe:/a:netscape:directory_server:4.12 + + CVE-2001-0164 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:25.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A030701-1 + + + XF + netscape-directory-server-bo(6233) + + Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field. + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0165 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:26.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + solaris-ximp40-bo + + + BID + 2322 + + + BUGTRAQ + 20010131 [SPSadvisory#40]Solaris7/8 ximp40 shared library buffer overflow + + Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument. + + + + + + + + + cpe:/a:macromedia:shockwave_flash_plugin:8.0 + + CVE-2001-0166 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:26.180-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + shockwave-flash-swf-bo + + + BUGTRAQ + 20001229 Shockwave Flash buffer overflow + + Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file. + + + + + + + + + cpe:/a:att:winvnc:3.3.3r7 + + CVE-2001-0167 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:26.320-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + winvnc-client-bo + + + BID + 2305 + + + BUGTRAQ + 20010129 [CORE SDI ADVISORY] WinVNC client buffer overflow + + Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string. + + + + + + + + + cpe:/a:att:winvnc:3.3.3r7 + + CVE-2001-0168 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:26.463-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#598581 + + + BID + 2306 + + + BUGTRAQ + 20010129 [CORE SDI ADVISORY] WinVNC server buffer overflow + + + XF + winvnc-server-bo(6026) + + Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:turbolinux:turbolinux:6.0.5 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:6.0::i386 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:turbolinux:turbolinux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:6.1::i386 + + CVE-2001-0169 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:26.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2223 + + + BUGTRAQ + 20010121 Trustix Security Advisory - glibc + + + REDHAT + RHSA-2001:002 + + + MANDRAKE + MDKSA-2001:012 + + + XF + linux-glibc-preload-overwrite + + + SUSE + SuSE-SA:2001:01 + + + DEBIAN + DSA-039 + + + CALDERA + CSSA-2001-007 + + + TURBO + TLSA2000021-2 + + When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:6.0 + cpe:/o:conectiva:linux:ecommerce + cpe:/o:conectiva:linux:4.0es + cpe:/o:conectiva:linux:4.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + cpe:/o:debian:debian_linux:2.3 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:conectiva:linux:graficas + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.0::alpha + + CVE-2001-0170 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:26.807-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2181 + + + REDHAT + RHSA-2001:001 + + + BUGTRAQ + 20010110 [slackware-security] glibc 2.2 local vulnerability on setuid binaries + + + XF + linux-glibc-read-files + + + BUGTRAQ + 20010110 Glibc Local Root Exploit + + glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. + + + + + + + + + cpe:/a:whitsoft:slimserve:1.0 + + CVE-2001-0171 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:26.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + slimserve-httpd-dos + + + BID + 2318 + + + BUGTRAQ + 20010130 DOS Vulnerability in SlimServe HTTPd + + Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request. + + + + + + + + + + + + + + cpe:/a:hans_reiser:reiserfs:3.5.28 + cpe:/o:suse:suse_linux:7.0 + + CVE-2001-0172 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:27.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + suse-reiserfs-long-filenames + + + BID + 2180 + + + BUGTRAQ + 20010109 major security bug in reiserfs (may affect SuSE Linux) + + Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:qdecoder:qdecoder:4.3.1 + cpe:/a:nobreak_technologies:crazywwwboard:2000px + cpe:/a:nobreak_technologies:crazywwwboard:2000.0px + cpe:/a:nobreak_technologies:crazywwwboard:2000lepx + cpe:/a:qdecoder:qdecoder:5.0.1 + cpe:/a:qdecoder:qdecoder:5.0 + cpe:/a:qdecoder:qdecoder:5.0.2 + cpe:/a:nobreak_technologies:crazywwwboard:98 + cpe:/a:qdecoder:qdecoder:5.0.3 + cpe:/a:nobreak_technologies:crazywwwboard:3.0.1 + cpe:/a:nobreak_technologies:crazywwwboard:98pe + cpe:/a:qdecoder:qdecoder:4.0 + cpe:/a:qdecoder:qdecoder:4.0.1 + cpe:/a:nobreak_technologies:crazywwwboard:2000.0lepx + cpe:/a:qdecoder:qdecoder:4.3 + + CVE-2001-0173 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:27.273-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2329 + + + XF + crazywwwboard-qdecoder-bo + + + BUGTRAQ + 20010130 Nobreak Tecnologies CrazyWWWBoard Remote Buffer Overflow + + Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header. + + + + + + + + + cpe:/a:trend_micro:virus_buster_2001:8.0 + + CVE-2001-0174 + 2001-05-03T00:00:00.000-04:00 + 2013-08-03T00:16:05.240-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + virusbuster-mua-bo(6034) + + + OSVDB + 6138 + + + BUGTRAQ + 20010130 Security hole in Virus Buster 2001 + + Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address. + + + + + + + + + cpe:/a:netscape:fasttrack_server:4.0.1 + + CVE-2001-0175 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:27.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-fasttrack-cache-dos(5985) + + + BID + 2273 + + + BUGTRAQ + 20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications + + + BUGTRAQ + 20010122 def-2001-05: Netscape Fasttrack Server Caching DoS + + The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs. + + + + + + + + + cpe:/a:voyant_technologies:sonata:3.0 + + CVE-2001-0176 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:27.743-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2125 + + + BUGTRAQ + 20001218 More Sonata Conferencing software vulnerabilities. + + + XF + sonata-command-execute(5787) + + The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges. + + + + + + + + + cpe:/a:webmaster:conferenceroom:1.8.1 + + CVE-2001-0177 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:27.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2178 + + + XF + conferenceroom-developer-dos + + + BUGTRAQ + 20010110 Vulnerable: Conference Room Professional-Developer Edititon. + + WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:conectiva:linux:6.0 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.0 + + CVE-2001-0178 + 2001-03-26T00:00:00.000-05:00 + 2008-09-10T15:07:23.273-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001:018 + + + CALDERA + CSSA-2001-005.0 + + + XF + kde2-kdesu-retrieve-passwords + + + SUSE + SuSE-SA:2001:02 + + kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. + + + + + + + + + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-0179 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:28.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ALLAIRE + ASB01-02 + + + XF + jrun-webinf-file-retrieval + + Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "." + + + + + + + + + cpe:/a:lars_ellingsen:guestserver:4.12 + + CVE-2001-0180 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:28.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + guestserver-cgi-execute-commands + + + BUGTRAQ + 20010129 Remote Command Execution in guestserver.cgi + exploit + + Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter. + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:caldera:openlinux_eserver:2.3.1 + cpe:/a:caldera:openlinux_desktop:2.3 + + CVE-2001-0181 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:28.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2215 + + + CALDERA + CSSA-2001-003.0 + + + XF + dhcp-format-string + + Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + cpe:/a:checkpoint:firewall-1:4.1:sp3 + + CVE-2001-0182 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:28.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2238 + + + XF + fw1-limited-license-dos + + + BUGTRAQ + 20010117 Licensing Firewall-1 DoS Attack + + + OSVDB + 1733 + + FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources. + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.0:alpha + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2001-0183 + 2001-03-26T00:00:00.000-05:00 + 2008-09-10T15:07:23.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2293 + + + FREEBSD + FreeBSD-SA-01:08 + + + XF + ipfw-bypass-firewall(5998) + + + BUGTRAQ + 20010125 ecepass - proof of concept code for FreeBSD ipfw bypass + + + OSVDB + 1743 + + + CIAC + L-029 + + ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection. + + + + + + + + + cpe:/a:eeye_digital_security:iris:1.0.1 + + CVE-2001-0184 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:28.993-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eeye-iris-dos + + + BID + 2278 + + + BUGTRAQ + 20010121 eEye Iris the Network traffic analyser DoS + + + BUGTRAQ + 20010121 eEye Iris the Network traffic analyser DoS + + eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet. + + + + + + + + + cpe:/h:netopia:r9100_router:4.6 + + CVE-2001-0185 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:29.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2287 + + + XF + netopia-telnet-dos + + + BUGTRAQ + 20010123 Make The Netopia R9100 Router To Crash + + Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash. + + + + + + + + + cpe:/a:free_java_web_server:free_java_web_server:1.0 + + CVE-2001-0186 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:29.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010204 Vulnerability in Free Java Web Server + + Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.5 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr10 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr11 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr12 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr13 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr14 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr15 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr6 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr5 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr4 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr8 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr7 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta18::academ + cpe:/a:washington_university:wu-ftpd:2.6 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr16 + cpe:/a:washington_university:wu-ftpd:2.4.1 + cpe:/a:washington_university:wu-ftpd:2.4.2_vr17 + cpe:/a:washington_university:wu-ftpd:2.4.2_beta9::academ + + CVE-2001-0187 + 2001-03-26T00:00:00.000-05:00 + 2013-09-13T00:13:04.473-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2296 + + + XF + wuftp-debug-format-string + + + DEBIAN + DSA-016 + + + CONFIRM + ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch + + + CONECTIVA + CLA-2001:443 + + Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment. + + + + + + + + + + cpe:/a:goodtech:ftp_server_nt_2000:3.0.1 + cpe:/a:goodtech:ftp_server_95_98:3.0.1 + + CVE-2001-0188 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:29.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2270 + + + BUGTRAQ + 20010122 def-2001-03: GoodTech Systems FTP Connection DoS + + + XF + goodtech-ftp-dos + + GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash. + + + + + + + + + cpe:/a:intranet-server:localweb2000:1.1 + + CVE-2001-0189 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:29.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + localweb2k-directory-traversal + + + BID + 2268 + + + BUGTRAQ + 20010119 LocalWEB2000 Directory Traversal Vulnerability + + Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.7 + cpe:/o:sun:solaris:2.8 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0190 + 2001-03-26T00:00:00.000-05:00 + 2011-03-07T21:04:58.173-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010123 Solaris /usr/bin/cu Vulnerability + + + BUGTRAQ + 20010117 Solaris /usr/bin/cu Vulnerability + + + XF + cu-argv-bo(6224) + + Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0). + + + + + + + + + cpe:/a:andy_norman:gnuserv:3.11 + + CVE-2001-0191 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:30.070-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2001:011 + + + REDHAT + RHSA-2001:010 + + + MANDRAKE + MDKSA-2001:019 + + + BUGTRAQ + 20010202 Remote vulnerability in gnuserv/XEmacs + + + XF + gnuserv-tcp-cookie-overflow(6056) + + gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length. + + + + + + + + + cpe:/a:davide_libenzi:xmail:0.66 + + CVE-2001-0192 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:30.213-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://xmailserver.org/XMail-Readme.txt + + + BUGTRAQ + 20010201 XMail CTRLServer remote buffer overflow vulnerability + + Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:suse:suse_linux:7.0 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2001-0193 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:30.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2327 + + + DEBIAN + DSA-028 + + + BUGTRAQ + 20010131 SuSe / Debian man package format string vulnerability + + + XF + man-i-format-string(6059) + + Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter. + + + + + + + + + cpe:/a:easy_software_products:cups:1.1.4 + + CVE-2001-0194 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:30.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2001:020-1 + + + XF + cups-httpgets-dos(6043) + + + OSVDB + 6064 + + Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line. + + + + + + + + + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-0195 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:30.667-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-sash-shadow-readable + + + DEBIAN + DSA-015 + + sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:freebsd:freebsd:3.5 + + CVE-2001-0196 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:30.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2324 + + + FREEBSD + FreeBSD-SA-01:11 + + + XF + inetd-ident-read-files(6052) + + + OSVDB + 1753 + + inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group. + + + + + + + + + + + + + + + + + + cpe:/a:icecast:icecast:1.3.8_beta2 + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + cpe:/a:icecast:icecast:1.3.7 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0197 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:30.963-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2264 + + + REDHAT + RHSA-2001:004 + + + CONECTIVA + CLA-2001:374 + + + BUGTRAQ + 20010121 [pkc] format bugs in icecast 1.3.8b2 and prior + + + XF + icecast-format-string + + Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands. + + + + + + + + + + cpe:/a:apple:quicktime:4.1.2 + cpe:/a:apple:quicktime:4.1.2:::japanese + + CVE-2001-0198 + 2001-05-03T00:00:00.000-04:00 + 2013-04-04T21:08:02.797-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + quicktime-embedded-tag-bo + + + BID + 2328 + + + EXPLOIT-DB + 20605 + + + BUGTRAQ + 20010131 [SPSadvisory#41]Apple Quick Time Plug-in Buffer Overflow + + Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag. + + + + + + + + + cpe:/a:guido_frassetto:sedum:2.0 + + CVE-2001-0199 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:31.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#651994 + + + XF + sedum-directory-traversal(6063) + + + BID + 2335 + + + OSVDB + 14797 + + + BUGTRAQ + 20010204 Vulnerability in SEDUM HTTP Server + + Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request. + + + + + + + + + cpe:/a:heat-on_software:hsweb:2.0 + + CVE-2001-0200 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:31.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2336 + + + BUGTRAQ + 20010204 Web root exposure in HSWeb Webserver + + HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled. + + + + + + + + + + cpe:/a:umut_gokbayrak:postaci:1.1.3 + cpe:/a:umut_gokbayrak:postaci:1.1.2 + + CVE-2001-0201 + 2001-03-26T00:00:00.000-05:00 + 2008-09-10T15:07:27.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + postaci-sql-command-injection + + + BID + 2230 + + + BUGTRAQ + 20010117 Postaci allows arbitrary SQL query execution + + The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program. + + + + + + + + + cpe:/a:informs:picserver:1.0 + + CVE-2001-0202 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:31.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2339 + + + BUGTRAQ + 20010205 Vulnerability in Picserver + + Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request. + + + + + + + + + + + + + + cpe:/h:watchguard:firebox_ii:4.3 + cpe:/h:watchguard:firebox_ii:4.4 + cpe:/h:watchguard:firebox_ii:4.5 + cpe:/h:watchguard:firebox_ii:4.0 + cpe:/h:watchguard:firebox_ii:4.1 + cpe:/h:watchguard:firebox_ii:4.2 + + CVE-2001-0203 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:31.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2284 + + + BUGTRAQ + 20010120 Watchguard Firewall Elevated Privilege Vulnerability + + + XF + watchguard-firebox-obtain-passphrase + + Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication. + + + + + + + + + cpe:/h:watchguard:firebox_ii + + CVE-2001-0204 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:32.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2369 + + + BUGTRAQ + 20010214 def-2001-07: Watchguard Firebox II PPTP DoS + + + XF + firebox-pptp-dos(6109) + + Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets. + + + + + + + + + cpe:/a:aol:aol_server:3.2 + + CVE-2001-0205 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:32.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2343 + + + BUGTRAQ + 20010208 Vulnerability in AOLserver + + + BUGTRAQ + 20010206 Vulnerability in AOLserver + + Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack. + + + + + + + + + cpe:/a:soft_lite:serverworx:3.00 + + CVE-2001-0206 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:32.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010207 Vulnerability in Soft Lite ServerWorx + + + BID + 2346 + + Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request. + + + + + + + + + cpe:/a:pierre_beyssac:bing:1.0.4 + + CVE-2001-0207 + 2001-03-26T00:00:00.000-05:00 + 2008-09-10T15:07:28.447-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2279 + + + XF + linux-bing-bo + + + BUGTRAQ + 20010119 Buffer overflow in bing + + Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function. + + + + + + + + + cpe:/a:microfocus:cobol:4.1 + + CVE-2001-0208 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:32.633-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2359 + + + BUGTRAQ + 20010211 Security Hole in Microfocus Cobol + + MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files. + + + + + + + + + cpe:/a:shoutcast:dnas:1.7.1 + + CVE-2001-0209 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:32.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + shoutcast-description-bo + + + BUGTRAQ + 20010118 Shoutcast Server Buffer Crashes Server + + Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description. + + + + + + + + + cpe:/a:carey_internet_service:commerce.cgi:2.0.1 + + CVE-2001-0210 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:32.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010212 Commerce.cgi Directory Traversal + + + BID + 2361 + + Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter. + + + + + + + + + cpe:/a:silverplatter:webspirs:3.3.1 + + CVE-2001-0211 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:33.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2362 + + + BUGTRAQ + 20010212 WebSPIRS CGI script "show files" Vulnerability. + + Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter. + + + + + + + + + cpe:/a:his:auktion:1.62 + + CVE-2001-0212 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:33.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2367 + + + BUGTRAQ + 20010212 HIS Auktion 1.62: "show files" vulnerability and remote command execute. + + Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters. + + + + + + + + + cpe:/a:planet_intra:planet_intra:2.5 + + CVE-2001-0213 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:33.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + planetintra-pi-bo + + + BUGTRAQ + 200101125 [SAFER] Security Bulletin 010125.EXP.1.12 + + Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:way:way-board:cgi + + CVE-2001-0214 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:33.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2370 + + + BUGTRAQ + 20010212 Way board: "show files" Vulnerability with null bite bug + + Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte. + + + + + + + + + cpe:/a:martin_hamilton:roads:2.3 + + CVE-2001-0215 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:33.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2371 + + + CONFIRM + http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html + + + BUGTRAQ + 20010212 ROADS search system "show files" Vulnerability with "null bite" bug + + + XF + roads-search-view-files(6097) + + ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte. + + + + + + + + + cpe:/a:mnscu_pals:webpals:1.0 + + CVE-2001-0216 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:33.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2372 + + + BUGTRAQ + 20010212 PALS Library System "show files" Vulnerability and remote command execution + + + XF + webpals-library-cgi-url(6102) + + PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter. + + + + + + + + + cpe:/a:mnscu_pals:webpals:1.0 + + CVE-2001-0217 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:34.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2372 + + + BUGTRAQ + 20010212 PALS Library System "show files" Vulnerability and remote command execution + + + XF + webpals-library-cgi-url(6102) + + Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter. + + + + + + + + + cpe:/a:martin_stover:mars_nwe:0.99_pl19 + + CVE-2001-0218 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:30.743-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-01:20 + + + BUGTRAQ + 20010126 format string vulnerability in mars_nwe 0.99pl19 + + + XF + mars-nwe-format-string(6019) + + Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands. + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + + CVE-2001-0219 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:34.307-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2239 + + + HP + HPSBUX0101-137 + + + XF + hp-stm-dos + + + OSVDB + 7030 + + + OSVDB + 7029 + + + OSVDB + 6991 + + Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service. + + + + + + + + + + cpe:/a:ko-helvis:ko-helvis:1.8h2_1 + cpe:/a:ja-elvis:ja-elvis:1.8.4_1 + + CVE-2001-0220 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:34.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-01:21 + + Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges. + + + + + + + + + cpe:/a:freebsd:ja-xklock:2.7.1 + + CVE-2001-0221 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:34.617-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + FREEBSD + FreeBSD-SA-01:19 + + + XF + ja-xklock-bo(6073) + + Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges. + + + + + + + + + cpe:/a:webmin:webmin:0.83 + + CVE-2001-0222 + 2001-03-26T00:00:00.000-05:00 + 2011-03-07T21:05:00.893-05:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001-016 + + + CALDERA + CSSA-2001-004.0 + + + XF + linux-webmin-tmpfiles + + webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:spawar.navy.mil:wwwwais.25.c + + CVE-2001-0223 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:34.917-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + wwwwais-cgi-dos + + + BUGTRAQ + 20010117 numerous holes + + Buffer overflow in wwwwais allows remote attackers to execute arbitrary commands via a long QUERY_STRING (HTTP GET request). + + + + + + + + + cpe:/a:brightstation:muscat_empower:1.0 + + CVE-2001-0224 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:35.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2374 + + + BUGTRAQ + 20010212 Vulnerability in Muscat Empower wich can print path to DB-dir. + + + XF + muskat-empower-url-dir(6093) + + Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. + + + + + + + + + cpe:/a:lenzo:infobot:0.44.5.3 + + CVE-2001-0225 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:35.210-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010207 Infobot 0.44.5.3/below remotely vulnerable (also in FreeBSD ports tree) + + + BID + 2349 + + fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/a:biblioscape:biblioweb_server:2.0 + + CVE-2001-0226 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:35.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010205 Vulnerabilities in BiblioWeb Server + + Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers tor ead arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request. + + + + + + + + + cpe:/a:biblioscape:biblioweb_server:2.0 + + CVE-2001-0227 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:35.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010205 Vulnerabilities in BiblioWeb Server + + Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. + + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:v.2.0 + cpe:/a:goahead_software:goahead_webserver:v.2.1 + + CVE-2001-0228 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:35.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010202 GoAhead Web Server Directory Traversal Vulnerability + + Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request. + + + + + + + + + cpe:/a:sun:chilisoft:3.6 + + CVE-2001-0229 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:35.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010206 Security hole in ChiliSoft ASP on Linux. + + Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts. + + + + + + + + + cpe:/o:freebsd:freebsd:0.4_1 + + CVE-2001-0230 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:35.947-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + FREEBSD + FreeBSD-SA-01:22 + + + XF + dc20ctrl-port-bo(6077) + + + OSVDB + 6081 + + Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges. + + + + + + + + + cpe:/a:ibrow:news_desk:1.2 + + CVE-2001-0231 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:36.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#496064 + + + XF + newsdesk-cgi-read-files(5898) + + + BID + 2172 + + + BUGTRAQ + 20010103 News Desk 1.2 CGI Vulnerbility + + Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter. + + + + + + + + + cpe:/a:ibrow:news_desk:1.2 + + CVE-2001-0232 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:36.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010103 News Desk 1.2 CGI Vulnerbility + + newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters. + + + + + + + + + + + + + + + + + + cpe:/a:matthew_smith:micq:0.4.6 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0233 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:36.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2001:005 + + + DEBIAN + DSA-012 + + + BUGTRAQ + 20010124 patch Re: [PkC] Advisory #003: micq-0.4.6 remote buffer overflow + + + FREEBSD + FreeBSD-SA-01:14 + + + XF + micq-sprintf-remote-bo(5962) + + + BUGTRAQ + 20010118 [PkC] Advisory #003: micq-0.4.6 remote buffer overflow + + Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field. + + + + + + + + + cpe:/a:sourceforge:newsdaemon:0.21b + + CVE-2001-0234 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:36.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010126 NewsDaemon remote administrator access + + + XF + newsdaemon-gain-admin-access + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=60570 + + NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter. + + + + + + + + + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-0235 + 2001-03-26T00:00:00.000-05:00 + 2008-09-05T16:23:36.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-024 + + + FREEBSD + FreeBSD-SA-01:09 + + + XF + crontab-read-files(6225) + + + BID + 2332 + + Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0236 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:36.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-05 + + + BID + 2417 + + + BUGTRAQ + 20010314 Solaris /usr/lib/dmi/snmpXdmid vulnerability + + + XF + solaris-snmpxdmid-bo(6245) + + + CIAC + L-065 + + + SUN + 00207 + + Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2001-0237 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:36.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-024 + + + BUGTRAQ + 20010509 def-2001-24: Windows 2000 Kerberos DoS + + + XF + win2k-kerberos-dos(6506) + + + BID + 2707 + + + CIAC + L-079 + + Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0238 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:37.150-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-022 + + + XF + ms-dacipp-webdav-access(6405) + + + CIAC + L-074 + + Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests. + + + + + + + + + cpe:/a:microsoft:isa_server:2000 + + CVE-2001-0239 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:37.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2600 + + + MS + MS01-021 + + + BUGTRAQ + 20010427 Microsoft ISA Server Vulnerability + + + BUGTRAQ + 20010417 [SX-20010320-2b] - Followup re. Microsoft ISA Server Denial of Service + + + BUGTRAQ + 20010416 [SX-20010320-2] - Microsoft ISA Server Denial of Service + + + XF + isa-web-proxy-dos(6383) + + + CIAC + L-073 + + Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type. + + + + + + + + + + + + + cpe:/a:microsoft:word:98:::japanese + cpe:/a:microsoft:word:2001::mac + cpe:/a:microsoft:word:97 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:word:98::mac + + CVE-2001-0240 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:37.447-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-028 + + + XF + word-rtf-macro-execution(6571) + + + BID + 2753 + + Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro. + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2001-0241 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:37.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT + CA-2001-10 + + + BID + 2674 + + + MS + MS01-023 + + + BUGTRAQ + 20010501 Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access) + + + XF + iis-isapi-printer-bo(6485) + + + OSVDB + 3323 + + + + + Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0. + + + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + cpe:/a:microsoft:windows_media_player:6.3 + + CVE-2001-0242 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:37.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#187528 + + + MS + MS01-029 + + + XF + mediaplayer-asx-bo(5574) + + + BID + 2686 + + + BID + 2677 + + + BUGTRAQ + 20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability + + + BUGTRAQ + 20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability + + Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090. + + + + + + + + + + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2001-0243 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:37.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-029 + + + XF + mediaplayer-html-shortcut(6584) + + + BID + 2765 + + Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files. + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-2001-0244 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:38.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-025 + + + XF + winnt-indexserver-search-bo(6517) + + + BID + 2709 + + Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter. + + + + + + + + + + cpe:/a:microsoft:indexing_service + cpe:/a:microsoft:index_server:2.0 + + CVE-2001-0245 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:38.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-025 + + + XF + win-indexserver-view-files(6518) + + Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0246 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:38.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-027 + + Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:openbsd:openbsd:2.8 + cpe:/a:mit:kerberos:5-1.2.2 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:sgi:irix:6.5.1 + cpe:/a:mit:kerberos:5-1.2 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:freebsd:freebsd:4.0 + cpe:/a:mit:kerberos:5-1.2.1 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:sgi:irix:6.1 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:sgi:irix:6.5.3m + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + cpe:/o:sgi:irix:6.5.3f + cpe:/a:mit:kerberos:5_1.1.1 + + CVE-2001-0247 + 2001-06-18T00:00:00.000-04:00 + 2011-03-07T21:05:02.797-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-07 + + + BID + 2548 + + + FREEBSD + FreeBSD-SA-01:33 + + + NETBSD + NetBSD-SA2000-018 + + + XF + ftp-glob-expansion(6332) + + + NAI + 20010409 Globbing Vulnerabilities in Multiple FTP Daemons + + + SGI + 20010802-01-P + + Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.00 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.30 + + CVE-2001-0248 + 2001-06-18T00:00:00.000-04:00 + 2008-09-10T15:07:35.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-07 + + + BID + 2552 + + + XF + ftp-glob-expansion(6332) + + + NAI + 20010409 Globbing Vulnerabilities in Multiple FTP Daemons + + Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0249 + 2001-06-18T00:00:00.000-04:00 + 2008-09-10T15:07:35.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-07 + + + BID + 2550 + + + XF + ftp-glob-expansion(6332) + + + NAI + 20010409 Globbing Vulnerabilities in Multiple FTP Daemons + + Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.0 + cpe:/a:netscape:enterprise_server:4.0 + + CVE-2001-0250 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-enterprise-list-directories + + + BID + 2285 + + + BUGTRAQ + 20010124 [SAFER] Security Bulletin 010124.EXP.1.11 + + The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command. + + + + + + + + + cpe:/a:netscape:enterprise_server:3.0 + + CVE-2001-0251 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-enterprise-revlog-dos + + + BID + 2294 + + + BUGTRAQ + 20010125 [SAFER] Security Bulletin 010125.DOS.1.5 + + The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command. + + + + + + + + + cpe:/a:iplanet:iplanet_enterprise_server:4.1sp5 + + CVE-2001-0252 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-enterprise-dot-dos + + + BID + 2282 + + + BUGTRAQ + 20010122 def-2001-04: Netscape Enterprise Server Dot-DoS + + + BUGTRAQ + 20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications + + iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences. + + + + + + + + + cpe:/a:iweb_systems:hyperseek:2000 + + CVE-2001-0253 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#146704 + + + BID + 2314 + + + XF + hyperseek-cgi-reveal-info + + + BUGTRAQ + 20010128 Hyperseek 2000 Search Engine - "show directory & files" bug + + Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter. + + + + + + + + + cpe:/a:fastream:ftp%2b%2b_server:2.0 + + CVE-2001-0254 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS) + + FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command. + + + + + + + + + + cpe:/a:fastream:fastream_ftp_server:2.0beta_11 + cpe:/a:fastream:fastream_ftp%2b%2b_server:2.0 + + CVE-2001-0255 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fastream-ftp-path-disclosure + + + BUGTRAQ + 20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS) + + + BID + 2267 + + FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname. + + + + + + + + + cpe:/a:fastream:ftp%2b%2b_server:2.0 + + CVE-2001-0256 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:39.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS) + + + XF + fastream-ftp-server-dos + + + BID + 2261 + + FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username. + + + + + + + + + cpe:/a:i-data_international:easycom_safecom_print_server:1.0 + + CVE-2001-0257 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + easycom-safecom-url-bo + + + BID + 2291 + + + BUGTRAQ + 20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS + + Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:". + + + + + + + + + cpe:/a:i-data_international:easycom_safecom_print_server:1.0 + + CVE-2001-0258 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + easycom-safecom-printguide-dos + + + BUGTRAQ + 20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS + + The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters. + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + + CVE-2001-0259 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.413-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ssh-rpc-private-key + + + BID + 2222 + + + BUGTRAQ + 20010116 Bug in SSH1 secure-RPC support can expose users' private keys + + + CONFIRM + http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html + + ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file. + + + + + + + + + cpe:/a:lotus:domino_mail_server:5.0.5 + + CVE-2001-0260 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + lotus-domino-smtp-bo + + + BID + 2283 + + + BUGTRAQ + 20010123 [SAFER] Security Bulletin 010123.EXP.1.10 + + + OSVDB + 3321 + + Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0261 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win2k-efs-recover-data + + + BID + 2243 + + + BUGTRAQ + 20010123 Reply to EFS note on Bugtraq + + + BUGTRAQ + 20010119 BugTraq: EFS Win 2000 flaw + + Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files. + + + + + + + + + cpe:/a:netscape:smartdownload:1.3 + + CVE-2001-0262 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:40.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A041301-1 + + Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. + + + + + + + + + cpe:/a:gene6:g6_ftp_server:2.0 + + CVE-2001-0263 + 2001-06-18T00:00:00.000-04:00 + 2013-07-31T00:11:38.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + bpftp-obtain-credentials(6330) + + + ATSTAKE + A040301-1 + + + BID + 2537 + + Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled. + + + + + + + + + cpe:/a:gene6:g6_ftp_server:2.0 + + CVE-2001-0264 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:41.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2534 + + + ATSTAKE + A040301-1 + + Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. + + + + + + + + + + cpe:/a:pgp:pgp:7.0.3 + cpe:/a:pgp:pgp:5 + + CVE-2001-0265 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:41.307-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A040901-1 + + + XF + pgp-armor-code-execution(6643) + + + BID + 2556 + + + OSVDB + 1782 + + ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2001-0266 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:41.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX0102-143 + + + OSVDB + 6033 + + Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges. + + + + + + + + + cpe:/o:hp:mpe_ix:5.5 + + CVE-2001-0267 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:41.587-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBMP0102-008 + + + XF + hp-nmdebug-gain-privileges(6226) + + + OSVDB + 6032 + + NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges. + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:openbsd:openbsd:2.8 + + CVE-2001-0268 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:38.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#358960 + + + NETBSD + NetBSD-SA:2001-002 + + + XF + user-ldt-validation(6222) + + + BID + 2739 + + + OSVDB + 6141 + + + OPENBSD + 20010302 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory. + + + CALDERA + CSSA-2001-SCO.35 + + + BUGTRAQ + 20010219 Re: your mail + + The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address. + + + + + + + + + cpe:/o:sun:solaris:8.0 + + CVE-2001-0269 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:41.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010217 Solaris 8 pam_ldap.so.1 module broken + + + XF + solaris-pamldap-bypass-authentication(6440) + + + OSVDB + 6030 + + pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password. + + + + + + + + + + + + + + cpe:/h:marconi:asx-1000 + cpe:/a:marconi:forethought:6.2 + + CVE-2001-0270 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2400 + + + BUGTRAQ + 20010219 Denial of Service Condition exists in Fore/Marconi ASX Switches + + Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set. + + + + + + + + + cpe:/a:mailnews.cgi:mailnews.cgi:1.3 + + CVE-2001-0271 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010218 mailnews.cgi + + + BID + 2391 + + mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters. + + + + + + + + + cpe:/a:w3.org:sendtemp.pl + + CVE-2001-0272 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010212 W3.ORG sendtemp.pl + + Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter. + + + + + + + + + cpe:/a:holger_lamm:pgp4pine:1.75.6 + + CVE-2001-0273 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.507-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#566640 + + + BUGTRAQ + 20010220 [CryptNET Advisory] pgp4pine-1.75-6 - expired public keys + + + XF + pgp4pine-expired-keys(6135) + + + BID + 2405 + + pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext. + + + + + + + + + cpe:/a:kicq:kicq:1.0.0 + + CVE-2001-0274 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010303 Re: Security hole in kicq + + + BUGTRAQ + 20010214 Security hole in kicq + + + XF + kicq-execute-commands(6112) + + kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. + + + + + + + + + cpe:/a:moby:netsuite_web_server:1.02 + + CVE-2001-0275 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.807-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010219 NetSuite 1.02 web server vulnerabilty + + Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.2.7 + + CVE-2001-0276 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:42.947-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2390 + + + BUGTRAQ + 20010217 BadBlue Web Server Ext.dll Vulnerabilities + + + CONFIRM + http://www.badblue.com/p010219.htm + + + XF + badblue-ext-reveal-path(6130) + + ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.2.7 + + CVE-2001-0277 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:43.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2392 + + + BUGTRAQ + 20010217 BadBlue Web Server Ext.dll Vulnerabilities + + Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. + + + + + + + + + cpe:/o:hp:mpe_ix:6.5 + + CVE-2001-0278 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:43.290-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBMP0102-009 + + + XF + hp-linkeditor-gain-privileges(6223) + + Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges. + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + + CVE-2001-0279 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:43.460-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2001:024 + + + DEBIAN + DSA-031 + + + BUGTRAQ + 20010222 Sudo version 1.6.3p6 now available (fwd) + + + REDHAT + RHSA-2001:019 + + + REDHAT + RHSA-2001:018 + + + CONECTIVA + CLA-2001:381 + + + BUGTRAQ + 20010225 [slackware-security] buffer overflow in sudo fixed + + + BUGTRAQ + 20010226 Trustix Security Advisory - sudo + + Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges. + + + + + + + + + cpe:/a:atrium_software:mercur + + CVE-2001-0280 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:43.617-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010223 Mercur Mailserver 3.3 buffer overflow with EXPN + + + XF + mercur-expn-bo(6149) + + + OSVDB + 6027 + + Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. + + + + + + + + + cpe:/o:microsoft:windows_nt + + CVE-2001-0281 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:43.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010221 NT drivers are potentially vulnerable to format string bug + + Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. + + + + + + + + + cpe:/a:guido_frassetto:sedum:2.1 + + CVE-2001-0282 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:39.820-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010223 SEDUM v2.1 HTTPd - Denial of Service + + SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. + + + + + + + + + cpe:/a:sun:sun_ftp:build_9 + + CVE-2001-0283 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.057-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010302 Sunftp build9(1) - ftp server Vulnerability + + Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT. + + + + + + + + + cpe:/o:openbsd:openbsd:2.8 + + CVE-2001-0284 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:39.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OSVDB + 6026 + + + OPENBSD + 20010302 Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun in the kernel. + + Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option. + + + + + + + + + cpe:/a:a1webserver:http_server:1.0 + + CVE-2001-0285 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.350-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010226 A1 Server v1.0a HTTPd (DoS & Dir Traversal) + + Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. + + + + + + + + + cpe:/a:a1webserver:http_server:1.0 + + CVE-2001-0286 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010226 A1 Server v1.0a HTTPd (DoS & Dir Traversal) + + Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. + + + + + + + + + cpe:/a:symantec_veritas:cluster_server:1.3.0 + + CVE-2001-0287 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.647-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://seer.support.veritas.com/docs/234326.htm + + + BUGTRAQ + 20010302 Option to VERITAS Cluster Server (VCS) lltstat command will panic system. + + + OSVDB + 6025 + + VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command. + + + + + + + + + cpe:/o:cisco:ios:12.1 + + CVE-2001-0288 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010228 Cisco IOS Software TCP Initial Sequence Number Randomization Improvements + + Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. + + + + + + + + + cpe:/a:joseph_allen:joe:2.8 + + CVE-2001-0289 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:44.930-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MANDRAKE + MDKSA-2001:026 + + + DEBIAN + DSA-041 + + + BUGTRAQ + 20010228 Joe's Own Editor File Handling Error + + + REDHAT + RHSA-2001:024 + + Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory. + + + + + + + + + cpe:/a:gnu:mailman:2.0.2 + + CVE-2001-0290 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010306 [Mailman-Announce] ANNOUNCE Mailman 2.0.2 (important privacy patch) + + Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. + + + CVE-2001-0291 + 2001-05-03T00:00:00.000-04:00 + 2005-10-20T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010305 Remote buffer overflow condition in post-query (CGI). + + Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.4.1a + + CVE-2001-0292 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010302 PHPNUKE4.4.1a Advisory + + PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator. + + + + + + + + + cpe:/a:datawizard:ftpxq:2.0.93 + + CVE-2001-0293 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2426 + + + BUGTRAQ + 20010228 Vulnerability in FtpXQ Server + + Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. + + + + + + + + + cpe:/a:typsoft:typsoft_ftp_server:0.85 + + CVE-2001-0294 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010228 Vulnerability in TYPSoft FTP Server + + Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command. + + + + + + + + + cpe:/a:jarle_aase:war_ftpd:1.67b04 + + CVE-2001-0295 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2444 + + + BUGTRAQ + 20010306 Warftp 1.67b04 Directory Traversal + + + OSVDB + 874 + + + CONFIRM + http://support.jgaa.com/?cmd=ShowArticle&ID=31 + + Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command. + + + + + + + + + cpe:/a:texas_imperial_software:wftpd_pro:3.00 + + CVE-2001-0296 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:45.913-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010303 WFTPD Pro 3.00 R1 Buffer Overflow + + Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. + + + + + + + + + cpe:/a:dattaraj_rao:simple_server:1.0 + + CVE-2001-0297 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:46.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2415 + + + BUGTRAQ + 20010224 The Simple Server HTTPd Directory Traversal + + Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. + + + + + + + + + cpe:/a:sapio_design_ltd:webreflex:1.55 + + CVE-2001-0298 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:46.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2425 + + + BUGTRAQ + 20010227 WebReflex 1.55 HTTPd DoS + + Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request. + + + + + + + + + cpe:/h:nokia:ip440_firewall_vpn_appliance:1.0 + + CVE-2001-0299 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:46.350-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2054 + + + BUGTRAQ + 20001205 Nokia firewalls - Response from Nokia + + + BUGTRAQ + 20001127 Nokia firewalls + + + XF + nokia-ip440-bo(5640) + + + OSVDB + 6020 + + Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL. + + + + + + + + + cpe:/a:oracle:internet_directory:2.1.1.1 + + CVE-2001-0300 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:46.493-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#610904 + + + BUGTRAQ + 20001222 vulnerability #2 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7 + + + XF + oracle-oidldap-write-permission(5804) + + oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack. + + + + + + + + + + cpe:/a:stephen_turner:analog:4.90_beta2 + cpe:/a:stephen_turner:analog:4.15 + + CVE-2001-0301 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:46.633-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2377 + + + DEBIAN + DSA-033 + + + CONFIRM + http://www.analog.cx/security2.html + + + REDHAT + RHSA-2001:017 + + + BUGTRAQ + 20010213 Security advisory for analog + + + XF + analog-alias-bo(6105) + + + OSVDB + 1762 + + Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings. + + + + + + + + + cpe:/a:pi3:pi3web:1.0.1 + + CVE-2001-0302 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:46.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2381 + + + BUGTRAQ + 20010215 Vulnerabilities in Pi3Web Server + + Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL. + + + + + + + + + cpe:/a:pi3:pi3web:1.0.1 + + CVE-2001-0303 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:46.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2381 + + + BUGTRAQ + 20010215 Vulnerabilities in Pi3Web Server + + tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file. + + + + + + + + + cpe:/a:caucho_technology:resin:1.2.2 + + CVE-2001-0304 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:47.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2384 + + + BUGTRAQ + 20010216 Vulnerability in Resin Webserver + + Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request. + + + + + + + + + cpe:/a:thinking_arts:es.one:1.0 + + CVE-2001-0305 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:47.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2385 + + + BUGTRAQ + 20010216 Thinking Arts Store.cgi Directory Traversal + + Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter. + + + + + + + + + cpe:/a:itafrica:webactive:1.0 + + CVE-2001-0306 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:47.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2386 + + + BUGTRAQ + 20010216 WEBactive HTTP Server 1.0 Directory Traversal + + Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. + + + + + + + + + cpe:/a:bajie:java_http_server:0.79 + + CVE-2001-0307 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:47.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BUGTRAQ + 20010216 Vulnerabilities in Bajie Http JServer + + + CONFIRM + http://www.geocities.com/gzhangx/websrv/docs/security.html + + Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. + + + + + + + + + cpe:/a:bajie:java_http_server:0.79 + + CVE-2001-0308 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:47.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 2388 + + + CONFIRM + http://www.geocities.com/gzhangx/websrv/docs/security.html + + + BUGTRAQ + 20010216 Vulnerabilities in Bajie Http JServer + + UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program. + + + + + + + + + cpe:/o:redhat:linux:6.2 + + CVE-2001-0309 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:47.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:006 + + + XF + inetd-internal-socket-dos(6380) + + inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:3.5.1 + + CVE-2001-0310 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:47.960-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sort-temp-file-abort + + + BID + 3960 + + + FREEBSD + FreeBSD-SA-01:13 + + sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts. + + + + + + + + + + + + + + cpe:/a:hp:omniback_ii:a.03.50 + cpe:/o:hp:hp-ux:11 + + CVE-2001-0311 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:48.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + omniback-unauthorized-access(6434) + + + HP + HPSBUX0102-142 + + + HPBUG + PHSS_22915 + + + HPBUG + PHSS_22914 + + Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. + + + + + + + + + cpe:/a:ibm:websphere_plugin + + CVE-2001-0312 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:48.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010125 Yet Another IBM WebSphere Showcode Vulerability + + IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing. + + + + + + + + + cpe:/h:borderware:firewall_server:6.1.2 + + CVE-2001-0313 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:48.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + borderware-ping-dos + + + BUGTRAQ + 20010126 Borderware v6.1.2 ping DoS vulnerability + + Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network. + + + + + + + + + cpe:/a:aol:aol_server:5.0 + + CVE-2001-0314 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:48.553-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aol-malformed-url-dos + + + BUGTRAQ + 20010125 America Online 5.0 contains a buffer overflow + + Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link. + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc:5.7 + + CVE-2001-0315 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:48.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mirc-bypass-password + + + BUGTRAQ + 20010125 mIRC allows password protection to be bypassed + + The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.2.0 + + CVE-2001-0316 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:44.103-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2001-009 + + + BUGTRAQ + 20010213 Trustix Security Advisory - proftpd, kernel + + + XF + linux-sysctl-read-memory(6079) + + + BID + 2364 + + + REDHAT + RHSA-2001:013 + + + OSVDB + 6017 + + Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.2.0 + + CVE-2001-0317 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:07:44.197-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2001-009 + + + BUGTRAQ + 20010213 Trustix Security Advisory - proftpd, kernel + + + XF + linux-ptrace-modify-process(6080) + + + REDHAT + RHSA-2001:013 + + Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process. + + + + + + + + + cpe:/a:proftpd_project:proftpd:1.2.0_rc2 + + CVE-2001-0318 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:49.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001:021 + + + DEBIAN + DSA-029 + + + BUGTRAQ + 20010206 Response to ProFTPD issues + + + XF + proftpd-format-string(6433) + + + BUGTRAQ + 20010110 proftpd 1.2.0rc2 -- example of bad coding + + + CONECTIVA + CLA-2001:380 + + Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd). + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ibm:net.commerce:3.1.2::start + cpe:/a:ibm:net.commerce:3.1.1::start + cpe:/a:ibm:net.commerce:3.1::start + cpe:/a:ibm:net.commerce:3.1.1::pro + cpe:/a:ibm:websphere_commerce_suite:4.1.1::pro + cpe:/a:ibm:websphere_commerce_suite:3.2::service_provider + cpe:/a:ibm:net.commerce:3.2::pro + cpe:/a:ibm:websphere_commerce_suite:4.1::marketplace + cpe:/a:ibm:net.commerce_hosting_server:3.2 + cpe:/a:ibm:net.commerce:3.1::pro + cpe:/a:ibm:net.commerce:3.2::start + cpe:/a:ibm:websphere_commerce_suite:4.1::pro + cpe:/a:ibm:websphere_commerce_suite:3.1.2::service_provider + cpe:/a:ibm:net.commerce:2.0 + cpe:/a:ibm:websphere_commerce_suite:4.1::start + cpe:/a:ibm:websphere_commerce_suite:4.1.1::start + cpe:/a:ibm:net.commerce:3.1.2::pro + cpe:/a:ibm:net.commerce_hosting_server:3.1.1 + cpe:/a:ibm:net.commerce_hosting_server:3.1.2 + cpe:/a:ibm:net.commerce:3.0 + + CVE-2001-0319 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:49.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2350 + + + CONFIRM + http://www-4.ibm.com/software/webservers/commerce/netcomletter.html + + + BUGTRAQ + 20010205 IBM NetCommerce Security + + + XF + ibm-netcommerce-reveal-information(6067) + + orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability. + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.0.4 + cpe:/a:francisco_burzi:php-nuke:4.4 + + CVE-2001-0320 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:49.507-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010223 Yet another hole in PHP-Nuke + + bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:8.0_final + + CVE-2001-0321 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:49.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010212 Fwd: Re: phpnuke, security problem... + + + XF + phpnuke-opendir-read-files(6512) + + opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter. + + + + + + + + + + + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2001-0322 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:23:49.803-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-mshtml-dos + + + BID + 2202 + + + BUGTRAQ + 20010115 Stack Overflow in MSHTML.DLL + + MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object. + + + CVE-2001-0323 + 2001-06-02T00:00:00.000-04:00 + 2013-10-10T21:11:45.360-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + icmp-pmtu-dos + + + CONFIRM + http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html + + + MANDRIVA + MDVSA-2013:150 + + + BUGTRAQ + 20010115 ICMP fragmentation required but DF set problems. + + The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_2000 + + CVE-2001-0324 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:50.053-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2340 + + + BUGTRAQ + 20010206 Windows client UDP exhaustion denial of service + + Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash. + + + + + + + + + cpe:/a:qnx:rtp:5.60 + + CVE-2001-0325 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:50.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2342 + + + BUGTRAQ + 20010202 QNX RTP ftpd stack overflow + + Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command. + + + + + + + + + + cpe:/a:oracle:application_server:release_1.0.2.0.1 + cpe:/a:oracle:oracle8i:8.1.7_r3 + + CVE-2001-0326 + 2001-05-03T00:00:00.000-04:00 + 2008-09-05T16:23:50.350-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010212 Solution for Potential Vunerability in Granting FilePermission to Oracle Java Virtual Machine + + + XF + oracle-jvm-file-permissions(6438) + + + OSVDB + 5706 + + Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1_enterprise + + CVE-2001-0327 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:50.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#276767 + + + ATSTAKE + A041601-1 + + + CONFIRM + http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html + + + OSVDB + 5704 + + iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server. + + + CVE-2001-0328 + 2001-06-27T00:00:00.000-04:00 + 2009-03-04T00:07:42.703-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT + CA-2001-09 + + + SREASON + 57 + + + SGI + 20030201-01-P + + + + + TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + + CVE-2001-0329 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:07:46.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A043001-1 + + + BID + 1199 + + + CONFIRM + http://www.mozilla.org/projects/bugzilla/security2_12.html + + Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + + CVE-2001-0330 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:50.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2671 + + + ATSTAKE + A043001-1 + + + XF + bugzilla-gobalpl-gain-information(6489) + + Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed. + + + + + + + + + + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.8 + + CVE-2001-0331 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.053-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#258632 + + + ISS + 20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure + + + XF + irix-espd-bo(6502) + + + BID + 2714 + + + OSVDB + 1822 + + + SGI + 20010501-01-P + + Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0332 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-027 + + + BUGTRAQ + 20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl + + Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0333 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + + CERT + CA-2001-12 + + + MS + MS01-026 + + + BUGTRAQ + 20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability + + + XF + iis-url-decoding(6534) + + + BID + 2708 + + + + + + + + + + + + + + Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0334 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-026 + + + XF + iis-ftp-wildcard-dos(6535) + + FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0335 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-026 + + + XF + iis-ftp-domain-authentication(6545) + + + BID + 2719 + + FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0336 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-026 + + + XF + iis-crosssitescripting-patch-dos(6858) + + + OSVDB + 5693 + + The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0337 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:51.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-026 + + The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0338 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:52.070-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-027 + + + XF + ie-crl-certificate-spoofing(6555) + + + BID + 2735 + + + CIAC + L-087 + + Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability." + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0339 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:52.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS01-027 + + + XF + ie-html-url-spoofing(6556) + + + BID + 2737 + + + OSVDB + 5694 + + + CIAC + L-087 + + + + + Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability." + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:5.5 + + CVE-2001-0340 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:52.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-030 + + + XF + exchange-owa-script-execution(6652) + + + CIAC + L-091 + + An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/a:microsoft:frontpage_server_extensions:2000 + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2001-0341 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:52.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2906 + + + MS + MS01-035 + + + BUGTRAQ + 20010625 NSFOCUS SA2001-03 : Microsoft FrontPage 2000 Server Extensions Buffer Overflow Vulnerability + + + XF + frontpage-ext-rad-bo(6730) + + + OSVDB + 577 + + Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:2000:gold + + CVE-2001-0344 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:52.773-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + MS + MS01-032 + + + XF + mssql-cached-connection-access(6684) + + + CIAC + L-095 + + + + + An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0345 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:07:47.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-031 + + + XF + win2k-telnet-idle-sessions-dos(6667) + + + BID + 2843 + + Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0346 + 2001-07-21T00:00:00.000-04:00 + 2011-03-07T21:05:11.407-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win2k-telnet-handle-leak-dos(6668) + + + MS + MS01-031 + + Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0347 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:53.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS01-031 + + + XF + win2k-telnet-domain-authentication(6665) + + + BID + 2847 + + + OSVDB + 5686 + + + CIAC + L-092 + + Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0348 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:07:47.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-031 + + + XF + win2k-telnet-username-dos(6666) + + + CIAC + L-092 + + + BINDVIEW + 20010608 Range checking fault condition in Microsoft Windows 2000 Telnet server + + Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0349 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:53.553-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#587587 + + + MS + MS01-031 + + + XF + win2k-telnet-pipe-privileges(6664) + + + BID + 2849 + + Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0350 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:53.710-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-031 + + + XF + win2k-telnet-pipe-privileges(6664) + + Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0351 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:07:48.273-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-031 + + + XF + win2k-telnet-system-call-dos(6669) + + + BID + 2846 + + + CIAC + L-092 + + Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service. + + + + + + + + + + + + + + cpe:/h:3com:3crwe747a + cpe:/a:symbol:41x1_access_point + + CVE-2001-0352 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:07:48.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0353 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:23:54.147-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-15 + + + XF + solaris-lpd-bo(6718) + + + ISS + 20010619 Remote Buffer Overflow Vulnerability in Solaris Print Protocol Daemon + + + BID + 2894 + + + SUN + 00206 + + Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine. + + + + + + + + + cpe:/a:thenet:checkbo:1.56 + + CVE-2001-0354 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:54.303-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2634 + + + BUGTRAQ + 20010420 CheckBO Win9x memo overflow + + TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on. + + + + + + + + + cpe:/a:novell:groupwise:5.5 + + CVE-2001-0355 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:54.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010210 Novell Groupwise Client Vulnerability + + Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies. + + + + + + + + + cpe:/a:matt_wright:formmail:1.6 + + CVE-2001-0357 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:23:54.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + formmail-anonymous-flooding(6242) + + + BUGTRAQ + 20010310 CORRECTION to CODE: FormMail.pl can be used to send anonymous email + + FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters. + + + + + + + + + + cpe:/a:sierra:half-life:1573 + cpe:/a:valve_software:half-life:1573 + + CVE-2001-0358 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:54.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + halflife-config-file-bo + + + XF + halflife-map-bo + + + BUGTRAQ + 20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities + + Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file. + + + + + + + + + + cpe:/a:sierra:half-life:1573 + cpe:/a:valve_software:half-life_dedicated_server:1573 + + CVE-2001-0359 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:54.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + halflife-map-format-string + + + BUGTRAQ + 20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities + + Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command. + + + + + + + + + cpe:/a:ikonboard.com:ikonboard:2.1.7b + + CVE-2001-0360 + 2001-06-27T00:00:00.000-04:00 + 2009-04-03T00:08:05.127-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ikonboard-cgi-read-files + + + BID + 2471 + + + BUGTRAQ + 20010311 Ikonboard v2.1.7b "show files" vulnerability + + Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter. + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.1.1 + + CVE-2001-0361 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:07:49.147-04:00 + + + 4.0 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 2344 + + + XF + ssh-session-key-recovery(6082) + + + OSVDB + 2116 + + + SUSE + SuSE-SA:2001:04 + + + DEBIAN + DSA-086 + + + DEBIAN + DSA-027 + + + DEBIAN + DSA-023 + + + CIAC + L-047 + + + BUGTRAQ + 20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability + + + FREEBSD + FreeBSD-SA-01:24 + + + + + Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5. + + + + + + + + + cpe:/a:ssh:ssh2:2.4 + + CVE-2001-0364 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:55.350-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ssh-ssheloop-dos(6241) + + + BID + 2477 + + + BUGTRAQ + 20010315 Remote DoS attack against SSH Secure Shell for Windows Servers + + SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections. + + + + + + + + + + cpe:/a:qualcomm:eudora:5.0.2 + cpe:/a:qualcomm:eudora:5.1 + + CVE-2001-0365 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:55.490-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eudora-html-execute-code(6262) + + + BID + 2490 + + + BUGTRAQ + 20010318 feeble.you!dora.exploit + + Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags. + + + + + + + + + + + + + cpe:/a:sap:saposcol:1.0::linux + cpe:/a:sap:saposcol:1.1::linux + cpe:/a:sap:sap_r_3_web_application_server_demo:1.5 + cpe:/a:sap:saposcol:1.3::linux + cpe:/a:sap:saposcol:1.2::linux + + CVE-2001-0366 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:55.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2662 + + + BUGTRAQ + 20010429 SAP R/3 Web Application Server Demo for Linux: root exploit + + + CONFIRM + ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol + + + XF + linux-sap-execute-code(6487) + + saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program. + + + + + + + + + cpe:/a:mirabilis:icq:2000.0b_build3278 + + CVE-2001-0367 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:55.803-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2664 + + + BUGTRAQ + 20010428 Mirabilis ICQ WebFront Plug-in Denial of Service + + Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters. + + + + + + + + + + + cpe:/a:free_peers:bearshare:2.2 + cpe:/a:free_peers:bearshare:2.2.1 + cpe:/a:free_peers:bearshare:2.2.2 + + CVE-2001-0368 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:55.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2672 + + + BUGTRAQ + 20010430 A Serious Security Vulnerability Found in BearShare (Directory Traversal) + + + XF + bearshare-dot-download-files(6481) + + + OSVDB + 1810 + + Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack. + + + + + + + + + + cpe:/o:digital:unix:mu02 + cpe:/o:digital:unix:r4.20mu06 + + CVE-2001-0369 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:56.100-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + dgux-lpsched-bo + + + BUGTRAQ + 20010319 DGUX lpsched buffer overflow + + Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name). + + + + + + + + + cpe:/a:michael_a._gumienny:fcheck:2.57.59 + + CVE-2001-0370 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:56.240-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fcheck-open-execute-commands + + + BUGTRAQ + 20010320 fcheck prior to 2.07.59 - vulnerability - improper use of perl 'magic open' + + fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters. + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + + CVE-2001-0371 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:56.397-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ufs-ext2fs-data-disclosure(6268) + + + FREEBSD + FreeBSD-SA-01:30 + + + OSVDB + 5682 + + Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information. + + + + + + + + + + cpe:/a:akopia:akopia_interchange:4.6.3 + cpe:/a:akopia:akopia_interchange:4.5.3 + + CVE-2001-0372 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:56.537-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2499 + + + BUGTRAQ + 20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability + + + XF + akopia-interchange-gain-access(6273) + + + CONFIRM + http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html + + Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0373 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:56.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2501 + + + XF + win-userdmp-insecure-permission(6275) + + + OSVDB + 5683 + + + BUGTRAQ + 20010323 NT crash dump files insecure by default + + The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information. + + + + + + + + + cpe:/a:compaq:web-enabled_management + + CVE-2001-0374 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:56.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + compaq-wbm-bypass-proxy + + + COMPAQ + SSRT0715 + + + BUGTRAQ + 20010322 Compaq Insight Manager Proxy Vuln + + The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301. + + + + + + + + + + cpe:/h:cisco:pix_firewall_520 + cpe:/h:cisco:pix_firewall_515 + + CVE-2001-0375 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:56.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2551 + + + BUGTRAQ + 20010406 PIX Firewall 5.1 DoS Vulnerability + + + XF + cisco-pix-tacacs-dos(6353) + + + CISCO + 20011003 Cisco PIX Firewall Authentication Denial of Service Vulnerability + + Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests. + + + + + + + + + + cpe:/h:sonicwall:tele2:6.0.0 + cpe:/h:sonicwall:soho2:6.0.0 + + CVE-2001-0376 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:57.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010327 SonicWall IKE pre-shared key length bug and security concern + + + XF + sonicwall-ike-shared-keys + + SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used. + + + + + + + + + cpe:/a:infradig:inframail:3.97a + + CVE-2001-0377 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:57.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + inframail-post-dos(6297) + + + BUGTRAQ + 20010328 Inframail Denial of Service Vulnerability + + + OSVDB + 5685 + + Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string. + + + + + + + + + cpe:/o:openbsd:openbsd:2.8 + + CVE-2001-0378 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:07:51.820-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch + + + XF + bsd-readline-permissions(6586) + + + OSVDB + 5680 + + readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files. + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + + CVE-2001-0379 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:57.570-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#249224 + + + HP + HPSBUX0103-147 + + + XF + hp-newgrp-additional-privileges(6282) + + + OSVDB + 5681 + + + + + Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights. + + + + + + + + + cpe:/h:crosscom_olicom:xlt-f + + CVE-2001-0380 + 2001-06-18T00:00:00.000-04:00 + 2009-03-04T00:07:48.250-05:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BUGTRAQ + 200103 ILMI community in olicom/crosscomm routers + + + + + Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'. + + + + + + + + + cpe:/a:pgp:openpgp + + CVE-2001-0381 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:23:57.850-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + openpgp-private-key-disclosure(6558) + + + BID + 2673 + + + REDHAT + RHSA-2001:063 + + + OSVDB + 11966 + + + BUGTRAQ + 20010322 Re: Yes, they have found a serious PGP vulnerability...sort of + + + BUGTRAQ + 20010320 Yes, they have found a serious PGP vulnerability...sort of + + + BUGTRAQ + 20010319 Have they found a serious PGP vulnerability?! + + + CALDERA + CSSA-2001-017.0 + + The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key. + + + + + + + + + cpe:/a:ca:ccc_harvest:5.0 + + CVE-2001-0382 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:58.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + NTBUGTRAQ + 20010327 CA CCC\Harvest exploit + + Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.4 + + CVE-2001-0383 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:58.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://phpnuke.org/download.php?dcategory=Fixes + + + BUGTRAQ + 20010401 Php-nuke exploit... + + + XF + php-nuke-url-redirect(6342) + + + BID + 2544 + + banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication. + + + + + + + + + cpe:/o:siemens:reliant_unix:5.45 + + CVE-2001-0384 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:58.303-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2606 + + + BUGTRAQ + 20010414 Re: Reliant Unix 5.43 / 5.44 ICMP port unreachable problem + + ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file. + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:2.1 + + CVE-2001-0385 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:58.443-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2607 + + + BUGTRAQ + 20010417 Advisory for GoAhead Webserver v2.1 + + + XF + goahead-aux-dos(6400) + + + OSVDB + 6664 + + GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.0.8 + + CVE-2001-0386 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:58.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2608 + + + BUGTRAQ + 20010417 Advisory for SimpleServer:WWW (analogX) + + + XF + analogx-simpleserver-aux-dos(6395) + + + OSVDB + 3781 + + AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. + + + + + + + + + + + + + + cpe:/a:hylafax:hylafax:4.1_beta3 + cpe:/a:hylafax:hylafax:4.1_beta2 + cpe:/a:hylafax:hylafax:4.1_beta1 + cpe:/a:hylafax:hylafax:4.0_pl0 + cpe:/a:hylafax:hylafax:4.0_pl1 + cpe:/a:hylafax:hylafax:4.0_pl2 + + CVE-2001-0387 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:58.740-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2574 + + + MANDRAKE + MDKSA-2001:041 + + + SUSE + SuSE-SA:2001:15 + + + BUGTRAQ + 20010415 **SECURITY ADVISORY** - HylaFAX format string vulnerability + + + BUGTRAQ + 20010412 HylaFAX vulnerability + + + XF + hylafax-hfaxd-format-string(6377) + + + OSVDB + 5679 + + + FREEBSD + FreeBSD-SA-01:34 + + Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument. + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:suse:suse_linux:6.4 + + CVE-2001-0388 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:07:52.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + timed-remote-dos(6228) + + + MANDRAKE + MDKSA-2001:034 + + + FREEBSD + FreeBSD-SA-01:28 + + + SUSE + SuSE-SA:2001:07 + + time server daemon timed allows remote attackers to cause a denial of service via malformed packets. + + + + + + + + + + cpe:/a:ibm:websphere_application_server:5.1.0.3 + cpe:/a:ibm:net.commerce:3.1.2 + + CVE-2001-0389 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:59.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2587 + + + BUGTRAQ + 20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more. + + IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument. + + + + + + + + + + + + + + + + cpe:/a:ibm:net.commerce:2.0 + cpe:/a:ibm:websphere_application_server:5.1.0.3 + cpe:/a:ibm:net.commerce_hosting_server:3.1.1 + cpe:/a:ibm:net.commerce:3.1.2 + cpe:/a:ibm:net.commerce:3.1 + cpe:/a:ibm:net.commerce_hosting_server:3.1.2 + cpe:/a:ibm:net.commerce:3.1.1 + cpe:/a:ibm:net.commerce:3.0 + + CVE-2001-0390 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:23:59.240-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2588 + + + BUGTRAQ + 20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more. + + IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters. + + + + + + + + + + cpe:/a:imatix:xitami:2.4d7::windows + cpe:/a:imatix:xitami:2.5d4::windows + + CVE-2001-0391 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:07:53.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010417 Advisory for Xitami 2.4d7, 2.5d4 + + Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory. + + + + + + + + + + cpe:/a:navision:financials_server:2.60 + cpe:/a:navision:financials_server:2.50 + + CVE-2001-0392 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:59.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2539 + + + BUGTRAQ + 20010403 def-2001-17: Navision Financials Server DoS + + Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash. + + + + + + + + + cpe:/a:navision:financials_server:2.0 + + CVE-2001-0393 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:23:59.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010404 Re: def-2001-17: Navision Financials Server DoS + + Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits. + + + + + + + + + cpe:/a:oreilly:website_pro:3.0.37 + + CVE-2001-0394 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:23:59.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010328 def-2001-15: Website Pro Remote Manager DoS + + + XF + website-pro-remote-dos(6295) + + + OSVDB + 5669 + + Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory. + + + + + + + + + cpe:/h:lightwave:consoleserver:3200 + + CVE-2001-0395 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:00.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2578 + + + BUGTRAQ + 20010410 Console 3200 telnetd problem. + + Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing. + + + + + + + + + cpe:/h:lightwave:consoleserver:3200 + + CVE-2001-0396 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:00.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2578 + + + BUGTRAQ + 20010410 Console 3200 telnetd problem. + + The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users. + + + + + + + + + cpe:/a:silent_runner:silent_runner_collector_src:1.6.1 + + CVE-2001-0397 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:00.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010329 Silent Runner Collector - HELO buffer overflow vulnerability + + Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ritlabs:the_bat:1.21 + cpe:/a:ritlabs:the_bat:1.22 + cpe:/a:ritlabs:the_bat:1.041 + cpe:/a:ritlabs:the_bat:1.101 + cpe:/a:ritlabs:the_bat:1.43 + cpe:/a:ritlabs:the_bat:1.44 + cpe:/a:ritlabs:the_bat:1.043 + cpe:/a:ritlabs:the_bat:1.41 + cpe:/a:ritlabs:the_bat:1.42 + cpe:/a:ritlabs:the_bat:1.029 + cpe:/a:ritlabs:the_bat:1.42f + cpe:/a:ritlabs:the_bat:1.028 + cpe:/a:ritlabs:the_bat:1.1 + cpe:/a:ritlabs:the_bat:1.48 + cpe:/a:ritlabs:the_bat:1.47 + cpe:/a:ritlabs:the_bat:1.46 + cpe:/a:ritlabs:the_bat:1.45 + cpe:/a:ritlabs:the_bat:1.49 + cpe:/a:ritlabs:the_bat:1.031 + cpe:/a:ritlabs:the_bat:1.31 + cpe:/a:ritlabs:the_bat:1.32 + cpe:/a:ritlabs:the_bat:1.011 + cpe:/a:ritlabs:the_bat:1.33 + cpe:/a:ritlabs:the_bat:1.035 + cpe:/a:ritlabs:the_bat:1.032 + cpe:/a:ritlabs:the_bat:1.039 + cpe:/a:ritlabs:the_bat:1.037 + cpe:/a:ritlabs:the_bat:1.036 + cpe:/a:ritlabs:the_bat:1.015 + cpe:/a:ritlabs:the_bat:1.0_build1349 + cpe:/a:ritlabs:the_bat:1.14 + cpe:/a:ritlabs:the_bat:1.0_build1336 + cpe:/a:ritlabs:the_bat:1.15 + cpe:/a:ritlabs:the_bat:1.17 + cpe:/a:ritlabs:the_bat:1.18 + cpe:/a:ritlabs:the_bat:1.19 + cpe:/a:ritlabs:the_bat:1.39 + cpe:/a:ritlabs:the_bat:1.35 + cpe:/a:ritlabs:the_bat:1.34 + cpe:/a:ritlabs:the_bat:1.36 + + CVE-2001-0398 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:00.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2530 + + + BUGTRAQ + 20010402 ~..~!guano + + The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon. + + + + + + + + + + cpe:/a:caucho_technology:resin:1.2 + cpe:/a:caucho_technology:resin:1.3 + + CVE-2001-0399 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:00.693-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2533 + + + BUGTRAQ + 20010403 CHINANSL Security Advisory(CSA-200111) + + Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request. + + + + + + + + + + cpe:/a:matt_tourtillott:nph-maillist:3.5 + cpe:/a:matt_tourtillott:nph-maillist:3.0 + + CVE-2001-0400 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:00.850-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2563 + + + BUGTRAQ + 20010410 CGI - nph-maillist.pl vulnerability... + + nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address. + + + + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0401 + 2001-06-18T00:00:00.000-04:00 + 2009-07-21T16:46:14.360-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010327 Solaris /usr/bin/tip Vulnerability + + + XF + solaris-tip-bo + + + BID + 2475 + + Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. + + + + + + + + + + + + + + + cpe:/a:darren_reed:ipfilter:3.4.16 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:openbsd:openbsd:2.8 + + CVE-2001-0402 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:01.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010408 A fragmentation attack against IP Filter + + + FREEBSD + FreeBSD-SA-01:32 + + + XF + ipfilter-access-ports(6331) + + IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port. + + + + + + + + + cpe:/o:sun:solaris:2.0 + + CVE-2001-0403 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:01.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010323 [ Hackerslab bug_paper ] SunOS application perfmon vulnerability + + + XF + solaris-perfmon-create-files + + /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI. + + + + + + + + + cpe:/a:sun:javaserver_web_dev_kit:1.0.1 + + CVE-2001-0404 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:01.443-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010328 CHINANSL Security Advisory(CSA-200106) + + Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.0:test1 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.1 + + CVE-2001-0405 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:01.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2602 + + + BUGTRAQ + 20010416 Tempest Security Techonologies -- Adivsory #01/2001 -- Linux IPTables + + + REDHAT + RHSA-2001:052 + + + XF + linux-netfilter-iptables(6390) + + + REDHAT + RHSA-2001:084 + + + MANDRAKE + MDKSA-2001:071 + + ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall. + + + + + + + + + cpe:/a:samba:samba:2.0.7 + + CVE-2001-0406 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:01.757-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#670568 + + + DEBIAN + DSA-048 + + + CALDERA + CSSA-2001-015.0 + + + BUGTRAQ + 20010418 PROGENY-SA-2001-05: Samba /tmp vulnerabilities + + + BUGTRAQ + 20010418 TSLSA-#2001-0005 - samba + + + BUGTRAQ + 20010417 Samba 2.0.8 security fix + + + BID + 2617 + + + MANDRAKE + MDKSA-2001:040 + + + FREEBSD + FreeBSD-SA-01:36 + + + CONECTIVA + CLA-2001:395 + + Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient. + + + + + + + + + cpe:/a:mysql:mysql:3.23.36 + + CVE-2001-0407 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:01.913-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010327 MySQL 3.23.36 is relased (fwd) + + + BUGTRAQ + 20010318 potential vulnerability of mysqld running with root privileges (can be used as good DoS or r00t expoloit) + + + XF + mysql-dot-directory-traversal(6617) + + + BID + 2522 + + Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot). + + + + + + + + + cpe:/a:vim_development_group:vim:5.7 + + CVE-2001-0408 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.053-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2510 + + + REDHAT + RHSA-2001:008 + + + CALDERA + CSSA-2001-014.0 + + + XF + vim-elevate-privileges(6259) + + + SUSE + SuSE-SA:2001:12 + + + MANDRAKE + MDKSA-2001:035 + + + BUGTRAQ + 20010329 Immunix OS Security update for vim + + vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes. + + + + + + + + + cpe:/a:vim_development_group:vim:5.7 + + CVE-2001-0409 + 2001-06-18T00:00:00.000-04:00 + 2008-09-10T15:07:55.197-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2001-014.0 + + + XF + vim-tmp-symlink(6628) + + + SUSE + SuSE-SA:2001:12 + + vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory. + + + + + + + + + cpe:/a:trend_micro:virus_buster_2001:8.02 + + CVE-2001-0410 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.350-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010330 Virus Buster 2001(ver8.02) Buffer Overflow + + Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header. + + + + + + + + + cpe:/o:siemens:reliant_unix:5.44 + + CVE-2001-0411 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010406 Reliant Unix 5.43 / 5.44 ICMP port unreachable problem + + Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet. + + + + + + + + + + + cpe:/h:cisco:content_services_switch_11150 + cpe:/h:cisco:content_services_switch_11050 + cpe:/h:cisco:content_services_switch_11800 + + CVE-2001-0412 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CISCO + 20010404 Cisco Content Services Switch User Account Vulnerability + + + XF + cisco-css-elevate-privileges(6322) + + + BID + 2559 + + + OSVDB + 1784 + + Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode. + + + + + + + + + + + cpe:/h:bintec:x4000:5.1.6_patch_10 + cpe:/h:bintec:x1000 + cpe:/h:bintec:x1200 + + CVE-2001-0413 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.803-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010406 X4000 DoS: Details and workaround + + + BUGTRAQ + 20010410 BinTec Router DoS: Workaround and Details + + + BUGTRAQ + 20010404 BinTec X4000 Access Router DoS Vulnerability + + + XF + bintec-x4000-nmap-dos(6323) + + + BUGTRAQ + 20010409 BINTEC X1200 + + BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:dave_mills:xntp3:5.93b + cpe:/a:dave_mills:xntp3:5.93c + cpe:/a:dave_mills:xntp3:5.93d + cpe:/a:dave_mills:xntp3:5.93e + cpe:/a:dave_mills:ntpd:4.0.99a + cpe:/a:dave_mills:xntp3:5.93 + cpe:/a:dave_mills:xntp3:5.93a + cpe:/a:dave_mills:ntpd:4.0.99d + cpe:/a:dave_mills:ntpd:4.0.99e + cpe:/a:dave_mills:ntpd:4.0.99b + cpe:/a:dave_mills:ntpd:4.0.99c + cpe:/a:dave_mills:ntpd:4.0.99h + cpe:/a:dave_mills:ntpd:4.0.99i + cpe:/a:dave_mills:ntpd:4.0.99f + cpe:/a:dave_mills:ntpd:4.0.99g + cpe:/a:dave_mills:ntpd:4.0.99 + cpe:/a:dave_mills:ntpd:4.0.99j + cpe:/a:dave_mills:ntpd:4.0.99k + + CVE-2001-0414 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:02.960-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 2540 + + + MANDRAKE + MDKSA-2001:036 + + + DEBIAN + DSA-045 + + + XF + ntpd-remote-bo(6321) + + + REDHAT + RHSA-2001:045 + + + OSVDB + 805 + + + CALDERA + CSSA-2001-013 + + + BUGTRAQ + 20010409 ntpd - new Debian 2.2 (potato) version is also vulnerable + + + BUGTRAQ + 20010409 PROGENY-SA-2001-02: ntpd remote buffer overflow + + + BUGTRAQ + 20010409 ntp-4.99k23.tar.gz is available + + + BUGTRAQ + 20010408 [slackware-security] buffer overflow fix for NTP + + + BUGTRAQ + 20010406 Immunix OS Security update for ntp and xntp3 + + + BUGTRAQ + 20010405 Re: ntpd =< 4.0.99k remote buffer overflow] + + + BUGTRAQ + 20010404 ntpd =< 4.0.99k remote buffer overflow + + + SUSE + SuSE-SA:2001:10 + + + CONECTIVA + CLA-2001:392 + + + BUGTRAQ + 20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp + + + BUGTRAQ + 20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow + + + BUGTRAQ + 20010409 [ESA-20010409-01] xntp buffer overflow + + + SCO + SSE074 + + + SCO + SSE073 + + + NETBSD + NetBSD-SA2001-004 + + + FREEBSD + FreeBSD-SA-01:31 + + + + + + + + Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument. + + + + + + + + + cpe:/a:redi:rediplus:1.0 + + CVE-2001-0415 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:03.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + rediplus-weak-security + + + BID + 2495 + + + BUGTRAQ + 20010320 Password stored in clear text vulnerability in real time stock trading program + + REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts. + + + + + + + + + + + + + + + + + + + + cpe:/a:immunix:immunix:7.0 + cpe:/a:debian:sgml-tools:1.0.9.15 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/a:immunix:immunix:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + + CVE-2001-0416 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:03.303-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:027 + + + MANDRAKE + MDKSA-2001:030 + + + BUGTRAQ + 20010316 Immunix OS Security update for sgml-tools + + + CONECTIVA + CLA-2001:390 + + + DEBIAN + DSA-038 + + + XF + sgmltools-symlink + + + BID + 2683 + + + BID + 2506 + + + SUSE + SuSE-SA:2001:16 + + sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools. + + + + + + + + + + cpe:/a:mit:kerberos:5-1.5.2 + cpe:/a:mit:kerberos:4 + + CVE-2001-0417 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:03.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010307 Security advisory: Unsafe temporary file handling in krb4 + + + REDHAT + RHSA-2001:025 + + Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files. + + + + + + + + + cpe:/a:ncm:ncm_content_management_system + + CVE-2001-0418 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:03.677-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2584 + + + BUGTRAQ + 20010413 Exploitable NCM.at - Content Management System + + content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. + + + + + + + + + cpe:/a:oracle:application_server:4.0.8.2 + + CVE-2001-0419 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:03.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2569 + + + BUGTRAQ + 20010410 Oracle Application Server shared library buffer overflow + + Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/. + + + + + + + + + cpe:/a:way_to_the_web:talkback:1.1 + + CVE-2001-0420 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:03.990-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2547 + + + BUGTRAQ + 20010409 talkback.cgi vulnerability may allow users to read any file + + Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter. + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0421 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:04.133-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2601 + + + BUGTRAQ + 20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit ! + + FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition. + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-0422 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:04.287-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 2561 + + + BUGTRAQ + 20010410 Solaris Xsun buffer overflow vulnerability + + + XF + solaris-xsun-home-bo(6343) + + + + + Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + + CVE-2001-0423 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:04.443-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2581 + + + BUGTRAQ + 20010412 Solaris ipcs vulnerability + + + XF + solaris-ipcs-bo(6369) + + Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:timecop:bubblemon:1.2test1 + cpe:/a:timecop:bubblemon:1.31 + cpe:/a:timecop:bubblemon:1.2 + cpe:/a:timecop:bubblemon:1.1test7 + cpe:/a:timecop:bubblemon:1.3 + cpe:/a:timecop:bubblemon:1.0 + cpe:/a:timecop:bubblemon:1.1 + cpe:/a:timecop:bubblemon:1.22 + cpe:/a:timecop:bubblemon:1.23 + cpe:/a:timecop:bubblemon:1.21 + cpe:/a:timecop:bubblemon:1.0pl1 + cpe:/a:timecop:bubblemon:1.21test1 + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/a:timecop:bubblemon:1.0pl2 + cpe:/a:timecop:bubblemon:1.0pl3 + cpe:/a:timecop:bubblemon:1.0pl4 + cpe:/a:timecop:bubblemon:1.0pl6 + cpe:/a:timecop:bubblemon:1.0pl7 + cpe:/a:timecop:bubblemon:1.1test1 + cpe:/a:timecop:bubblemon:1.0pl8 + cpe:/a:timecop:bubblemon:1.1test2 + cpe:/a:timecop:bubblemon:1.0pl9 + cpe:/a:timecop:bubblemon:1.1test5 + cpe:/a:timecop:bubblemon:1.1test6 + cpe:/a:timecop:bubblemon:1.1test3 + cpe:/a:timecop:bubblemon:1.1test4 + + CVE-2001-0424 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:04.600-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2609 + + + BUGTRAQ + 20010415 BubbleMon 1.31 + + BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. + + + + + + + + + + cpe:/a:adcycle:adcycle:0.78b + cpe:/a:adcycle:adcycle:0.77 + + CVE-2001-0425 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:04.803-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010219 Adcycle 0.78b Authentication + + + BID + 2393 + + AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0426 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:07:56.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities + + Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable. + + + + + + + + + + + + + + cpe:/h:cisco:vpn_3005_concentrator + cpe:/h:cisco:vpn_3000_concentrator + cpe:/h:cisco:vpn_3080_concentrator + cpe:/h:cisco:vpn_3060_concentrator + cpe:/h:cisco:vpn_3015_concentrator + cpe:/h:cisco:vpn_3030_concentator + + CVE-2001-0427 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:05.117-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CISCO + 20010328 VPN3000 Concentrator TELNET Vulnerability + + + XF + cisco-vpn-telnet-dos(6298) + + + OSVDB + 5643 + + Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts. + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2001-0428 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:05.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2573 + + + CISCO + 20010412 VPN 3000 Concentrator IP Options Vulnerability + + + XF + cisco-vpn-ip-dos(6360) + + + OSVDB + 1786 + + Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option. + + + + + + + + + + + + + + + cpe:/o:cisco:catos:5.5%284b%29 + cpe:/o:cisco:catos:6.1%281c%29 + cpe:/o:cisco:catos:4.5%2811%29 + cpe:/o:cisco:catos:6.1%282%29 + cpe:/o:cisco:catos:6.1.2 + cpe:/o:cisco:catos:5.5%286%29 + cpe:/o:cisco:catos:4.5.10 + + CVE-2001-0429 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:05.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2604 + + + CISCO + 20010416 Catalyst 5000 Series 802.1x Vulnerability + + + XF + cisco-catalyst-8021x-dos(6379) + + + CIAC + L-072 + + Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service. + + + + + + + + + + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:3.2.4 + + CVE-2001-0430 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:05.587-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-046 + + + XF + exuberant-ctags-symlink(6388) + + + OSVDB + 5642 + + Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.x_enterprise + + CVE-2001-0431 + 2001-07-02T00:00:00.000-04:00 + 2011-03-07T21:05:17.893-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html + + Vulnerability in iPlanet Web Server Enterprise Edition 4.x. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2001-0432 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:05.880-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2579 + + + BUGTRAQ + 20010413 Trend Micro Interscan VirusWall 3.01 vulnerability + + Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:micheal_lamont:savant_webserver:3.0 + + CVE-2001-0433 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:06.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010405 Savant 3.0 Denial Of Service + + Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header. + + + + + + + + + cpe:/a:compaq:presario + + CVE-2001-0434 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.177-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + COMPAQ + SSRT0716 + + + XF + compaq-activex-dos(6355) + + The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service. + + + + + + + + + cpe:/a:pgp:pgp:7.0 + + CVE-2001-0435 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.337-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010410 [wsir-01/02-03] PGP 7.0 Split Key/Cached Passphrase Vulnerability + + The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate. + + + + + + + + + + + + + + + cpe:/a:dcscripts:dcforum:3.0 + cpe:/a:dcscripts:dcforum:1.0 + cpe:/a:dcscripts:dcforum:5.0 + cpe:/a:dcscripts:dcforum:2.0 + cpe:/a:dcscripts:dcforum_2000:1.0 + cpe:/a:dcscripts:dcforum:4.0 + cpe:/a:dcscripts:dcforum:6.0 + + CVE-2001-0436 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2611 + + + CONFIRM + http://www.dcscripts.com/FAQ/sec_2001_03_31.html + + + BUGTRAQ + 20010416 qDefense Advisory: DCForum allows remote read/write/execute + + + XF + dcforum-az-expr(6392) + + + OSVDB + 3862 + + dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. + + + + + + + + + + + + + + + cpe:/a:dcscripts:dcforum:3.0 + cpe:/a:dcscripts:dcforum:1.0 + cpe:/a:dcscripts:dcforum:5.0 + cpe:/a:dcscripts:dcforum:2.0 + cpe:/a:dcscripts:dcforum_2000:1.0 + cpe:/a:dcscripts:dcforum:4.0 + cpe:/a:dcscripts:dcforum:6.0 + + CVE-2001-0437 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.630-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2611 + + + CONFIRM + http://www.dcscripts.com/FAQ/sec_2001_03_31.html + + + BUGTRAQ + 20010416 qDefense Advisory: DCForum allows remote read/write/execute + + + XF + dcforum-az-file-upload(6393) + + upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. + + + + + + + + + cpe:/a:netopia:timbuktu_mac:initial + + CVE-2001-0438 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.787-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010418 Hole in Netopia's Mac OS X Timbuktu + + Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:conectiva:linux:4.0es + cpe:/a:licq:licq:1.0.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:conectiva:linux:4.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0439 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:06.943-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + licq-url-execute-commands(6261) + + + MANDRAKE + MDKSA-2001:032 + + + CONECTIVA + CLA-2001:389 + + + FREEBSD + FreeBSD-SA-01:35 + + + REDHAT + RHSA-2001:023 + + + REDHAT + RHSA-2001:022 + + + OSVDB + 5641 + + licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:prg_graficos + cpe:/o:conectiva:linux:ecommerce + cpe:/o:conectiva:linux:6.0 + cpe:/o:conectiva:linux:4.0es + cpe:/a:licq:licq:1.0.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:conectiva:linux:4.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:conectiva:linux:4.1 + cpe:/o:conectiva:linux:4.0 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2001-0440 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:07.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001:032 + + + CONECTIVA + CLA-2001:389 + + + FREEBSD + FreeBSD-SA-01:35 + + + XF + licq-logging-bo(6645) + + + REDHAT + RHSA-2001:023 + + + REDHAT + RHSA-2001:022 + + + OSVDB + 5601 + + Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands. + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0441 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:07.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:028 + + + MANDRAKE + MDKSA-2001:028 + + + DEBIAN + DSA-040 + + + FREEBSD + FreeBSD-SA-01:37 + + + XF + slrn-wrapping-bo + + + BID + 2493 + + + BUGTRAQ + 20010316 Immunix OS Security update for slrn + + + CONECTIVA + CLA-2001:383 + + Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header. + + + + + + + + + + + cpe:/a:david_harris:mercury_nlm:1.45 + cpe:/a:david_harris:mercury_nlm:1.47 + cpe:/a:david_harris:mercury_nlm:1.46 + + CVE-2001-0442 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:07.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2641 + + + BUGTRAQ + 20010421 Mercury for NetWare POP3 server vulnerable to remote buffer overflow + + + XF + mercury-mta-bo(6444) + + + BUGTRAQ + 20010424 Re: Mercury for NetWare POP3 server vulnerable to remote buffer overflow + + Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command. + + + + + + + + + + cpe:/a:qpc_software:qvt_net:5.0 + cpe:/a:qpc_software:qvt_term_plus:5.0 + + CVE-2001-0443 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:07:58.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010413 QPC POPd Buffer Overflow Vulnerability + + Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password. + + + + + + + + + + cpe:/o:cisco:cbos:2.3.053 + cpe:/o:cisco:cbos:2.4.1 + + CVE-2001-0444 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:07.773-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2635 + + + BUGTRAQ + 20010420 Bug in Cisco CBOS v2.3.0.053 + + + XF + cisco-cbos-gain-information(6453) + + + OSVDB + 1796 + + Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information. + + + + + + + + + cpe:/a:ibm:websphere_commerce_suite:4.0.1 + + CVE-2001-0446 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:07.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010328 CHINANSL Security Advisory(CSA-200107) + + IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL. + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2000a_2000.0.1.34 + + CVE-2001-0447 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:08.053-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2514 + + + BUGTRAQ + 20010326 602Pro Lansuite Denial Of Service 1.0.34 + + Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters. + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2000a_1.0.34 + + CVE-2001-0448 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:08.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010326 602Pro Lansuite Denial Of Service 1.0.34 + + Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names. + + + + + + + + + cpe:/a:winzip:winzip:8.0 + + CVE-2001-0449 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:08.350-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + winzip-zipandemail-bo(6191) + + + BUGTRAQ + 20010302 def-2001-09: Winzip32 zipandemail Buffer Overflow + + Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option. + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:5.5 + + CVE-2001-0450 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:08.490-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + broker-ftp-delete-files + + + XF + broker-ftp-list-directories + + + CONFIRM + http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&P=0&C=0 + + + BUGTRAQ + 20010303 Broker Ftp Server 5.0 Vulnerability + + Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. + + + + + + + + + + + cpe:/a:sentraweb:indexu:1.0 + cpe:/a:sentraweb:indexu:2.0beta + cpe:/a:sentraweb:indexu:1.1 + + CVE-2001-0451 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:08.630-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + indexu-gain-access + + INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1. + + + + + + + + + + + + + + + cpe:/a:brs:webweaver:0.61_beta + cpe:/a:brs:webweaver:0.60_beta + cpe:/a:brs:webweaver:0.51_beta + cpe:/a:brs:webweaver:0.49_beta + cpe:/a:brs:webweaver:0.50_beta + cpe:/a:brs:webweaver:0.52_beta + cpe:/a:brs:webweaver:0.62_beta + + CVE-2001-0452 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:08.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010428 Vulnerabilities in BRS WebWeaver + + + BID + 2676 + + + CONFIRM + http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html + + BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command. + + + + + + + + + + + + + + + cpe:/a:brs:webweaver:0.61_beta + cpe:/a:brs:webweaver:0.60_beta + cpe:/a:brs:webweaver:0.51_beta + cpe:/a:brs:webweaver:0.49_beta + cpe:/a:brs:webweaver:0.50_beta + cpe:/a:brs:webweaver:0.52_beta + cpe:/a:brs:webweaver:0.62_beta + + CVE-2001-0453 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:08.943-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010428 Vulnerabilities in BRS WebWeaver + + + BID + 2675 + + + CONFIRM + http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html + + Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories. + + + + + + + + + cpe:/a:whitsoft:slimserve:1.1a + + CVE-2001-0454 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:09.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010303 SlimServe HTTPd ver. 1.1a Directory Traversal + + + XF + slimserve-httpd-directory-traversal + + Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request. + + + + + + + + + cpe:/a:cisco:aironet_340:8.55 + + CVE-2001-0455 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:09.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-aironet-web-access(6200) + + + CISCO + 20010307 Access to the Cisco Aironet 340 Series Wireless Bridge via Web Interface + + + OSVDB + 5597 + + Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration. + + + + + + + + + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-0456 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:09.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + proftpd-postinst-root(6208) + + + DEBIAN + DSA-032 + + postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended. + + + + + + + + + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-0457 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:09.553-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + man2html-remote-dos(6211) + + + DEBIAN + DSA-035 + + + OSVDB + 5631 + + man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion). + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:suse:suse_linux:6.4 + cpe:/a:ralf_s._engelschall:eperl:2.2.12 + cpe:/a:ralf_s._engelschall:eperl:2.2.13 + + CVE-2001-0458 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:08:03.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-eperl-bo + + + BID + 2464 + + + MANDRAKE + MDKSA-2001:027 + + + DEBIAN + DSA-034 + + + SUSE + SuSE-SA:2001:08 + + Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. + + + + + + + + + + cpe:/a:afterstep.org:afterstep + cpe:/a:rob_malda:ascdc:0.3 + + CVE-2001-0459 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:09.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ascdc-afterstep-bo + + + BUGTRAQ + 20010308 ascdc Buffer Overflow Vulnerability + + Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option. + + + + + + + + + cpe:/o:baltimore_technologies:websweeper:4.0 + + CVE-2001-0460 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:10.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010308 def-2001-10: Websweeper Infinite HTTP Request DoS + + + XF + websweeper-http-dos + + Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header. + + + + + + + + + cpe:/a:denis_howe:foldoc + + CVE-2001-0461 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:10.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + foldoc-cgi-execute-commands + + + BUGTRAQ + 20010309 Cgisecurity.com advisory #4 The Free On-line Dictionary of Computing + + + CONFIRM + http://wombat.doc.ic.ac.uk/foldoc/index.html + + + OSVDB + 5591 + + template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi. + + + + + + + + + + + + + + + + cpe:/a:spencer_christensen:perl_web_server:0.1 + cpe:/a:spencer_christensen:perl_web_server:0.2 + cpe:/a:spencer_christensen:perl_web_server:0.3 + cpe:/a:spencer_christensen:perl_web_server:0.0.1 + cpe:/a:spencer_christensen:perl_web_server:0.0.2 + cpe:/a:spencer_christensen:perl_web_server:0.0.3 + cpe:/a:spencer_christensen:perl_web_server:0.0.4 + cpe:/a:spencer_christensen:perl_web_server:0.0.9 + + CVE-2001-0462 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:10.303-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2648 + + + BUGTRAQ + 20010424 Advisory for perl webserver + + + XF + perl-webserver-directory-traversal(6451) + + Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:acme_labs:perlcal:2.9c + cpe:/a:acme_labs:perlcal:2.9d + cpe:/a:acme_labs:perlcal:2.9e + cpe:/a:acme_labs:perlcal:2.80 + cpe:/a:acme_labs:perlcal:2.9 + cpe:/a:acme_labs:perlcal:2.7 + cpe:/a:acme_labs:perlcal:2.6 + cpe:/a:acme_labs:perlcal:2.5 + cpe:/a:acme_labs:perlcal:2.95 + cpe:/a:acme_labs:perlcal:2.4 + cpe:/a:acme_labs:perlcal:2.3 + cpe:/a:acme_labs:perlcal:2.9a + cpe:/a:acme_labs:perlcal:2.9b + cpe:/a:acme_labs:perlcal:2.13 + cpe:/a:acme_labs:perlcal:2.18 + + CVE-2001-0463 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:10.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2663 + + + BUGTRAQ + 20010427 PerlCal (CGI) show files vulnerability + + + XF + perlcal-calmake-directory-traversal(6480) + + + CONFIRM + http://www.perlcal.com/calendar/docs/bugs.txt + + Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. + + + + + + + + + cpe:/a:crosswind:cyberscheduler:2.1 + + CVE-2001-0464 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:10.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2628 + + + BUGTRAQ + 20010417 Cyberscheduler remote root compromise + + Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter. + + + + + + + + + cpe:/a:intuit:turbo_tax + + CVE-2001-0465 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:10.787-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010405 + + + CONFIRM + http://www.turbotax.com/atr/update/ + + + XF + turbotax-save-passwords(6622) + + TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information. + + + + + + + + + cpe:/a:microburst:ustorekeeper_online_shopping_system:1.61 + + CVE-2001-0466 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:10.927-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010403 new advisory + + Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. + + + + + + + + + cpe:/a:robtex:viking_server:1.0.7 + + CVE-2001-0467 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.083-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2643 + + + BUGTRAQ + 20010423 Vulnerability in Viking Web Server + + + CONFIRM + http://www.robtex.com/files/viking/beta/chglog.txt + + + XF + viking-dot-directory-traversal(6450) + + Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request. + + + + + + + + + cpe:/a:ftpfs:ftpfs:0.1.1 + + CVE-2001-0468 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.227-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ftpfs-bo + + + BUGTRAQ + 20010313 Buffer oveflow in FTPFS (linux kernel module) + + Buffer overflow in FTPFS allows local users to gain root privileges via a long user name. + + + + + + + + + cpe:/o:freebsd:freebsd:4.2 + + CVE-2001-0469 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rwhod-remote-dos(6229) + + + BID + 2473 + + + FREEBSD + FreeBSD-SA-01:29 + + rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length. + + + + + + + + + + cpe:/o:sun:solaris:5.8 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0470 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + snmpd-argv-bo + + + BUGTRAQ + 20010315 Re: Solaris 5.8 snmpd Vulnerability + + + BUGTRAQ + 20010313 Solaris 5.8 snmpd Vulnerability + + Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name. + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + + CVE-2001-0471 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2345 + + + BUGTRAQ + 20010205 SSHD-1 Logging Vulnerability + + SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack. + + + + + + + + + cpe:/a:ibm:high_availability_cluster_multiprocessing:1.0 + + CVE-2001-0472 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.803-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hslctf-http-dos + + + BUGTRAQ + 20010320 def-2001-12: Hursley Software Laboratories Consumer Transaction Framework DoS + + Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mutt:mutt:1.2.5 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:6.0 + cpe:/o:conectiva:linux + cpe:/o:redhat:linux:7.0 + cpe:/a:immunix:immunix:7.0 + cpe:/o:mandrakesoft:mandrake_linux:6.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/o:mandrakesoft:mandrake_linux:6.1 + + CVE-2001-0473 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:11.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mutt-imap-format-string(6235) + + + REDHAT + RHSA-2001:029 + + + MANDRAKE + MDKSA-2001-031 + + + BUGTRAQ + 20010315 Immunix OS Security update for mutt + + + BUGTRAQ + 20010320 Trustix Security Advisory - mutt + + + OSVDB + 5615 + + + CONECTIVA + CLA-2001:385 + + Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands. + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/a:brian_paul:mesa:3.3-14 + + CVE-2001-0474 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.130-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mesa-utahglx-symlink(6231) + + + MANDRAKE + MDKSA-2001:029 + + Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file. + + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.0_beta_2 + cpe:/a:jelsoft:vbulletin:1.1.5 + + CVE-2001-0475 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.287-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vbulletin-php-elevate-privileges(6237) + + + CONFIRM + http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&threadid=10839 + + + BUGTRAQ + 20010315 vBulletin allows arbitrary code execution + + + BID + 2474 + + index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter. + + + + + + + + + + cpe:/a:swsoft:aspseek:1.0 + cpe:/a:swsoft:aspseek:1.0.3 + + CVE-2001-0476 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.443-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aspseek-scgi-bo + + + CONFIRM + http://www.aspseek.org/changes.html + + + BID + 2492 + + + BUGTRAQ + 20010318 Aspseek Buffer Overflow + + Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter. + + + + + + + + + + + + + + + + + + + + cpe:/a:webcalendar:webcalendar:0.9.19 + cpe:/a:webcalendar:webcalendar:0.9.16 + cpe:/a:webcalendar:webcalendar:0.9.24 + cpe:/a:webcalendar:webcalendar:0.9.15 + cpe:/a:webcalendar:webcalendar:0.9.23 + cpe:/a:webcalendar:webcalendar:0.9.26 + cpe:/a:webcalendar:webcalendar:0.9.25 + cpe:/a:webcalendar:webcalendar:0.9.20 + cpe:/a:webcalendar:webcalendar:0.9.11 + cpe:/a:webcalendar:webcalendar:0.9.22 + cpe:/a:webcalendar:webcalendar:0.9.8 + cpe:/a:webcalendar:webcalendar:0.9.21 + + CVE-2001-0477 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.583-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010423 (SRPRE00004) WebCalendar 0.9.26 + + + BID + 2639 + + Vulnerability in WebCalendar 0.9.26 allows remote command execution. + + + + + + + + + cpe:/a:phpmyadmin:phpmyadmin:2.2.0 + + CVE-2001-0478 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2642 + + + BUGTRAQ + 20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1 + + Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. + + + + + + + + + + cpe:/a:phppgadmin:phppgadmin:2.2.1 + cpe:/a:phppgadmin:phppgadmin:2.2 + + CVE-2001-0479 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:12.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2640 + + + BUGTRAQ + 20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1 + + + CONFIRM + http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13 + + Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. + + + + + + + + + cpe:/a:alex_linde:alexs_ftp_server:0.7 + + CVE-2001-0480 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:13.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010428 Vulnerabilities in Alex's FTP Server + + + BID + 2668 + + Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands. + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:8.0 + + CVE-2001-0481 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:13.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001:043 + + + XF + linux-rpmdrake-temp-file(6494) + + + OSVDB + 5612 + + Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling. + + + + + + + + + cpe:/a:argus_systems:pitbull_lx + + CVE-2001-0482 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:13.350-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010330 Serious Pitbull LX Vulnerability + + + XF + pitbull-lx-modify-kernel(6623) + + Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl. + + + + + + + + + cpe:/a:symantec:raptor_firewall:6.5 + + CVE-2001-0483 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:24:13.490-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2517 + + + BUGTRAQ + 20010327 RE: Raptor 6.5 http vulnerability + + + BUGTRAQ + 20010324 Raptor 6.5 http vulnerability + + Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set. + + + + + + + + + cpe:/a:tek:phaserlink:850 + + CVE-2001-0484 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:13.647-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tektronix-phaserlink-webserver-backdoor(6482) + + + BUGTRAQ + 20010425 Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW) + + Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages. + + + + + + + + + cpe:/o:sgi:irix:6.2 + + CVE-2001-0485 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:13.833-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2656 + + + XF + irix-netprint-shared-library(6473) + + + BUGTRAQ + 20010426 IRIX /usr/lib/print/netprint local root symbols exploit. + + + OSVDB + 8571 + + + BUGTRAQ + 20010427 Re: IRIX /usr/lib/print/netprint local root symbols exploit. + + + SGI + 20010701-01-P + + Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option. + + + + + + + + + cpe:/a:novell:bordermanager:3.6 + + CVE-2001-0486 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:24:14.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2623 + + + CONFIRM + http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm + + + BUGTRAQ + 20010420 Novell BorderManager 3.5 VPN Denial of Service + + + BUGTRAQ + 20010501 Re: Proof of concept DoS against novell border manager enterprise edition 3.5 + + + VULN-DEV + 20010402 (no subject) + + + XF + bordermanager-vpn-syn-dos(6429) + + + BUGTRAQ + 20010429 Proof of concept DoS against novell border manager enterprise + + Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353. + + + + + + + + + cpe:/a:ibm:aix_snmp + + CVE-2001-0487 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:08:10.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + OSVDB + 5611 + + + XF + aix-snmpd-rst-dos(6996) + + + AIXAPAR + IY17630 + + AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.26 + + CVE-2001-0488 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:08:11.023-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2646 + + + XF + hp-pcltotiff-insecure-permissions(6447) + + + HP + HPSBUX0104-149 + + + OSVDB + 2188 + + pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service. + + + + + + + + + cpe:/a:gftp:gftp:2.0.7 + + CVE-2001-0489 + 2001-06-27T00:00:00.000-04:00 + 2008-09-10T15:08:11.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:053 + + + XF + gftp-format-string(6478) + + + BID + 2657 + + + OSVDB + 1805 + + + DEBIAN + DSA-057 + + + VULN-DEV + 20010417 gftp exploitable? + + Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands. + + + + + + + + + + cpe:/a:nullsoft:winamp:2.6x + cpe:/a:nullsoft:winamp:2.7x + + CVE-2001-0490 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:14.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010429 Winamp 2.6x / 2.7x buffer overflow + + Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file. + + + + + + + + + cpe:/a:team_johnlong:raidenftpd:2.1_build_947 + + CVE-2001-0491 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:14.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010425 Vulnerabilities in RaidenFTPD Server + + + XF + raidenftpd-dot-directory-traversal(6455) + + Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST. + + + + + + + + + cpe:/a:netcruiser_software:netcruiser_web_server:0.1.2.8 + + CVE-2001-0492 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:14.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netcruiser-server-path-disclosure(6468) + + + BID + 2650 + + + BUGTRAQ + 20010424 Advisory for Netcruiser + + Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:2.03 + + CVE-2001-0493 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:15.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2649 + + + CONFIRM + http://home.lanck.net/mf/srv/index.htm + + + BUGTRAQ + 20010424 Advisory for Small HTTP Server + + + XF + small-http-aux-dos(6446) + + Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux. + + + + + + + + + cpe:/a:ipswitch:imail:6.06 + + CVE-2001-0494 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:15.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010424 IPSwitch IMail 6.06 SMTP Remote System Access Vulnerability + + + CONFIRM + http://ipswitch.com/Support/IMail/news.html + + + XF + ipswitch-imail-smtp-bo(6445) + + + OSVDB + 5610 + + Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header. + + + + + + + + + cpe:/a:datawizard:webxq:2.1.204 + + CVE-2001-0495 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:15.350-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2660 + + + BUGTRAQ + 20010426 Vulnerability in WebXQ Server + + + XF + webxq-dot-directory-traversal(6466) + + + OSVDB + 1799 + + Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:2007 + cpe:/o:redhat:linux:7.1::i386 + + CVE-2001-0496 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:24:15.490-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:059 + + + MANDRAKE + MDKSA-2001:046 + + + XF + kdelibs-kdesu-insecure-tmpfile(6856) + + kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges. + + + + + + + + + + cpe:/a:isc:bind:8.2.4 + cpe:/a:isc:bind:9.1.2 + + CVE-2001-0497 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:15.647-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ISS + 20010611 BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys + + + XF + bind-local-key-exposure(6694) + + + OSVDB + 5609 + + dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.7 + + CVE-2001-0498 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:08:13.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NAI + 20010627 Oracle 8i SQLNet Header Vulnerability + + Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension. + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.7 + + CVE-2001-0499 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:08:13.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#620495 + + + CERT + CA-2001-16 + + + XF + oracle-tns-listener-bo(6758) + + + BID + 2941 + + + NAI + 20010627 Vulnerability in Oracle 8i TNS Listener + + Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. + + + + + + + + + + + cpe:/a:microsoft:indexing_service:::windows_2000 + cpe:/a:microsoft:index_server:2.0 + cpe:/a:microsoft:internet_information_server:6.0:beta + + CVE-2001-0500 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:16.083-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT + CA-2001-13 + + + MS + MS01-033 + + + BID + 2880 + + + BUGTRAQ + 20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access) + + + XF + iis-isapi-idq-bo(6705) + + + CIAC + L-098 + + + + + Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red. + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:word:2000:sr1a + cpe:/a:microsoft:word:2002 + cpe:/a:microsoft:word:2001::mac + cpe:/a:microsoft:word:98 + cpe:/a:microsoft:word:97 + cpe:/a:microsoft:word:97:sr2 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:word:97:sr1 + cpe:/a:microsoft:word:98::mac + cpe:/a:microsoft:word:2000:sr2 + cpe:/a:microsoft:word:2000:sr1 + + CVE-2001-0501 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:16.240-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2876 + + + MS + MS01-034 + + + BUGTRAQ + 20010622 Fwd: Microsoft Word macro vulnerability advisory MS01-034 + + + XF + msword-macro-bypass-security(6732) + + Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0502 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:16.413-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS01-036 + + + XF + win2k-ldap-change-passwords(6745) + + + BID + 2929 + + + CIAC + L-101 + + Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users. + + + + + + + + + cpe:/a:microsoft:netmeeting:3.01 + + CVE-2001-0503 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:16.553-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS00-077 + + + OSVDB + 5608 + + + XF + netmeeting-desktop-sharing-dos(5368) + + Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0504 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:16.693-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#435963 + + + MS + MS01-037 + + + XF + win2k-smtp-mail-relay(6803) + + + BID + 2988 + + + CIAC + L-107 + + Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying. + + + + + + + + + cpe:/a:microsoft:services:2.0::unix + + CVE-2001-0505 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:16.850-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#994851 + + + CERT-VN + VU#581603 + + + MS + MS01-039 + + + XF + sfu-telnet-dos(6883) + + + XF + sfu-nfs-dos(6882) + + + BID + 3089 + + Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0506 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:16.990-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3190 + + + MS + MS01-044 + + + XF + iis-ssi-directive-bo(6984) + + + CIAC + L-132 + + + BUGTRAQ + 20011127 IIS Server Side Include Buffer overflow exploit code + + + BUGTRAQ + 20010817 NSFOCUS SA2001-06 : Microsoft IIS ssinc.dll Buffer Overflow Vulnerability + + Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0507 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:17.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MS + MS01-044 + + + XF + iis-relative-path-privilege-elevation(6985) + + + OSVDB + 5607 + + + CIAC + L-132 + + + BUGTRAQ + 20010816 ENTERCEPT SECURITY ALERT: Privilege Escalation Vulnerability in Microsoft IIS + + + + + + + + IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0508 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:17.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-044 + + + BID + 2690 + + + OSVDB + 5633 + + + OSVDB + 5606 + + + XF + iis-webdav-long-request-dos(6982) + + + BUGTRAQ + 20010506 IIS 5.0 PROPFIND DOS #2 + + Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/o:microsoft:windows_2000 + cpe:/a:microsoft:sql_server:2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0509 + 2001-09-20T00:00:00.000-04:00 + 2008-09-10T15:08:15.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS01-041 + + + + + Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs. + + + + + + + + + cpe:/a:oracle:oracle9i + + CVE-2001-0513 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:17.583-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#105259 + + + ISS + 20010619 Oracle Redirect Denial of Service + + + XF + oracle-listener-redirect-dos(6717) + + + OSVDB + 5600 + + Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port. + + + + + + + + + + + cpe:/h:netgear:me102 + cpe:/h:linksys:wap11 + cpe:/h:atmel:802.11b_vnet-b_access_point:1.3 + + CVE-2001-0514 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:17.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20010620 Multiple Vendor 802.11b Access Point SNMP authentication flaw + + + XF + atmel-vnetb-ap-snmp-security(6576) + + + BID + 2896 + + SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network. + + + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.6 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:database_server:7.3 + + CVE-2001-0515 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:08:15.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20010515 Multiple Oracle Listener Denial of Service Vulnerabilities + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf + + Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. + + + + + + + + + + cpe:/a:oracle:oracle9i + cpe:/a:oracle:oracle8i + + CVE-2001-0516 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:08:15.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20010515 Multiple Oracle Listener Denial of Service Vulnerabilities + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf + + Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data. + + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.6 + cpe:/a:oracle:oracle8i:8.1.7 + + CVE-2001-0517 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:18.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + oracle-listener-data-transport-dos(6715) + + + ISS + 20010515 Multiple Oracle Listener Denial of Service Vulnerabilities + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf + + + OSVDB + 5590 + + Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0. + + + + + + + + + cpe:/a:oracle:oracle9i + + CVE-2001-0518 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:24:18.303-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + oracle-listener-fragmentation-dos(6716) + + + ISS + 20010515 Multiple Oracle Listener Denial of Service Vulnerabilities + + + CONFIRM + http://otn.oracle.com/deploy/security/alerts.htm + + Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang. + + + + + + + + + cpe:/a:aladdin_knowledge_systems:esafe_gateway:2.0 + + CVE-2001-0519 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:18.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010529 Aladdin eSafe Gateway Filter Bypass - Updated Advisory + + + XF + esafe-gateway-bypass-filtering(6580) + + Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags. + + + + + + + + + cpe:/a:aladdin_knowledge_systems:esafe_gateway:3.0 + + CVE-2001-0520 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:18.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + esafe-gateway-bypass-filtering(6580) + + + BUGTRAQ + 20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tags + + Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined. + + + + + + + + + cpe:/a:aladdin_knowledge_systems:esafe_gateway:3.0 + + CVE-2001-0521 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:18.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + esafe-gateway-bypass-filtering(6580) + + + BUGTRAQ + 20010529 Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability + + Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document. + + + + + + + + + + + cpe:/a:gnu:privacy_guard:8.0 + cpe:/a:gnu:privacy_guard:7.1 + cpe:/a:gnu:privacy_guard:7.2 + + CVE-2001-0522 + 2001-08-14T00:00:00.000-04:00 + 2008-09-10T15:08:16.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#403051 + + + MANDRAKE + MDKSA-2001:053 + + + CONFIRM + http://www.gnupg.org/whatsnew.html#rn20010529 + + + XF + gnupg-tty-format-string(6642) + + + TURBO + TLSA2001028 + + + BID + 2797 + + + REDHAT + RHSA-2001:073 + + + OSVDB + 1845 + + + SUSE + SuSE-SA:2001:020 + + + DEBIAN + DSA-061 + + + CALDERA + CSSA-2001-020.0 + + + BUGTRAQ + 20010601 The GnuPG format string bug (was: TSLSA-2001-0009 - GnuPG) + + + IMMUNIX + IMNX-2001-70-023-01 + + + CONECTIVA + CLA-2001:399 + + Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file. + + + + + + + + + + cpe:/a:eeye_digital_security:securells:1.0.3 + cpe:/a:eeye_digital_security:secureiis:1.0.2 + + CVE-2001-0523 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.053-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eeye-secureiis-directory-traversal(6564) + + + XF + eeye-secureiis-bypass-detection(6563) + + + BUGTRAQ + 20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS + + + BUGTRAQ + 20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS + + eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected. + + + + + + + + + cpe:/a:eeye_digital_security:securells:1.0.3 + + CVE-2001-0524 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eeye-secureiis-http-header-bo(6574) + + + BUGTRAQ + 20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS + + + BUGTRAQ + 20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS + + eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier. + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2001-0525 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.350-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + dqs-dsh-bo(6577) + + + BUGTRAQ + 20010519 Re: dqs 3.2.7 local root exploit. + + + BUGTRAQ + 20010519 dqs 3.2.7 local root exploit. + + + BID + 2749 + + Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument. + + + + + + + + + + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + + CVE-2001-0526 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.490-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + solaris-mailtool-openwinhome-bo(6626) + + + BUGTRAQ + 20010528 [synnergy] - Solaris mailtool(1) buffer overflow vulnerability + + Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable. + + + + + + + + + + cpe:/a:dcscripts:dcforum_2000:1.0 + cpe:/a:dcscripts:dcforum:6.0 + + CVE-2001-0527 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.630-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + dcforum-cgi-admin-access(6538) + + + CONFIRM + http://www.dcscripts.com/dcforum/dcfNews/167.html + + + BUGTRAQ + 20010515 DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2) + + + BID + 2728 + + + OSVDB + 480 + + DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. + + + + + + + + + cpe:/a:oracle:e-business_suite:11i + + CVE-2001-0528 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.770-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + oracle-adi-plaintext-passwords(6501) + + + BID + 2694 + + + BUGTRAQ + 20010522 Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator + + + BUGTRAQ + 20010507 Oracle's ADI 7.1.1.10.1 Major security hole + + Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges. + + + + + + + + + cpe:/a:openbsd:openssh:2.9 + + CVE-2001-0529 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:19.927-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#655259 + + + BID + 2825 + + + NETBSD + NetBSD-SA2001-010 + + + CALDERA + CSSA-2001-023.0 + + + BUGTRAQ + 20010604 Re: SSH allows deletion of other users files... + + + BUGTRAQ + 20010604 SSH allows deletion of other users files... + + + XF + openssh-symlink-file-deletion(6676) + + + OSVDB + 1853 + + + OPENBSD + 20010612 + + + BUGTRAQ + 20010605 OpenSSH_2.5.2p2 RH7.0 <- version info + + + IMMUNIX + IMNX-2001-70-034-01 + + + CONECTIVA + CLA-2001:431 + + OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack. + + + + + + + + + + cpe:/h:spearhead:netgap_200:78 + cpe:/h:spearhead:netgap_300:78 + + CVE-2001-0530 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:20.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netgap-unicode-bypass-filter(6625) + + + BID + 2798 + + + BUGTRAQ + 20010607 SpearHead Security NetGAP + + + BUGTRAQ + 20010528 Vulnerability discovered in SpearHead NetGap + + Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters. + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:5.1 + + CVE-2001-0533 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:20.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + IBM + MSS-OAR-E01-2001:271.1 + + + XF + aix-libi18n-lang-bo(6863) + + + OSVDB + 5585 + + + CIAC + L-123 + + Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable. + + + + + + + + + + cpe:/a:lucent:radius:2.1.2 + cpe:/a:merit:radius:3.6b + + CVE-2001-0534 + 2001-07-21T00:00:00.000-04:00 + 2008-09-10T15:08:17.883-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#898931 + + + ISS + 20010705 Remote Buffer Overflow in Multiple RADIUS Implementations + + + BID + 2989 + + Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands. + + + + + + + + + cpe:/a:macromedia:coldfusion_server:4.x + + CVE-2001-0535 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:20.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ISS + 20010807 Remote Vulnerabilities in Macromedia ColdFusion Example Applications + + + ALLAIRE + MPSB01-08 + + Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1yd + cpe:/o:cisco:ios:12.1yc + cpe:/o:cisco:ios:11.3t + cpe:/o:cisco:ios:12.1yb + cpe:/o:cisco:ios:12.2xa + cpe:/o:cisco:ios:12.1ya + cpe:/o:cisco:ios:12.2xd + cpe:/o:cisco:ios:11.3ha + cpe:/o:cisco:ios:12.1yf + cpe:/o:cisco:ios:12.2xe + cpe:/o:cisco:ios:11.3db + cpe:/o:cisco:ios:12.1xz + cpe:/o:cisco:ios:11.3da + cpe:/o:cisco:ios:12.1xy + cpe:/o:cisco:ios:12.1xx + cpe:/o:cisco:ios:12.0%287%29xk + cpe:/o:cisco:ios:12.1aa + cpe:/o:cisco:ios:12.2xq + cpe:/o:cisco:ios:12.1ez + cpe:/o:cisco:ios:12.1ey + cpe:/o:cisco:ios:12.1ex + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.2xh + cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29 + cpe:/o:cisco:ios:11.3xa + cpe:/o:cisco:ios:12.0%2814%29w5%2820%29 + cpe:/o:cisco:ios:11.3 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.1ec + cpe:/o:cisco:ios:12.0sl + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.0wc + cpe:/o:cisco:ios:11.3na + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0dc + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:12.0da + cpe:/o:cisco:ios:11.3aa + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1db + cpe:/o:cisco:ios:12.1dc + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.0sc + cpe:/o:cisco:ios:12.1da + cpe:/o:cisco:ios:12.0wt + cpe:/o:cisco:ios:12.1cx + cpe:/o:cisco:ios:12.1xm + cpe:/o:cisco:ios:12.1xl + cpe:/o:cisco:ios:12.1xk + cpe:/o:cisco:ios:12.1xj + cpe:/o:cisco:ios:12.1xi + cpe:/o:cisco:ios:12.1xh + cpe:/o:cisco:ios:12.1xw + cpe:/o:cisco:ios:12.0xb + cpe:/o:cisco:ios:12.1xv + cpe:/o:cisco:ios:12.0xa + cpe:/o:cisco:ios:12.1xu + cpe:/o:cisco:ios:12.0xd + cpe:/o:cisco:ios:12.1xt + cpe:/o:cisco:ios:12.0xc + cpe:/o:cisco:ios:12.1xs + cpe:/o:cisco:ios:12.0xf + cpe:/o:cisco:ios:12.1xr + cpe:/o:cisco:ios:12.0xe + cpe:/o:cisco:ios:12.1xq + cpe:/o:cisco:ios:12.0xh + cpe:/o:cisco:ios:12.1xp + cpe:/o:cisco:ios:11.3ma + cpe:/o:cisco:ios:12.0xg + cpe:/o:cisco:ios:12.0xi + cpe:/o:cisco:ios:12.0%285%29xk + cpe:/o:cisco:ios:12.0xj + cpe:/o:cisco:ios:12.0xl + cpe:/o:cisco:ios:12.0xm + cpe:/o:cisco:ios:12.0xn + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.0xp + cpe:/o:cisco:ios:12.1xf + cpe:/o:cisco:ios:12.0xq + cpe:/o:cisco:ios:12.1xg + cpe:/o:cisco:ios:12.0xr + cpe:/o:cisco:ios:12.1xd + cpe:/o:cisco:ios:12.0st + cpe:/o:cisco:ios:12.0xs + cpe:/o:cisco:ios:12.1xe + cpe:/o:cisco:ios:12.1xb + cpe:/o:cisco:ios:12.0xu + cpe:/o:cisco:ios:12.1xc + cpe:/o:cisco:ios:12.0xv + cpe:/o:cisco:ios:12.1xa + + CVE-2001-0537 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T00:00:00.000-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT + CA-2001-14 + + + BID + 2936 + + + CISCO + 20010627 IOS HTTP authorization vulnerability + + + XF + cisco-ios-admin-access(6749) + + + BUGTRAQ + 20010702 Cisco device HTTP exploit... + + + BUGTRAQ + 20010629 Re: Cisco Security Advisory: IOS HTTP authorization vulnerability + + + BUGTRAQ + 20010702 ios-http-auth.sh + + + BUGTRAQ + 20010702 Cisco IOS HTTP Configuration Exploit + + + OSVDB + 578 + + + CIAC + L-106 + + + + + HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. + + + + + + + + + cpe:/a:microsoft:outlook:2002 + + CVE-2001-0538 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:21.020-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#131569 + + + MS + MS01-038 + + + BUGTRAQ + 20010712 MS Office XP - the more money I give to Microsoft, the more vulnerable my Windows computers are + + + XF + outlook-activex-view-control(6831) + + + BID + 3025 + + + NTBUGTRAQ + 20010712 Vulnerability in IE/Outlook ActiveX control + + + CIAC + L-113 + + Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. + + + + + + + + + cpe:/a:microsoft:terminal_server + + CVE-2001-0540 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:21.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-040 + + + XF + win-terminal-rdp-dos(6912) + + + BID + 3099 + + Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389. + + + + + + + + + + + cpe:/a:microsoft:windows_media_player:7.1 + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2001-0541 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:21.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-042 + + + BUGTRAQ + 20010527 Microsoft Windows Media Player Buffer Overflow Vulnerability + + + XF + mediaplayer-nsc-bo(6907) + + + BID + 3105 + + Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file. + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:2000 + + CVE-2001-0542 + 2001-12-20T00:00:00.000-05:00 + 2008-09-10T15:08:20.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#700575 + + + XF + mssql-text-message-bo(7724) + + + BID + 3733 + + + MS + MS01-060 + + + ATSTAKE + A122001-1 + + + BUGTRAQ + 20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server + + + + + Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879. + + + + + + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0543 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:21.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS01-043 + + + XF + win-nntp-dos(6977) + + + BID + 3183 + + + + + Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0544 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:21.770-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-044 + + + XF + iis-invalid-mime-header-dos(6983) + + + BID + 3195 + + + CIAC + L-132 + + IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0545 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:21.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-044 + + + XF + iis-url-redirection-dos(6981) + + + OSVDB + 5736 + + + CIAC + L-132 + + IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length. + + + + + + + + + cpe:/a:microsoft:isa_server:2000 + + CVE-2001-0546 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:22.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-045 + + + XF + isa-h323-gatekeeper-dos(6989) + + + BID + 3196 + + Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data. + + + + + + + + + cpe:/a:microsoft:isa_server:2000 + + CVE-2001-0547 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:22.223-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-045 + + + XF + isa-proxy-memory-leak-dos(6990) + + + BID + 3197 + + Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion). + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + + CVE-2001-0548 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:22.380-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010724 NSFOCUS SA2001-04 : Solaris dtmail Buffer Overflow Vulnerability + + + XF + solaris-dtmail-bo(6879) + + + BID + 3081 + + Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable. + + + + + + + + + cpe:/a:symantec:liveupdate:1.5 + + CVE-2001-0549 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:22.520-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#814187 + + + CONFIRM + http://www.sarc.com/avcenter/security/Content/2001_07_20.html + + + XF + liveupdate-obtain-proxy-password(7013) + + Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords. + + + + + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.6.0 + cpe:/a:washington_university:wu-ftpd:2.6.1 + cpe:/a:washington_university:wu-ftpd:2.5.0 + cpe:/a:david_madore:ftpd-bsd:0.3.2 + cpe:/a:david_madore:ftpd-bsd:0.3.3 + + CVE-2001-0550 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:24:22.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#886083 + + + CERT + CA-2001-33 + + + BID + 3581 + + + REDHAT + RHSA-2001:157 + + + CALDERA + CSSA-2001-041.0 + + + XF + wuftp-glob-heap-corruption(7611) + + + HP + HPSBUX0107-162 + + + VULN-DEV + 20010430 some ftpd implementations mishandle CWD ~{ + + + SUSE + SuSE-SA:2001:043 + + + MANDRAKE + MDKSA-2001:090 + + + DEBIAN + DSA-087 + + + BUGTRAQ + 20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability + + + IMMUNIX + IMNX-2001-70-036-01 + + + CONECTIVA + CLA-2001:442 + + wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-0551 + 2001-05-22T00:00:00.000-04:00 + 2009-03-04T00:08:09.000-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#860296 + + + HP + HPSBUX0105-151 + + + + + Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window. + + + + + + + + + + + + cpe:/a:ibm:tivoli_netview:6.0 + cpe:/a:hp:openview_network_node_manager:6.1 + cpe:/a:ibm:tivoli_netview:5.0 + cpe:/a:hp:openview_network_node_manager:5.01 + + CVE-2001-0552 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:22.973-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#952171 + + + CERT + CA-2001-24 + + + BID + 2845 + + + BUGTRAQ + 20010608 HP Openview NNM6.1 ovactiond bin exploit + + ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message. + + + + + + + + + cpe:/a:ssh:secure_shell:3.0.0 + + CVE-2001-0553 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:23.130-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#737451 + + + BUGTRAQ + 20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0 + + + CONFIRM + http://www.ssh.com/products/ssh/exploit.cfm + + + XF + ssh-password-length-unauth-access(6868) + + + BID + 3078 + + + OSVDB + 586 + + + CIAC + L-121 + + SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:sgi:irix:6.5 + cpe:/o:sun:solaris:8.0 + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:ibm:aix:5.1 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/a:mit:kerberos:5_1.1 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/a:mit:kerberos:5_1.1.1 + cpe:/o:netbsd:netbsd:1.4.2 + cpe:/a:netkit:linux_netkit:0.12 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/a:netkit:linux_netkit:0.11 + cpe:/o:openbsd:openbsd:2.3 + cpe:/a:netkit:linux_netkit:0.10 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:openbsd:openbsd:2.5 + cpe:/a:mit:kerberos:1.0 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:openbsd:openbsd:2.8 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:freebsd:freebsd:4.3 + cpe:/a:mit:kerberos:5-1.2.2 + cpe:/o:freebsd:freebsd:4.2 + cpe:/a:mit:kerberos:5-1.2 + cpe:/a:mit:kerberos:5-1.2.1 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.0 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sun:solaris:2.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:sun:solaris:2.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:4.1.1 + + CVE-2001-0554 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:23.287-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-21 + + + BID + 3064 + + + FREEBSD + FreeBSD-SA-01:49 + + + XF + telnetd-option-telrcv-bo(6875) + + + BUGTRAQ + 20010718 multiple vendor telnet daemon vulnerability + + + REDHAT + RHSA-2001:100 + + + REDHAT + RHSA-2001:099 + + + OSVDB + 809 + + + SUSE + SuSE-SA:2001:029 + + + MANDRAKE + MDKSA-2001:068 + + + DEBIAN + DSA-075 + + + DEBIAN + DSA-070 + + + CISCO + 20020129 Cisco CatOS Telnet Buffer Vulnerability + + + CIAC + L-131 + + + CALDERA + CSSA-2001-030.0 + + + BUGTRAQ + 20010810 ADV/EXP: netkit <=0.17 in.telnetd remote buffer overflow + + + BUGTRAQ + 20010725 SCO - Telnetd AYT overflow ? + + + BUGTRAQ + 20010725 Telnetd AYT overflow scanner + + + IBM + MSS-OAR-E01-2001:298 + + + COMPAQ + SSRT0745U + + + CONECTIVA + CLA-2001:413 + + + HP + HPSBUX0110-172 + + + CALDERA + CSSA-2001-SCO.10 + + + SGI + 20010801-01-P + + + NETBSD + NetBSD-SA2001-012 + + + + + Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. + + + + + + + + + cpe:/a:screaming_media:siteware:3.1 + + CVE-2001-0555 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:23.630-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#795707 + + + CONFIRM + http://www01.screamingmedia.com/en/security/sms1001.php + + + XF + siteware-dot-file-retrieval(6689) + + + BID + 2869 + + + OSVDB + 13887 + + + BUGTRAQ + 20010613 ScreamingMedia SITEWare source code disclosure vulnerability + + + BUGTRAQ + 20010613 ScreamingMedia SITEWare arbitrary file retrieval vulnerability + + ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet. + + + + + + + + + cpe:/a:nedit:nedit:5.1.1 + + CVE-2001-0556 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:08:24.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2667 + + + REDHAT + RHSA-2001:061 + + + MANDRAKE + MDKSA-2001:042 + + + DEBIAN + DSA-053 + + + BUGTRAQ + 20010428 More nedit problems ? (was Re: PROGENY-SA-2001-10...) + + + SUSE + SuSE-SA:2001:14 + + + CONFIRM + http://www.nedit.org/archives/develop/2001-Feb/0391.html + + The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file. + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.0j + cpe:/a:t._hauck:jana_web_server:2.0_beta_1 + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + + CVE-2001-0557 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:23.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#132099 + + + XF + jana-server-directory-traversal(6513) + + + BID + 2703 + + + BUGTRAQ + 20010507 Advisory for Jana server + + T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0b2 + cpe:/a:t._hauck:jana_web_server:2.0beta1 + + CVE-2001-0558 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:24.130-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + jana-server-device-dos(6521) + + + BUGTRAQ + 20010507 Advisory for Jana server + + + BID + 2704 + + + OSVDB + 1817 + + T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0). + + + + + + + + + cpe:/a:paul_vixie:vixie_cron:3.0.1 + + CVE-2001-0559 + 2001-08-14T00:00:00.000-04:00 + 2008-09-10T15:08:24.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2687 + + + BUGTRAQ + 20010507 Vixie cron vulnerability + + + MANDRAKE + MDKSA-2001:050 + + + DEBIAN + DSA-054 + + + XF + vixie-cron-gain-privileges(6508) + + + SUSE + SuSE-SA:2001:17 + + crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. + + + + + + + + + cpe:/a:paul_vixie:vixie_cron:3.0.1.56 + + CVE-2001-0560 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:24.427-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + vixie-crontab-bo(6098) + + + REDHAT + RHSA-2001:014 + + + MANDRAKE + MDKSA-2001:022 + + + BUGTRAQ + 20010220 Immunix OS Security update for vixie-cron + + + BUGTRAQ + 20010210 vixie cron possible local root compromise + + + OSVDB + 5583 + + + AIXAPAR + IY17261 + + + AIXAPAR + IY17048 + + Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters). + + + + + + + + + + cpe:/a:drummond_miles:a1stats:1.0 + cpe:/a:drummond_miles:a1stats:1.6 + + CVE-2001-0561 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:24.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#471691 + + + XF + a1stats-dot-directory-traversal(6503) + + + BUGTRAQ + 20010507 Advisory for A1Stats + + + BID + 2705 + + Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. + + + + + + + + + cpe:/a:drummond_miles:a1stats:1.6 + + CVE-2001-0562 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:24.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + a1stats-a1admin-dos(6505) + + + BUGTRAQ + 20010507 Advisory for A1Stats + + + BID + 2705 + + a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters. + + + + + + + + + + cpe:/a:electrosoft:electrocomm:1.0 + cpe:/a:electrosoft:electrocomm:2.0 + + CVE-2001-0563 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:24.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + electrocomm-telnet-dos(6514) + + + BID + 2706 + + + BUGTRAQ + 20010507 Advisory for Electrocomm 2.0 + + ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23. + + + + + + + + + cpe:/h:apc:ap9606:3.0 + + CVE-2001-0564 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:08:25.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010225 APC web/snmp/telnet management card dos + + + XF + apc-telnet-dos(6199) + + + BID + 2430 + + + MISC + ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt + + APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:2.6::sparc + cpe:/o:sun:solaris:2.5::sparc + cpe:/o:sun:solaris:2.5.1::sparc + cpe:/o:sun:solaris:7.0::sparc + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0565 + 2001-08-14T00:00:00.000-04:00 + 2008-09-10T15:08:25.523-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#446864 + + + BUGTRAQ + 20010502 Solaris mailx Vulnerability + + + XF + solaris-mailx-f-bo(8246) + + + BID + 2610 + + + BUGTRAQ + 20010511 Solaris /usr/bin/mailx exploit (SPARC) + + Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option. + + + + + + + + + cpe:/h:cisco:catalyst_2900:xl + + CVE-2001-0566 + 2001-08-14T00:00:00.000-04:00 + 2008-09-10T15:08:25.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-catalyst-udp-dos(6515) + + + BUGTRAQ + 20010503 Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled. + + Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled. + + + + + + + + + + cpe:/a:zope:zope:7.2 + cpe:/a:zope:zope:7.1 + + CVE-2001-0567 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:25.473-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:065 + + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert + + + MANDRAKE + MDKSA-2001:049 + + + DEBIAN + DSA-055 + + + XF + zope-zclass-gain-privileges(6958) + + + CONECTIVA + CLA-2001:407 + + Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass. + + + + + + + + + cpe:/a:zope:zope:2.3.1_b1 + + CVE-2001-0568 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:25.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23 + + + REDHAT + RHSA-2001:021 + + + MANDRAKE + MDKSA-2001:025 + + + DEBIAN + DSA-043 + + + CONECTIVA + CLA-2001:382 + + Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes. + + + + + + + + + cpe:/a:zope:zope:2.3.1_b1 + + CVE-2001-0569 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:25.770-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23 + + + REDHAT + RHSA-2001:021 + + + MANDRAKE + MDKSA-2001:025 + + + DEBIAN + DSA-043 + + + CONECTIVA + CLA-2001:382 + + Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet. + + + + + + + + + cpe:/a:minicom:minicom:1.83.1 + + CVE-2001-0570 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:25.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + minicom-xmodem-format-string(6498) + + + REDHAT + RHSA-2001:067 + + + CALDERA + CSSA-2001-016.0 + + + BUGTRAQ + 20010517 Immunix OS Security update for minicom + + + BUGTRAQ + 20010503 minicom exploit + + minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks. + + + + + + + + + + cpe:/a:elron:im_anti_virus:3.0.3 + cpe:/a:elron:im_message_inspector:3.0.3 + + CVE-2001-0571 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:26.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2520 + + + BID + 2519 + + + BUGTRAQ + 20010326 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html + + + BUGTRAQ + 20010323 Elron IM Products Vulnerability + + + BUGTRAQ + 20010406 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html + + Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL. + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:openbsd:openssh:4.5 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-0572 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:26.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#596827 + + + REDHAT + RHSA-2001:033 + + + MANDRAKE + MDKSA-2001:033 + + + BUGTRAQ + 20010318 Passive Analysis of SSH (Secure Shell) Traffic + + + CONECTIVA + CLA-2001:391 + + The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands. + + + + + + + + + cpe:/o:ibm:aix:4 + + CVE-2001-0573 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:26.367-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#123651 + + + AIXAPAR + IY16909 + + + XF + aix-lsfs-path(7007) + + + OSVDB + 5582 + + lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory. + + + + + + + + + + + + cpe:/a:jason_rahaim:mp3mystic:1.0.3 + cpe:/a:jason_rahaim:mp3mystic:1.0.1 + cpe:/a:jason_rahaim:mp3mystic:1.0 + cpe:/a:jason_rahaim:mp3mystic:1.0.4 + + CVE-2001-0574 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:26.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mp3mystic-dot-directory-traversal(6504) + + + BID + 2699 + + + CONFIRM + http://mp3mystic.com/mp3mystic/news.phtml + + + BUGTRAQ + 20010507 Advisory for MP3Mystic + + + OSVDB + 1815 + + Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0575 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:26.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sco-openserver-lpshut-bo(6290) + + + BUGTRAQ + 20010327 SCO 5.0.6 issues (lpshut) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0576 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T00:00:00.000-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + XF + sco-openserver-lpusers-bo(6292) + + + BUGTRAQ + 20010327 SCO 5.0.6 issues (lpusers) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0577 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:26.957-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sco-openserver-recon-bo(6289) + + + BUGTRAQ + 20010327 SCO 5.0.6 issues (recon) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0578 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:27.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sco-openserver-lpforms-bo(6293) + + + BUGTRAQ + 20010327 SCO 5.0.6 issues (lpforms) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0579 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:27.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + sco-openserver-lpadmin-bo(6291) + + + BUGTRAQ + 20010327 SCO 5.0.6 issues (lpadmin) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command. + + + + + + + + + cpe:/a:hughes_technologies:dsl_vdns:1.0 + + CVE-2001-0580 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:08:27.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 200105007 Advisory for Vdns + + Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection. + + + + + + + + + cpe:/a:spytech:spynet_chat:6.5 + + CVE-2001-0581 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:27.537-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2701 + + + XF + spynet-connection-dos(6509) + + + BUGTRAQ + 20010507 Advisory for Spynet Chat + + Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387. + + + + + + + + + + cpe:/a:ben_spink:crushftp_ftp_server:2.1.4 + cpe:/a:ben_spink:crushftp_ftp_server:2.1.6 + + CVE-2001-0582 + 2001-08-22T00:00:00.000-04:00 + 2009-04-03T00:08:31.657-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#110803 + + + XF + crushftp-directory-traversal(6495) + + + BUGTRAQ + 20010503 Vulnerabilities in CrushFTP Server + + Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR. + + + + + + + + + + cpe:/a:alt-n:mdaemon:3.5.4::pro + cpe:/a:alt-n:mdaemon:3.5.4::standard + + CVE-2001-0583 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:27.817-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mdaemon-webservices-dos(6240) + + + BUGTRAQ + 20010315 def-2001-11: MDaemon 3.5.4 Dos-Device DoS + + + CONFIRM + http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/ + + Alt-N Technologies MDaemon 3.5.4 allows a remote attacker to create a denial of service via the URL request of a MS-DOS device (such as GET /aux) to (1) the Worldclient service at port 3000, or (2) the Webconfig service at port 3001. + + + + + + + + + cpe:/a:alt-n:mdaemon:3.5.6 + + CVE-2001-0584 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:27.973-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010325 MDaemon IMAP Denial Of Service + + + XF + mdaemon-imap-command-dos(6279) + + + BID + 2508 + + IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands. + + + + + + + + + cpe:/a:gordano:ntmail:6.0.3c + + CVE-2001-0585 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:28.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ntmail-long-url-dos(6249) + + + BID + 2494 + + + BUGTRAQ + 20010320 def-2001-13: NTMail Web Services DoS + + Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000. + + + + + + + + + cpe:/a:trend_micro:scanmail_exchange:3.5 + + CVE-2001-0586 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:28.270-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010330 STAT Security Advisory: Trend Micro's ScanMail for Exchange store s passwords in registry unprotected + + + XF + scanmail-reveals-credentials(6311) + + + OSVDB + 5581 + + TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0587 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:28.410-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sco-openserver-deliver-bo(6302) + + + BUGTRAQ + 20010327 SCO 5.0.6 MMDF issues (deliver) + + + BID + 2583 + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-0588 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:08:28.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010327 SCO 5.0.6 MMDF issues (sendmail 8.9.3) + + + BUGTRAQ + 20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes + + sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command. + + + + + + + + + + + + cpe:/o:juniper:netscreen_screenos:1.64 + cpe:/o:juniper:netscreen_screenos:2.1 + cpe:/o:juniper:netscreen_screenos:2.5 + cpe:/o:juniper:netscreen_screenos:1.66 + + CVE-2001-0589 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:28.707-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2523 + + + BUGTRAQ + 20010326 Netscreen: DMZ Network Receives Some "Denied" Traffic + + + XF + netscreen-screenos-bypass-firewall(6317) + + + OSVDB + 1780 + + NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns. + + + + + + + + + cpe:/a:apache:tomcat:3.2.2 + + CVE-2001-0590 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:28.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010403 Re: Tomcat may reveal script source code by URL trickery + + + XF + jakarta-tomcat-jsp-source(6971) + + + HP + HPSBTL0112-004 + + + OSVDB + 5580 + + Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:jsp:1.1.1 + + CVE-2001-0591 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:08:28.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2286 + + + BUGTRAQ + 20010212 Patch for Potential Vulnerability in the execution of JSPs outside doc_root + + + XF + oracle-handlers-directory-traversal(5986) + + Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack. + + + + + + + + + cpe:/h:watchguard:firebox_ii:4.6 + + CVE-2001-0592 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:29.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + firebox-kernel-dos(6327) + + + BUGTRAQ + 20010405 def-2001-18: Watchguard Firebox II Kernel DoS + + Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets. + + + + + + + + + cpe:/a:anaconda_partners:clipper:3.3 + + CVE-2001-0593 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:29.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010327 advisory + + + XF + anaconda-clipper-directory-traversal(6286) + + + BID + 2512 + + + MISC + http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&f1=ap_af_updates_menu&f2=ap_af_releasenotes_clip + + Ananconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter. + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0594 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:29.443-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + XF + solaris-kcms-command-bo(6359) + + + BUGTRAQ + 20010409 Solaris kcms_configure vulnerability + + + BID + 2558 + + + + + + + + kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument. + + + + + + + + + + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0595 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:29.583-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + solaris-kcssunwiosolf-bo(6365) + + + BID + 2605 + + + BUGTRAQ + 20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities + + Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program. + + + + + + + + + cpe:/a:netscape:communicator:4.77 + + CVE-2001-0596 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:29.740-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + netscape-javascript-access-data(6344) + + + REDHAT + RHSA-2001:046 + + + DEBIAN + DSA-051 + + + BUGTRAQ + 20010409 Netscape 4.76 gif comment flaw + + + BID + 2637 + + + OSVDB + 5579 + + + IMMUNIX + IMNX-2001-70-014-01 + + + CONECTIVA + CLA-2001:393 + + Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. + + + + + + + + + + + cpe:/a:zetetic_enterprises:strip:0.4 + cpe:/a:zetetic_enterprises:strip:0.3 + cpe:/a:zetetic_enterprises:strip:0.5 + + CVE-2001-0597 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:29.880-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + strip-weak-passwords(6362) + + + BID + 2567 + + + BUGTRAQ + 20010410 Catastrophic failure of Strip password generation. + + Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'. + + + + + + + + + cpe:/a:symantec:norton_ghost:6.5 + + CVE-2001-0598 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ghost-configuration-server-dos(6357) + + + BID + 2570 + + + BUGTRAQ + 20010411 def-2001-21: Ghost Multiple DoS + + Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled. + + + + + + + + + cpe:/a:sybase:adaptive_server_anywhere:6.0.3.2747 + + CVE-2001-0599 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ghost-database-engine-dos(6356) + + + BID + 2572 + + + BUGTRAQ + 20010411 def-2001-21: Ghost Multiple DoS + + Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.7 + + CVE-2001-0600 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.317-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-header-dos(6347) + + + BUGTRAQ + 20010411 def-2001-20: Lotus Domino Multiple DoS + + Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated URL requests with the same HTTP headers, such as (1) Accept, (2) Accept-Charset, (3) Accept-Encoding, (4) Accept-Language, and (5) Content-Type. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.7 + + CVE-2001-0601 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.457-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-unicode-dos(6349) + + + BUGTRAQ + 20010411 def-2001-20: Lotus Domino Multiple DoS + + Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.7 + + CVE-2001-0602 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-device-dos(6348) + + + BUGTRAQ + 20010411 def-2001-20: Lotus Domino Multiple DoS + + Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.7 + + CVE-2001-0603 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-corba-dos(6350) + + + BUGTRAQ + 20010411 def-2001-20: Lotus Domino Multiple DoS + + Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.7 + + CVE-2001-0604 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:30.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-url-dos(6351) + + + BUGTRAQ + 20010411 def-2001-20: Lotus Domino Multiple DoS + + Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters. + + + + + + + + + cpe:/a:headlight_software:mygetright:1.0b + + CVE-2001-0605 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:31.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010226 My Getright Unsupervised File Download Vulnerability + + Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data. + + + + + + + + + + cpe:/a:hp:virtualvault:4.0 + cpe:/a:sun:iplanet_web_server:4.1 + + CVE-2001-0606 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:31.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-virtualvault-iws-dos(6110) + + + HP + HPSBUX0102-139 + + Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2001-0607 + 2001-08-22T00:00:00.000-04:00 + 2009-03-04T00:08:15.703-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + HP + HPSBUX0103-145 + + + + + asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083. + + + + + + + + + cpe:/o:hp:mpe:6.5 + + CVE-2001-0608 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:31.473-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#895496 + + + HP + HPSBMP0103-011 + + + XF + hp-aif-gain-privileges(6951) + + HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program. + + + + + + + + + + + + cpe:/a:infodrom:cfingerd:1.4.3 + cpe:/a:infodrom:cfingerd:1.4.1 + cpe:/a:infodrom:cfingerd:1.4.2 + cpe:/a:infodrom:cfingerd:1.4.0 + + CVE-2001-0609 + 2001-08-02T00:00:00.000-04:00 + 2008-09-10T15:08:30.680-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cfingerd-remote-format-string(6364) + + + BID + 2576 + + + BUGTRAQ + 20010411 CFINGERD remote vulnerability + + Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function. + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0::sparc + cpe:/o:suse:suse_linux:7.0:alpha + cpe:/o:kde:kde:1.x + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.0::ppc + + CVE-2001-0610 + 2001-08-02T00:00:00.000-04:00 + 2008-09-10T15:08:30.790-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kfm-tmpfile-symlink(6428) + + + BUGTRAQ + 20010418 Insecure directory handling in KFM file manager + + kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp. + + + + + + + + + + + + + cpe:/a:rimarts_inc.:becky_internet_mail:2.0.5 + cpe:/a:rimarts_inc.:becky_internet_mail:2.0.3 + cpe:/a:rimarts_inc.:becky_internet_mail:1.26.3 + cpe:/a:rimarts_inc.:becky_internet_mail:1.26.5 + cpe:/a:rimarts_inc.:becky_internet_mail:1.26.4 + + CVE-2001-0611 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:31.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + becky-mail-message-bo(6531) + + + BID + 2723 + + + BUGTRAQ + 20010514 Becky! 2.00.05 Buffer Overflow + + Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters. + + + + + + + + + + + cpe:/a:mcafee:remote_desktop_32:3.0 + cpe:/a:mcafee:remote_desktop_32:2.1.2 + + CVE-2001-0612 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:32.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2726 + + + BUGTRAQ + 20010516 Remote Desktop DoS + + + XF + remote-desktop-dos(6547) + + + OSVDB + 6288 + + McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045. + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.0.8 + + CVE-2001-0613 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:32.223-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + omnihttpd-post-dos(6540) + + + BID + 2730 + + + BUGTRAQ + 20010515 OmniHTTPd Pro Denial of Service Vulnerability + + Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request. + + + + + + + + + cpe:/a:carello:e-commerce:1.2.1 + + CVE-2001-0614 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:32.363-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + carello-url-code-execution(6532) + + + BUGTRAQ + 20010514 def-2001-25: Carello E-Commerce Arbitrary Command Execution + + Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL. + + + + + + + + + cpe:/a:faust_informatics:freestyle_chat:4.1 + + CVE-2001-0615 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:32.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + freestyle-chat-directory-traversal(6601) + + + BID + 2776 + + + BUGTRAQ + 20010525 Advisory for Freestyle Chat server + + + OSVDB + 1841 + + Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'. + + + + + + + + + cpe:/a:faust_informatics:freestyle_chat:4.1 + + CVE-2001-0616 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:32.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + freestyle-chat-device-dos(6602) + + + BID + 2777 + + + BUGTRAQ + 20010525 Advisory for Freestyle Chat server + + Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). + + + + + + + + + cpe:/h:alliedtelesyn:at-ar220e:1.08a:rc14 + + CVE-2001-0617 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:32.787-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + telesyn-portmapper-access-services(6560) + + + BUGTRAQ + 20010514 Cable-Router AR220e Portmapper Security-Flaw + + Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled. + + + + + + + + + cpe:/h:lucent:orinoco_rg-1000 + + CVE-2001-0618 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:32.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + orinoco-rg1000-wep-key(6328) + + + BUGTRAQ + 20010402 RG-1000 802.11 Residential Gateway default WEP key disclosure flaw + + Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic. + + + + + + + + + cpe:/h:lucent:orinoco + + CVE-2001-0619 + 2001-08-02T00:00:00.000-04:00 + 2008-09-10T15:08:31.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010402 Design Flaw in Lucent/Orinoco 802.11 proprietary access control- closed network + + The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear. + + + + + + + + + cpe:/a:iplanet:calendar_server:5.0p2 + + CVE-2001-0620 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:33.223-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iplanet-calendar-plaintext-password(6402) + + + BUGTRAQ + 20010418 iplanet calendar server 5.0p2 exposes Netscape Admin Server master password + + iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions. + + + + + + + + + cpe:/h:cisco:content_services_switch_11000 + + CVE-2001-0621 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:33.363-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-css-ftp-commands(6557) + + + CISCO + 20010517 Cisco Content Service Switch 11000 Series FTP Vulnerability + + + BID + 2745 + + + OSVDB + 1834 + + + CIAC + L-085 + + The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. + + + + + + + + + cpe:/h:cisco:content_services_switch_11000 + + CVE-2001-0622 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:33.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20010531 Cisco Content Service Switch 11000 Series Web Management Vulnerability + + + XF + cisco-css-web-management(6631) + + + BID + 2806 + + + OSVDB + 1848 + + The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface. + + + + + + + + + cpe:/a:sendfile:sendfile + + CVE-2001-0623 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:33.647-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + saft-sendfiled-execute-code(6430) + + + DEBIAN + DSA-052 + + + DEBIAN + DSA-050 + + sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges. + + + + + + + + + cpe:/a:qnx:qnx:2.4 + + CVE-2001-0624 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:24:33.787-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qnx-fat-file-read + + + VULN-DEV + 20010421 QNX FIle Read Vulnerability + + QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos. + + + + + + + + + cpe:/a:ca:inoculateit:6.0 + + CVE-2001-0625 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:33.943-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + inoculateit-ftpdownload-symlink(6607) + + + BID + 2778 + + + BUGTRAQ + 20010525 Security Bug in InoculateIT for Linux (fwd) + + + OSVDB + 1843 + + ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log . + + + + + + + + + cpe:/a:oreilly:website_professional:2.5.4 + + CVE-2001-0626 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:34.083-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2488 + + + BUGTRAQ + 20010316 WebServer Pro All Version Vulnerability + + + XF + website-pro-dir-path(3839) + + O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. + + + + + + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.6 + cpe:/o:sco:openserver:5.0.3 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sco:openserver:5.0.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + + CVE-2001-0627 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:34.287-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#747736 + + + BID + 2752 + + + BUGTRAQ + 20010522 [SRT2001-09] - vi and crontab -e /tmp issues + + + XF + sco-openserver-vi-symlink(6588) + + + CALDERA + CSSA-2001-SCO.17 + + vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack. + + + + + + + + + cpe:/a:microsoft:word:2000 + + CVE-2001-0628 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:34.443-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + word-asd-macro-execution(6614) + + + BID + 2760 + + + MSKB + Q274228 + + Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.1 + + CVE-2001-0629 + 2001-08-14T00:00:00.000-04:00 + 2008-09-10T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + openview-nnm-ecsd-bo(6582) + + + BID + 2761 + + + BUGTRAQ + 20010523 HP OpenView NNM v6.1 buffer overflow + + + HP + HPSBUX0107-158 + + + + + HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter. + + + + + + + + + cpe:/a:mimanet:source_viewer:2.0 + + CVE-2001-0630 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:34.723-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2762 + + + BUGTRAQ + 20010523 Vulnerability in viewsrc.cgi + + + XF + viewsrc-cgi-view-files(6583) + + + OSVDB + 5565 + + Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable. + + + + + + + + + cpe:/a:centrinity:centrinity_firstclass:5.50 + + CVE-2001-0631 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:34.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010226 Re: [Fwd: FirstClass Internetgateway "stupidity"] + + + BUGTRAQ + 20010221 FirstClass Internetgateway "stupidity" + + + XF + centrinity-firstclass-email-spoofing(6192) + + + BID + 2423 + + Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. + + + + + + + + + + cpe:/a:sun:chilisoft:3.6 + cpe:/a:sun:chilisoft:3.5.2 + + CVE-2001-0632 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:35.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities + + + BUGTRAQ + 20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities + + Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges. + + + + + + + + + cpe:/a:sun:chilisoft:3.5.2 + + CVE-2001-0633 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:35.160-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities + + + BUGTRAQ + 20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities + + Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'. + + + + + + + + + cpe:/a:sun:chilisoft:3.5.2 + + CVE-2001-0634 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:24:35.303-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010226 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities + + + BUGTRAQ + 20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities + + + XF + chilisoft-asp-license-dos(6176) + + + BID + 2409 + + Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service. + + + + + + + + + cpe:/o:redhat:linux:7.1 + + CVE-2001-0635 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:24:35.457-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:058 + + + XF + mount-swap-world-readable(6493) + + + OSVDB + 5564 + + Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords. + + + + + + + + + + cpe:/a:raytheon:silentrunner:2.0 + cpe:/a:raytheon:silentrunner:2.0.1 + + CVE-2001-0636 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:35.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20010806 Multiple Buffer Overflow Vulnerabilities in Raytheon SilentRunner + + Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1. NOTE: It is highly likely that this candidate will be split into multiple candidates. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:redhat:linux:6.2 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:redhat:linux:5.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:redhat:linux:7.0 + cpe:/o:suse:suse_linux:6.0 + cpe:/a:immunix:immunix:7.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + + CVE-2001-0641 + 2001-09-20T00:00:00.000-04:00 + 2008-09-10T15:08:33.837-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + man-s-bo(6530) + + + BID + 2711 + + + REDHAT + RHSA-2001:069 + + + BUGTRAQ + 20010513 RH 7.0:/usr/bin/man exploit: gid man + more + + + BUGTRAQ + 20010612 man 1.5h10 + man 1.5i-4 exploits + + + SUSE + SuSE-SA:2001:019 + + Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. + + + + + + + + + cpe:/a:incredimail:incredimail:1400185 + + CVE-2001-0642 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:35.927-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + incredimail-dot-overwrite-files(6529) + + + BUGTRAQ + 20010511 [eyeonsecurity.net] Incredimail allows automatic over writing offiles on your hard disk + + Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file. + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0643 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-clsid-execute-files(6426) + + + BUGTRAQ + 20010416 Double clicking on innocent looking files may be dangerous + + + MISC + http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html + + + MISC + http://vil.nai.com/vil/virusSummary.asp?virus_k=99048 + + + BID + 2612 + + + OSVDB + 7858 + + + MISC + http://www.guninski.com/clsidext.html + + Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. + + + + + + + + + + + + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.4 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:2.0.3_dev_3 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.2 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.3 + + CVE-2001-0644 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.207-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010515 Rumpus FTP DoS + + + XF + rumpus-plaintext-passwords(6543) + + + BID + 2718 + + Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server. + + + + + + + + + + cpe:/a:axent:netprowler:3.5.1 + cpe:/a:axent:netprowler:3.5 + + CVE-2001-0645 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.363-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#508387 + + + XF + netprowler-default-odbc-password(6539) + + + XF + netprowler-default-management-password(6537) + + + BUGTRAQ + 20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x password restrictions + + + BUGTRAQ + 20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration + + Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password. + + + + + + + + + + + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.4 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:2.0.3dev + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.2 + + CVE-2001-0646 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.520-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rumpus-long-directory-dos(6542) + + + BID + 2716 + + + BUGTRAQ + 20010515 Rumpus FTP DoS + + Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length. + + + + + + + + + cpe:/a:orange_software:orange_web_server:2.1 + + CVE-2001-0647 + 2001-08-06T00:00:00.000-04:00 + 2008-09-05T16:24:36.677-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2432 + + + BUGTRAQ + 20010227 Orange Web Server v2.1 DoS + + Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version. + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + + CVE-2001-0648 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.817-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phprojekt-dot-directory-traversal(6522) + + + BID + 2702 + + + BUGTRAQ + 20010508 security hole in os groupware suite PHProjekt + + Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module. + + + + + + + + + cpe:/a:apple:personal_web_sharing:1.5.5 + + CVE-2001-0649 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:36.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + macos-web-sharing-dos(6536) + + + BUGTRAQ + 20010510 Personal Web Sharing remote stop + + Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request. + + + + + + + + + + + + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.3 + cpe:/o:cisco:ios:11.2 + + CVE-2001-0650 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:37.097-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#106392 + + + XF + cisco-ios-bgp-dos(6566) + + + CISCO + 20010510 Cisco IOS BGP Attribute Corruption Vulnerability + + + BID + 2733 + + + OSVDB + 1830 + + + CIAC + L-082 + + + + + Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute. + + + + + + + + + cpe:/o:sun:solaris:8.0 + + CVE-2001-0652 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:37.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BUGTRAQ + 20010810 NSFOCUS SA2001-05 : Solaris Xlock Heap Overflow Vulnerability + + + XF + solaris-xlock-bo(6967) + + + BID + 3160 + + + + + + + + Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable. + + + + + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.11.2 + cpe:/a:sendmail:sendmail:8.12:beta7 + cpe:/a:sendmail:sendmail:8.11.3 + cpe:/a:sendmail:sendmail:8.11.4 + cpe:/a:sendmail:sendmail:8.11.5 + cpe:/a:sendmail:sendmail:8.12:beta12 + cpe:/a:sendmail:sendmail:8.11.0 + cpe:/a:sendmail:sendmail:8.12:beta5 + cpe:/a:sendmail:sendmail:8.12:beta10 + cpe:/a:sendmail:sendmail:8.11.1 + cpe:/a:sendmail:sendmail:8.12:beta16 + + CVE-2001-0653 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:37.397-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3163 + + + BUGTRAQ + 20010821 *ALERT* UPDATED BID 3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code Execution Vulnerability (fwd) + + + CONFIRM + http://www.sendmail.org/8.11.html + + + XF + sendmail-debug-signed-int-overflow(7016) + + + HP + HPSBTL0112-007 + + + SUSE + SuSE-SA:2001:028 + + + MANDRAKE + MDKSA-2001:075 + + + CIAC + L-133 + + + CALDERA + CSSA-2001-032.0 + + + REDHAT + RHSA-2001:106 + + + IMMUNIX + IMNX-2001-70-032-01 + + + CONECTIVA + CLA-2001:412 + + + NETBSD + NetBSD-SA2001-017 + + Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number. + + + + + + + + + cpe:/a:microsoft:isa_server:2000 + + CVE-2001-0658 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:37.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-045 + + + XF + isa-cross-site-scripting(6991) + + + BID + 3198 + + Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0659 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:37.707-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-046 + + + XF + win2k-irda-dos(7008) + + + BID + 3215 + + + BUGTRAQ + 20010821 IrDA semiremote vulnerability + + Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet. + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5:sp4 + + CVE-2001-0660 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:37.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-047 + + + MSKB + Q307195 + + + XF + exchange-owa-obtain-addresses(7089) + + + BID + 3301 + + Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL). + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0662 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:38.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-048 + + + XF + winnt-rpc-endpoint-dos(7105) + + + BID + 3313 + + + CIAC + L-142 + + RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-0663 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:38.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-052 + + + XF + win-rdp-packet-dos(7302) + + + BID + 3445 + + Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.01 + + CVE-2001-0664 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:38.287-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS01-051 + + + XF + ie-incorrect-security-zone(7258) + + + BID + 3420 + + + OSVDB + 1971 + + + MISC + http://morph3us.org/blog/?p=31 + + + BUGTRAQ + 20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing + + Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability." + + + + + + + + + cpe:/a:microsoft:ie:6:windows_server_2003_sp1 + + CVE-2001-0665 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:38.443-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-051 + + + XF + ie-url-http-requests(7259) + + + BID + 3421 + + + OSVDB + 1972 + + Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability." + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + + CVE-2001-0666 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:38.583-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-049 + + + XF + exchange-owa-folder-request-dos(7168) + + + BID + 3368 + + Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. + + + + + + + + + cpe:/a:microsoft:ie:6:windows_server_2003_sp1 + + CVE-2001-0667 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:38.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#952611 + + + MS + MS01-051 + + + XF + ie-telnet-command-execution-variant(7260) + + + CIAC + M-024 + + Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-0668 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:38.880-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#966075 + + + CERT + CA-2001-30 + + + ISS + 20010827 Remote Buffer Overflow Vulnerability in HP-UX Line Printer Daemon + + + XF + hpux-rlpd-bo(6811) + + + BID + 3240 + + + CIAC + L-134 + + + HP + HPSBUX0108-163 + + + + + Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands. + + + + + + + + + + + + + + + + + + + + cpe:/h:enterasys:dragon:4.x + cpe:/a:iss:realsecure_network_sensor:5.x + cpe:/a:cisco:secure_intrusion_detection_system + cpe:/a:iss:realsecure_server_sensor:6.0 + cpe:/a:iss:realsecure_server_sensor:5.5 + cpe:/a:snort:snort:1.8.1 + cpe:/a:iss:realsecure_network_sensor:6.x + cpe:/a:cisco:catalyst_6000_intrusion_detection_system_module + + CVE-2001-0669 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:39.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#548515 + + + ISS + 20010905 Multiple Vendor IDS Unicode Bypass Vulnerability + + + CISCO + 20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability + + + BUGTRAQ + 20010905 %u encoding IDS bypass vulnerability + + + BID + 3292 + + Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:openbsd:openbsd + cpe:/o:bsd:bsd:4.1 + + CVE-2001-0670 + 2001-10-03T00:00:00.000-04:00 + 2008-09-05T16:24:39.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#274043 + + + CERT + CA-2001-30 + + + ISS + 20010829 Remote Buffer Overflow Vulnerability in BSD Line Printer Daemon + + + OPENBSD + 20010829 + + + CALDERA + CSSA-2001-SCO.20 + + + XF + bsd-lpd-bo(7046) + + + BID + 3252 + + + REDHAT + RHSA-2001:147 + + + NETBSD + NetBSD-SA2001-018 + + Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue. + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:5.1 + + CVE-2001-0671 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:39.333-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#722143 + + + CERT-VN + VU#466239 + + + CERT-VN + VU#388183 + + + CERT + CA-2001-30 + + Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges. + + + + + + + + + + + + cpe:/a:robtex:viking_server:1.0.6 + cpe:/a:robtex:viking_server:1.0.7 + cpe:/a:robtex:viking_server:1.0.7_build381 + cpe:/a:robtex:viking_server:1.0.4 + + CVE-2001-0674 + 2001-09-20T00:00:00.000-04:00 + 2009-12-19T00:08:11.517-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + viking-hex-directory-traversal(6394) + + + BUGTRAQ + 20010417 Advisory for Viking + + + CONFIRM + http://www.robtex.com/viking/bugs.htm + + Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request. + + + + + + + + + cpe:/a:ritlabs:the_bat:1.51 + + CVE-2001-0675 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:39.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + thebat-pop3-dos(6423) + + + BID + 2636 + + + BUGTRAQ + 20010423 Re: SECURITY.NNOV: The Bat! <cr> bug + + + BUGTRAQ + 20010421 Re: SECURITY.NNOV: The Bat! <cr> bug + + + BUGTRAQ + 20010418 SECURITY.NNOV: The Bat! <cr> bug + + Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carrage return <CR> that is not followed by a line feed <LF>. + + + + + + + + + cpe:/a:ritlabs:the_bat:1.48f + + CVE-2001-0676 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:39.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + thebat-attachment-directory-traversal(5871) + + + BUGTRAQ + 20010104 SECURITY.NNOV advisory - The Bat! directory traversal (public release) + + Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment. + + + + + + + + + cpe:/a:qualcomm:eudora:5.0.2 + + CVE-2001-0677 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:39.927-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eudora-plain-text-attachment(6431) + + + BUGTRAQ + 20010418 Eudora file leakage problem (still) + + + BID + 2616 + + + OSVDB + 3085 + + Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user. + + + + + + + + + + cpe:/a:trend_micro:interscan_webmanager:1.2 + cpe:/a:trend_micro:interscan_viruswall:3.51 + + CVE-2001-0678 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:40.067-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + interscan-reggo-bo(6575) + + + BUGTRAQ + 20010519 TrendMicro Interscan VirusWall RegGo.dll BOf + + A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.3 + cpe:/a:trend_micro:interscan_viruswall:3.23 + + CVE-2001-0679 + 1999-11-08T00:00:00.000-05:00 + 2008-09-05T16:24:40.223-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + viruswall-helo-bo(3465) + + + NTBUGTRAQ + 19991109 InterScan VirusWall 3.23/3.3 Buffer Overflow + + + NTBUGTRAQ + 19991108 Patch for VirusWall 3.23. + + + NTBUGTRAQ + 19991108 Interscan VirusWall NT 3.23/3.3 buffer overflow. + + + BUGTRAQ + 19991108 Patch for VirusWall 3.23. + + A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server. + + + + + + + + + + + cpe:/a:qpc_software:qvt_net:5.0 + cpe:/a:qpc_software:avt_term:5.0 + cpe:/a:qpc_software:qvt_net:4.0 + + CVE-2001-0680 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:40.363-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qpc-ftpd-directory-traversal(6375) + + + BUGTRAQ + 20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities + + + BID + 2618 + + + OSVDB + 4050 + + + OSVDB + 1794 + + + BUGTRAQ + 20010925 Vulnerabilities in QVT/Term + + Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command. + + + + + + + + + + cpe:/a:qpc_software:qvt_net:5.0 + cpe:/a:qpc_software:qvt_term:5.0 + + CVE-2001-0681 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:40.520-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qpc-ftpd-bo(6376) + + + BUGTRAQ + 20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities + + Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password. + + + + + + + + + + cpe:/a:zonelabs:zonealarm:7.0.302.000::pro + cpe:/a:zonelabs:zonealarm + + CVE-2001-0682 + 2001-08-29T00:00:00.000-04:00 + 2008-09-05T16:24:40.660-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + zonealarm-mutex-dos(5821) + + + NTBUGTRAQ + 20001230 [DiamondCS Advisory] ZoneAlarm and ZoneAlarm Pro can be blocked from loading by setting a Mutex in memory + + ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting. + + + + + + + + + cpe:/a:netscape:collabra_server:3.5.4 + + CVE-2001-0683 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:40.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netscape-collabra-kernel-dos(6158) + + + BUGTRAQ + 20010226 def-2001-08: Netscape Collabra DoS + + Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238. + + + + + + + + + cpe:/a:netscape:collabra_server:3.5.4 + + CVE-2001-0684 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:40.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010226 def-2001-08: Netscape Collabra DoS + + + XF + netscape-collabra-cpu-dos(6159) + + Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239. + + + + + + + + + + + + + cpe:/a:thibault_godouet:fcron:1.0.3 + cpe:/a:thibault_godouet:fcron:1.0.2 + cpe:/a:thibault_godouet:fcron:1.0.1 + cpe:/a:thibault_godouet:fcron:1.0 + cpe:/a:thibault_godouet:fcron:1.1.0 + + CVE-2001-0685 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.097-04:00 + + + 2.6 + LOCAL + HIGH + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2835 + + + BUGTRAQ + 20010228 fcron 0.9.5 is vulnerable to a symlink attack + + + CONFIRM + http://fcron.free.fr/CHANGES.html + + + XF + fcron-tmpfile-symlink(7127) + + Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file. + + + + + + + + + + cpe:/o:sun:solaris:5.8::x86 + cpe:/o:sun:solaris:8.0::x86 + + CVE-2001-0686 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.240-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010604 $HOME buffer overflow in SunOS 5.8 x86 + + + BID + 2819 + + + XF + solaris-mail-home-bo(6638) + + Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable. + + + + + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:4.0 + cpe:/a:transsoft:broker_ftp_server:5.1 + cpe:/a:transsoft:broker_ftp_server:4.7.5.0 + cpe:/a:transsoft:broker_ftp_server:5.9.5.0 + cpe:/a:transsoft:broker_ftp_server:5.0 + + CVE-2001-0687 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + broker-ftp-cd-directory-traversal(6674) + + + BID + 2853 + + + BUGTRAQ + 20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal + + Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename). + + + + + + + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:4.0 + cpe:/a:transsoft:broker_ftp_server:5.1 + cpe:/a:transsoft:broker_ftp_server:4.7.5.0 + cpe:/a:transsoft:broker_ftp_server:5.7 + cpe:/a:transsoft:broker_ftp_server:5.9.5.0 + cpe:/a:transsoft:broker_ftp_server:3.0_build_1 + cpe:/a:transsoft:broker_ftp_server:5.0 + + CVE-2001-0688 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.537-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2851 + + + BUGTRAQ + 20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal + + Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command. + + + + + + + + + cpe:/a:trend_micro:virus_control_system:1.8 + + CVE-2001-0689 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010607 [SNS Advisory No.29] Trend Micro Virus Control System(VCS) + + Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program. + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:4.0 + cpe:/o:redhat:linux + cpe:/o:conectiva:linux + cpe:/a:university_of_cambridge:exim:3.22 + + CVE-2001-0690 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:41.847-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:078 + + + DEBIAN + DSA-058 + + + BUGTRAQ + 20010606 lil' exim format bug + + + XF + exim-syntax-format-string(6671) + + + BID + 2828 + + + CONECTIVA + CLA-2001:402 + + Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers. + + + + + + + + + + cpe:/a:university_of_washington:imapd:2000c + cpe:/a:university_of_washington:imapd:2000 + + CVE-2001-0691 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.003-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2856 + + + MANDRAKE + MDKSA-2001:054 + + + REDHAT + RHSA-2001:094 + + + XF + imap-ipop2d-ipop3d-bo(6269) + + Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations. + + + + + + + + + + + + cpe:/h:watchguard:firebox_4500:4.6 + cpe:/h:watchguard:firebox_4500:4.5 + cpe:/h:watchguard:firebox_2500:4.5 + cpe:/h:watchguard:firebox_2500:4.6 + + CVE-2001-0692 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2855 + + + BUGTRAQ + 20010628 RE: WatchGuard SMTP Proxy issue + + + XF + firebox-smtp-bypass-filter(6682) + + + BUGTRAQ + 20010608 WatchGuard SMTP Proxy issue + + SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes. + + + + + + + + + + cpe:/a:webtrends:webtrends_enterprise_reporting_server_nt:3.5 + cpe:/a:webtrends:webtrends_enterprise_reporting_server:3.1c + + CVE-2001-0693 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + webtrends-unicode-reveal-source(6639) + + + BID + 2812 + + + BUGTRAQ + 20010603 Webtrends HTTP Server %20 bug + + WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:3.00_r5 + + CVE-2001-0694 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.443-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + VULN-DEV + 20010525 WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS + + Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command. + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:3.00_r5 + + CVE-2001-0695 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.583-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wftpd-cd-dos(6496) + + + BUGTRAQ + 20010503 Potential DOS Vulnerability in WFTPD + + WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\). + + + + + + + + + + cpe:/a:netwin:surgeftp:1.0b + cpe:/a:netwin:surgeftp:2.0a + + CVE-2001-0696 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.723-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + surgeftp-concon-dos(6712) + + + BID + 2891 + + + BUGTRAQ + 20010619 SurgeFTP vulnerabilities + + + MISC + http://netwinsite.com/surgeftp/manual/updates.htm + + NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. + + + + + + + + + cpe:/a:netwin:surgeftp:1.1h + + CVE-2001-0697 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:42.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + surgeftp-listing-dos(6168) + + + BUGTRAQ + 20010228 SurgeFTP Denial of Service + + + WIN2KSEC + 20010301 SurgeFTP 1.0b Denial of Service + + + CONFIRM + http://netwinsite.com/surgeftp/manual/updates.htm + + + BID + 2442 + + NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. + + + + + + + + + + cpe:/a:netwin:surgeftp:1.0b + cpe:/a:netwin:surgeftp:2.0a + + CVE-2001-0698 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + surgeftp-nlist-directory-traversal(6711) + + + BID + 2892 + + + BUGTRAQ + 20010619 SurgeFTP vulnerabilities + + + CONFIRM + http://www.netwinsite.com/surgeftp/manual/updates.htm + + Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. + + + + + + + + + cpe:/o:sun:solaris:5.8 + + CVE-2001-0699 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.160-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sun-cbreset-bo(6726) + + + BID + 2893 + + + BUGTRAQ + 20010620 Solaris /opt/SUNWssp/bin/cb_reset Vulnerability + + Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument. + + + + + + + + + + + + + + + + + cpe:/a:w3m:w3m:0.2.1 + cpe:/a:w3m:w3m:0.1.6 + cpe:/a:w3m:w3m:0.1.7 + cpe:/a:w3m:w3m:0.1.8 + cpe:/a:w3m:w3m:0.1.3 + cpe:/a:w3m:w3m:0.1.4 + cpe:/a:w3m:w3m:0.1.10 + cpe:/a:w3m:w3m:0.2 + cpe:/a:w3m:w3m:0.1.9 + + CVE-2001-0700 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + w3m-mime-header-bo(6725) + + + BID + 2895 + + + CONFIRM + http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html + + + BUGTRAQ + 20010621 [SNS Advisory No.32] w3m malformed MIME header Buffer Overflow Vulnerability + + + DEBIAN + DSA-081 + + + DEBIAN + DSA-064 + + + CONECTIVA + CLA-2001:434 + + Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. + + + + + + + + + + + + cpe:/a:sun:sunvts:4.2 + cpe:/a:sun:sunvts:4.1 + cpe:/a:sun:sunvts:4.3 + cpe:/a:sun:sunvts:4.0 + + CVE-2001-0701 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.473-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sunvts-ptexec-bo(6736) + + + BID + 2898 + + + BUGTRAQ + 20010621 Solaris /opt/SUNWvts/bin/ptexec Vulnerability + + Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument. + + + + + + + + + + + + + + + cpe:/a:grant_averett:ceberus_ftp_server:1.0 + cpe:/a:grant_averett:ceberus_ftp_server:1.01 + cpe:/a:grant_averett:ceberus_ftp_server:1.5 + cpe:/a:grant_averett:ceberus_ftp_server:1.2 + cpe:/a:grant_averett:ceberus_ftp_server:1.1 + cpe:/a:grant_averett:ceberus_ftp_server:1.3 + cpe:/a:grant_averett:ceberus_ftp_server:1.22 + + CVE-2001-0702 + 2001-09-20T00:00:00.000-04:00 + 2008-09-10T15:08:40.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cerberus-ftp-bo(6728) + + + BID + 2901 + + + BUGTRAQ + 20010621 Cerberus FTP Server 1.x Remote DoS attack Vulnerability + + + BUGTRAQ + 20010704 CesarFTPd, Cerberus FTPd + + Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command. + + + + + + + + + cpe:/a:arcadia:arcadia_internet_store:1.0 + + CVE-2001-0703 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2905 + + + XF + arcadia-tradecli-dos(6739) + + + BUGTRAQ + 20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities. + + tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter. + + + + + + + + + cpe:/a:arcadia:arcadia_internet_store:1.0 + + CVE-2001-0704 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:43.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2904 + + + XF + arcadia-tradecli-reveal-path(6738) + + + BUGTRAQ + 20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities. + + tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist. + + + + + + + + + cpe:/a:arcadia:arcadia_internet_store:1.0 + + CVE-2001-0705 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2902 + + + XF + arcadia-tradecli-directory-traversal(6737) + + + BUGTRAQ + 20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities. + + Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument. + + + + + + + + + + + + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.4 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.5 + cpe:/a:maxum_development_corporation:rumpus_ftp_server:2.0.3dev + cpe:/a:maxum_development_corporation:rumpus_ftp_server:1.3.2 + + CVE-2001-0706 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.207-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rumpus-ftp-directory-dos(6699) + + + BID + 2864 + + + BUGTRAQ + 20010612 Rumpus FTP DoS vol. 2 + + Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders. + + + + + + + + + cpe:/a:denicomp:rshd:2.18 + + CVE-2001-0707 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.380-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + denicomp-rshd-dos(6523) + + + BUGTRAQ + 20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability + + Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514. + + + + + + + + + cpe:/a:denicomp:rexecd:1.05 + + CVE-2001-0708 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.567-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + denicomp-rexecd-dos(6524) + + + BUGTRAQ + 20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability + + Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string. + + + + + + + + + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-0709 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.707-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-unicode-asp-disclosure(6742) + + + BID + 2909 + + + BUGTRAQ + 20010622 [VIGILANTE-2001001] ASP source code retrieved with Unicode extens ion + + Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:netbsd:netbsd:1.5 + + CVE-2001-0710 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:24:44.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-ip-fragments-dos(6636) + + + BID + 2799 + + + NETBSD + NetBSD-SA2001-006 + + + FREEBSD + FreeBSD-SA-01:52 + + NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool. + + + + + + + + + + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11 + + CVE-2001-0711 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:24:44.990-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010207 Cisco IOS Software SNMP Read-Write ILMI Community String Vulnerability + + + XF + cisco-ios-modify-snmp(6169) + + Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.0.1 + + CVE-2001-0712 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:45.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010729 Re: TXT or HTML? -- IE NEW BUG + + + BUGTRAQ + 20010727 TXT or HTML? -- IE NEW BUG + + + BID + 3116 + + The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc. + + + + + + + + + cpe:/a:sendmail:sendmail:8.12.1 + + CVE-2001-0713 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:45.287-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BINDVIEW + 20011001 Multiple Local Sendmail Vulnerabilities + + + BID + 3377 + + + XF + sendmail-setregid-gain-privileges(7192) + + Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function. + + + + + + + + + cpe:/a:sendmail:sendmail:8.12.1 + + CVE-2001-0714 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:45.427-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BINDVIEW + 20011001 Multiple Local Sendmail Vulnerabilities + + + SGI + 20011101-01-I + + Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option. + + + + + + + + + cpe:/a:sendmail:sendmail:8.12.1 + + CVE-2001-0715 + 2001-10-30T00:00:00.000-05:00 + 2011-03-07T21:05:40.750-05:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BINDVIEW + 20011001 Multiple Local Sendmail Vulnerabilities + + + SGI + 20011101-01-I + + Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode. + + + + + + + + + + + cpe:/a:citrix:metaframe:xp_server_service_pack_1 + cpe:/a:citrix:metaframe:xp_server + cpe:/a:citrix:metaframe:1.8:sp3 + + CVE-2001-0716 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:45.723-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ISS + 20011016 Citrix MetaFrame Remote Denial of Service Vulnerability + + + XF + metaframe-multiple-sessions-dos(7068) + + + BID + 3440 + + Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server. + + + + + + + + + cpe:/a:tooltalk:tooltalk_database_server + + CVE-2001-0717 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:45.880-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2001-27 + + + ISS + 20011002 Multi-Vendor Format String Vulnerability in ToolTalk Service + + + XF + tooltalk-ttdbserverd-format-string(7069) + + + BID + 3382 + + + CIAC + M-002 + + + SUN + 00212 + + + SECTRACK + 1002479 + + + HP + HPSBUX0110-168 + + + COMPAQ + SSRT0767U + + + CALDERA + CSSA-2001-SCO.28 + + Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. + + + + + + + + + + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:powerpoint:2002 + + CVE-2001-0718 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:46.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2001-28 + + + CERT-VN + VU#287067 + + + MS + MS01-050 + + + XF + ms-malformed-document-macro(7223) + + + BID + 3402 + + + BUGTRAQ + 20011005 Symantec Security Response SecBul-10042001, Revision1, Malformed Microsoft Excel or PowerPoint documents bypass Microsoft macro security features + + Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document. + + + + + + + + + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2001-0719 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:46.160-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + MS + MS01-056 + + + BID + 3156 + + + OSVDB + 5558 + + + XF + mediaplayer-asf-marker-bo(6962) + + + BUGTRAQ + 20010807 MS Windows Media Player ASF Marker Buffer Overflow + + + + + Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file. + + + + + + + + + cpe:/o:apple:mac_os_x:10.4.9 + + CVE-2001-0720 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:46.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-053 + + + XF + ie-mac-downloaded-file-execution(7336) + + + BID + 3471 + + + CIAC + M-013 + + Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled. + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_me + + CVE-2001-0721 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:46.457-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-054 + + + BUGTRAQ + 20011109 Important Information Regarding MS01-054 and WindowsME + + + BUGTRAQ + 20011101 Three Windows XP UPNP DOS attacks + + Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0722 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:46.597-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011019 Minor IE vulnerability: about: URLs + + + MS + MS01-055 + + + BUGTRAQ + 20011108 Microsoft IE cookies readable via about: URLS + + + XF + ie-about-cookie-information(7486) + + + BID + 3513 + + + OSVDB + 1982 + + + CIAC + M-016 + + Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability." + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0723 + 2001-11-14T00:00:00.000-05:00 + 2008-09-05T16:24:46.753-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3546 + + + MS + MS01-055 + + Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0724 + 2001-11-14T00:00:00.000-05:00 + 2008-09-05T16:24:46.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS01-055 + + + XF + ie-incorrect-security-zone-variant(8471) + + + OSVDB + 5556 + + Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664. + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5 + + CVE-2001-0726 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:47.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS01-057 + + + XF + exchange-owa-embedded-script-execution(7663) + + + BID + 3650 + + + OSVDB + 5557 + + Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0727 + 2001-12-14T00:00:00.000-05:00 + 2008-09-05T16:24:47.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT + CA-2001-36 + + + CERT-VN + VU#443699 + + + MS + MS01-058 + + + BUGTRAQ + 20011214 MSIE may download and run progams automatically + + + BUGTRAQ + 20011216 Re: MSIE may download and run progams automatically - NOT SO FAST + + + XF + ie-file-download-execution(7703) + + + BID + 3578 + + + OSVDB + 3033 + + + CIAC + M-027 + + + + + Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability." + + + + + + + + + cpe:/a:compaq:management_agents:5.2 + + CVE-2001-0728 + 2001-10-30T00:00:00.000-05:00 + 2008-09-05T16:24:47.333-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#275979 + + + COMPAQ + SSRT0758 + + + XF + compaq-wbm-bo(7189) + + + BID + 3376 + + Buffer overflow in Compaq Management Agents before 5.2, included in Compaq Web-enabled Management Software, allows local users to gain privileges. + + + + + + + + + cpe:/a:apache:http_server:1.3.20 + + CVE-2001-0729 + 2001-10-30T00:00:00.000-05:00 + 2012-10-22T21:11:50.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html + + + CONFIRM + http://www.apacheweek.com/issues/01-09-28#security + + + BID + 22083 + + + SECTRACK + 1017522 + + Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. + + + + + + + + + cpe:/a:apache:http_server:1.3.20 + + CVE-2001-0730 + 2001-10-30T00:00:00.000-05:00 + 2008-09-10T15:08:43.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.apacheweek.com/issues/01-09-28#security + + + XF + apache-log-file-overwrite(7419) + + + REDHAT + RHSA-2001:164 + + + REDHAT + RHSA-2001:126 + + + ENGARDE + ESA-20011019-01 + + + MANDRAKE + MDKSA-2001:077 + + + CONECTIVA + CLA-2001:430 + + split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header. + + + + + + + + + cpe:/a:apache:http_server:1.3.20 + + CVE-2001-0731 + 2001-10-01T00:00:00.000-04:00 + 2008-09-05T16:24:47.770-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CONFIRM + http://www.apacheweek.com/issues/01-10-05#security + + + XF + apache-multiviews-directory-listing(8275) + + + BID + 3009 + + + BUGTRAQ + 20010709 How Google indexed a file with no external link + + + REDHAT + RHSA-2001:164 + + + REDHAT + RHSA-2001:126 + + + MANDRAKE + MDKSA-2001:077 + + + SGI + 20020301-01-P + + Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ralf_s._engelschall:eperl:2.2.2 + cpe:/a:ralf_s._engelschall:eperl:2.2.3 + cpe:/a:ralf_s._engelschall:eperl:2.0.3 + cpe:/a:ralf_s._engelschall:eperl:2.0.2 + cpe:/a:ralf_s._engelschall:eperl:2.2.1 + cpe:/a:ralf_s._engelschall:eperl:2.0.1 + cpe:/a:ralf_s._engelschall:eperl:2.2.8 + cpe:/a:ralf_s._engelschall:eperl:2.2.9 + cpe:/a:ralf_s._engelschall:eperl:2.2.10 + cpe:/a:ralf_s._engelschall:eperl:2.2.6 + cpe:/a:ralf_s._engelschall:eperl:2.0 + cpe:/a:ralf_s._engelschall:eperl:2.2.11 + cpe:/a:ralf_s._engelschall:eperl:2.2.7 + cpe:/a:ralf_s._engelschall:eperl:2.1 + cpe:/a:ralf_s._engelschall:eperl:2.2.12 + cpe:/a:ralf_s._engelschall:eperl:2.2.4 + cpe:/a:ralf_s._engelschall:eperl:2.2.13 + cpe:/a:ralf_s._engelschall:eperl:2.1.2 + cpe:/a:ralf_s._engelschall:eperl:2.2 + cpe:/a:ralf_s._engelschall:eperl:2.2.14 + cpe:/a:ralf_s._engelschall:eperl:2.2.5 + cpe:/a:ralf_s._engelschall:eperl:2.1.1 + + CVE-2001-0733 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:47.910-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eperl-embedded-code-execution(6743) + + + BUGTRAQ + 20010621 bugtraq submission + + + BID + 2912 + + The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code. + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1::sh3 + cpe:/o:netbsd:netbsd:1.5::sh3 + + CVE-2001-0734 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.113-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-sh3-sigreturn-privileges(6637) + + + BID + 2810 + + + NETBSD + NetBSD-SA2001-008 + + Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine. + + + + + + + + + + + cpe:/a:infodrom:cfingerd:1.4.3 + cpe:/a:infodrom:cfingerd:1.4.1 + cpe:/a:infodrom:cfingerd:1.4.2 + + CVE-2001-0735 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.253-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cfingerd-util-bo(6744) + + + BID + 2914 + + + BUGTRAQ + 20010621 cfingerd local vulnerability (possibly root) + + + DEBIAN + DSA-066 + + + BUGTRAQ + 20010711 Another exploit for cfingerd <= 1.4.3-8 + + Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:immunix:immunix:7.0 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/o:engardelinux:secure_linux:1.0.1 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/a:university_of_washington:pine:4.33 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0736 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.410-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pine-tmp-file-symlink(6367) + + + REDHAT + RHSA-2001:042 + + + MANDRAKE + MDKSA-2001:047 + + + BUGTRAQ + 20010527 [ESA-20010509-01] pine temporary file handling vulnerabilities + + + BUGTRAQ + 20010416 Immunix OS Security update for pine + + Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/h:logitech:cordless_freedom_pro + cpe:/h:logitech:cordless_freedom_navigator + cpe:/h:logitech:cordless_itouch_keyboard + cpe:/h:logitech:cordless_freedom + + CVE-2001-0737 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.583-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + logitech-wireless-unauthorized-access(6562) + + + BID + 2738 + + + BUGTRAQ + 20010522 Logitech vulnerability (DoS, man-in-the-middle-attack) - Resend + + + BUGTRAQ + 20010516 logitech wireless devices: man-in-the-middle attack + + A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack. + + + + + + + + + + + + + + + + + cpe:/a:immunix:immunix:7.0 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:1.3 + + CVE-2001-0738 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#249579 + + + BUGTRAQ + 20010614 sysklogd update -- Immunix OS 6.2, 7.0-beta, 7.0 + + + XF + klogd-null-byte-dos(7098) + + + IMMUNIX + IMNX-2001-70-026-01 + + LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages. + + + + + + + + + cpe:/o:engardelinux:secure_linux:1.0.1 + + CVE-2001-0739 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:48.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ENGARDE + ESA-20010529-02 + + + XF + linux-webtool-inherit-privileges(7404) + + + REDHAT + RHSA-2001:126 + + Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges. + + + + + + + + + + cpe:/h:3com:3cp4144:1.1.9 + cpe:/h:3com:3c840-us:1.1.9 + + CVE-2001-0740 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.037-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + 3com-officeconnect-http-dos(6573) + + + BID + 2721 + + + BUGTRAQ + 20010924 Regarding: 3Com OfficeConnect 812/840 Router DoS exploit code + + + BUGTRAQ + 20010515 3COM OfficeConnect DSL router vulneratibilities + + + BUGTRAQ + 20010921 3Com OfficeConnect 812/840 Router DoS exploit code + + 3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability. + + + + + + + + + cpe:/a:cisco:hsrp + + CVE-2001-0741 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.190-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-hsrp-dos(6497) + + + BID + 2684 + + + MISC + http://www.cisco.com/networkers/nw00/pres/2402.pdf + + + BUGTRAQ + 20010503 Cisco HSRP Weakness/DoS + + Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets. + + + + + + + + + cpe:/a:computalynx:cmail:2.4.9 + + CVE-2001-0742 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.333-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/5UP0B204AY.html + + Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command. + + + + + + + + + cpe:/a:oreilly:webboard:4.10.30 + + CVE-2001-0743 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.473-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2814 + + + BUGTRAQ + 20010602 O'Reilly WebBoard 4.10.30 JavaScript code execution problem + + Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands. + + + + + + + + + + + + + + cpe:/a:horde:imp:2.2.1 + cpe:/a:horde:imp:2.0 + cpe:/a:horde:imp:2.2.3 + cpe:/a:horde:imp:2.2 + cpe:/a:horde:imp:2.2.2 + cpe:/a:horde:imp:2.2.4 + + CVE-2001-0744 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:08:44.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.horde.org/imp/2.2/news.php + + + BUGTRAQ + 20010531 Imp-2.2.4 temporary files + + + CALDERA + CSSA-2001-025.0 + + Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:netscape:messanger:4.7x + + CVE-2001-0745 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010605 SECURITY.NNOV: Netscape 4.7x Messanger user information retrival + + + XF + netscape-user-info-retrieval(7417) + + + OSVDB + 5543 + + Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property. + + + + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1_sp3 + cpe:/a:iplanet:iplanet_web_server:4.1_sp6 + cpe:/a:iplanet:iplanet_web_server:4.1_sp7 + cpe:/a:iplanet:iplanet_web_server:4.1_sp4 + cpe:/a:iplanet:iplanet_web_server:4.1_sp5 + + CVE-2001-0746 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:49.927-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + netscape-enterprise-uri-bo(6554) + + + BID + 2732 + + + CONFIRM + http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html + + + BUGTRAQ + 20010515 iPlanet - Netscape Enterprise Web Publisher Buffer Overflow + + Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1 + + CVE-2001-0747 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:50.083-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html + + + BUGTRAQ + 20010518 Netscape Enterprise Server 4 Method and URI overflow + + Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request. + + + + + + + + + cpe:/a:acme_labs:acme%2cserver:1.7 + + CVE-2001-0748 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:50.223-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010531 Acme.Server v1.7 of 13nov96 Directory Browsing + + + BID + 2809 + + + OSVDB + 5544 + + + XF + acme-serve-directory-traversal(6634) + + + CISCO + 20020702 Cisco Secure ACS Unix Acme.server Information Disclosure Vulnerability + + Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_embedded-webserver + + CVE-2001-0749 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:24:50.380-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010524 IPC@Chip Security + + + XF + ipcchip-web-root-system(8922) + + + BID + 2775 + + Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root. + + + + + + + + + + cpe:/o:cisco:ios:12.1%283%29t + cpe:/o:cisco:ios:12.1%282%29t + + CVE-2001-0750 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:50.520-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-ios-tcp-dos(6589) + + + CISCO + 20010524 IOS Reload after Scanning Vulnerability + + + BID + 2804 + + + OSVDB + 800 + + + + + Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999. + + + + + + + + + cpe:/o:cisco:cbos:2.3.8 + + CVE-2001-0751 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:50.660-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010522 More Multiple Vulnerabilities in CBOS + + + XF + tcp-seq-predict(139) + + Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections. + + + + + + + + + cpe:/o:cisco:cbos:2.3.8 + + CVE-2001-0752 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:50.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010522 More Multiple Vulnerabilities in CBOS + + + XF + cisco-cbos-record-dos(7298) + + + OSVDB + 5573 + + Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set. + + + + + + + + + cpe:/o:cisco:cbos:2.3.8 + + CVE-2001-0753 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:08:45.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010522 More Multiple Vulnerabilities in CBOS + + + XF + cisco-cbos-execenable-info-disclosure(44544) + + Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges. + + + + + + + + + cpe:/o:cisco:cbos:2.3.8 + + CVE-2001-0754 + 2001-10-18T00:00:00.000-04:00 + 2013-09-08T00:12:05.530-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20010522 More Multiple Vulnerabilities in CBOS + + + XF + cisco-cbos-multiple-echo(7299) + + Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets. + + + + + + + + + cpe:/o:debian:debian_linux:6.2 + + CVE-2001-0755 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010518 Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability + + Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command. + + + + + + + + + cpe:/a:virtualcart:virtualcatalog + + CVE-2001-0756 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.380-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010607 cgisecurity.com Advisory #5 + + + BUGTRAQ + 20010611 re: Advisory #5 Corrections. + + CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter. + + + + + + + + + cpe:/h:cisco:6400_nrp_2:12.1dc + + CVE-2001-0757 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.520-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#516659 + + + BID + 2874 + + + CISCO + 20010614 Cisco 6400 NRP2 Telnet Vulnerability + + + XF + cisco-nrp2-telnet-access(6691) + + + OSVDB + 804 + + + CIAC + L-097 + + + + + Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet. + + + + + + + + + cpe:/a:evolvable_corporation:shambala_server:4.5 + + CVE-2001-0758 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.660-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.securiteam.com/windowsntfocus/5SP011P4KC.html + + Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. + + + + + + + + + + + cpe:/a:jetico:bestcrypt:0.6 + cpe:/a:jetico:bestcrypt:0.7 + cpe:/a:jetico:bestcrypt:0.8.1 + + CVE-2001-0759 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.817-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2875 + + + BUGTRAQ + 20010614 Buffer overflow in BestCrypt for Linux + + Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathname, which is processed during an unmount. + + + + + + + + + cpe:/a:citrix:nfuse:1.51 + + CVE-2001-0760 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:51.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2956 + + + BUGTRAQ + 20010702 Re: Nfuse reveals full path + + + BUGTRAQ + 20010630 Nfuse reveals full path + + + XF + citrix-nfuse-path-disclosure(6786) + + Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. + + + + + + + + + cpe:/a:trend_micro:interscan_webmanager:1.2 + + CVE-2001-0761 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:52.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2959 + + + BUGTRAQ + 20010702 [SNS Advisory No.36] TrendMicro InterScan WebManager Version 1.2 HttpSave.dll Buffer Overflow Vulnerability + + Buffer overflow in HttpSave.dll in Trend Micro InterScan WebManager 1.2 allows remote attackers to execute arbitrary code via a long value to a certain parameter. + + + + + + + + + cpe:/a:su-wrapper:su-wrapper:1.1.1 + + CVE-2001-0762 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:52.237-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010602 su-wrapper 1.1.1 Local root exploit. + + Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument. + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.1.8.8.p3-1.1 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:6.1 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.0 + + CVE-2001-0763 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:08:47.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-063 + + + BUGTRAQ + 20010608 potential buffer overflow in xinetd-2.1.8.9pre11-1 + + + XF + xinetd-identd-bo(6670) + + + BID + 2840 + + + REDHAT + RHSA-2001:075 + + + ENGARDE + ESA-20010621-01 + + + CIAC + L-104 + + + IMMUNIX + IMNX-2001-70-024-01 + + + CONECTIVA + CLA-2001:404 + + Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function. + + + + + + + + + + + + cpe:/a:juergen_schoenwaelder:scotty:2.1.7 + cpe:/a:juergen_schoenwaelder:scotty:2.1.9 + cpe:/a:juergen_schoenwaelder:scotty:2.1.8 + cpe:/a:juergen_schoenwaelder:scotty:2.1.10 + + CVE-2001-0764 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:08:47.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + scotty-ntping-bo(6735) + + + BID + 2911 + + + BUGTRAQ + 20010621 suid scotty (ntping) overflow (fwd) + + + SUSE + SuSE-SA:2001:023 + + + VULN-DEV + 20010615 Re: suid scotty (ntping) overflow (fwd) + + + VULN-DEV + 20010609 suid scotty / ntping overflow + + Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument. + + + + + + + + + cpe:/a:bisonware:bison_ftp_server:v4r1 + + CVE-2001-0765 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:52.707-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2963 + + + CONFIRM + http://www.bisonftp.com/ServRev.htm + + + BUGTRAQ + 20010702 BisonFTP Server V4R1 *.bdl upload Directory Traversal + + + XF + bisonftp-bdl-directory-traversal(6782) + + + OSVDB + 1888 + + BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories. + + + + + + + + + cpe:/a:apache:http_server:1.3.14 + + CVE-2001-0766 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:52.847-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2852 + + + BUGTRAQ + 20010610 Mac OS X - Apache & Case Insensitive Filesystems + + Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. + + + + + + + + + cpe:/a:steve_poulsen:guildftpd:0.9.7 + + CVE-2001-0767 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:52.987-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.nitrolic.com/ + + + BID + 2789 + + + BUGTRAQ + 20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption + + Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET. + + + + + + + + + cpe:/a:steve_poulsen:guildftpd:0.9.7 + + CVE-2001-0768 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.130-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + guildftpd-usr-plaintext-passwords(6611) + + + BID + 2792 + + + BUGTRAQ + 20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption + + GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file. + + + + + + + + + cpe:/a:steve_poulsen:guildftpd:0.97 + + CVE-2001-0769 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.270-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + guildftpd-null-memory-leak(6613) + + + BUGTRAQ + 20010527 def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS + + Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character. + + + + + + + + + cpe:/a:steve_poulsen:guildftpd:0.97 + + CVE-2001-0770 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.410-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + guildftpd-site-bo(6612) + + + CONFIRM + http://www.nitrolic.com/help/history.htm + + + BUGTRAQ + 20010527 def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS + + Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command. + + + + + + + + + cpe:/a:spytech:spyanywhere:1.50 + + CVE-2001-0771 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + spyanywhere-weak-authentication(6578) + + + BID + 2755 + + + BUGTRAQ + 20010521 SpyAnywhere Authentication Bypassing Vulnerabilities + + Spytech SpyAnywhere 1.50 allows remote attackers to gain administrator access via a a single character in the "loginpass" field. + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-0772 + 2001-10-18T00:00:00.000-04:00 + 2009-03-04T00:08:30.610-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + hpux-cde-bo(6585) + + + HP + HPSBUX0105-151 + + + + + Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges. + + + + + + + + + cpe:/h:cayman:3220-h_dsl_router:1.0 + + CVE-2001-0773 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#312761 + + + BID + 3001 + + + BUGTRAQ + 20010709 Cayman-DSL Model 3220-H DOS with nmap + + + XF + cayman-dsl-portscan-dos(6825) + + Cayman 3220-H DSL Router 1.0 allows remote attacker to cause a denial of service (crash) via a series of SYN or TCP connect requests. + + + + + + + + + + + cpe:/a:tripwire:tripwire:2.3.0 + cpe:/a:tripwire:tripwire:1.3.1 + cpe:/a:tripwire:tripwire:2.2.1 + + CVE-2001-0774 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:53.987-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#349019 + + + BID + 3003 + + + BUGTRAQ + 20010709 Tripwire temporary files + + + XF + tripwire-tmpfile-symlink(6820) + + + OSVDB + 1895 + + + MANDRAKE + MDKSA-2001:064 + + Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files. + + + + + + + + + + + cpe:/a:xloadimage:xloadimage:4.1 + cpe:/a:xli:xli:1.17 + cpe:/a:xli:xli:1.16 + + CVE-2001-0775 + 2001-10-18T00:00:00.000-04:00 + 2013-07-27T00:13:13.887-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3006 + + + BUGTRAQ + 20010710 xloadimage remote exploit - tstot.c + + + REDHAT + RHSA-2001:088 + + + SUSE + SA:2001:024 + + + XF + xloadimage-faces-bo(6821) + + + GENTOO + GLSA-200503-05 + + + DEBIAN + DSA-695 + + + DEBIAN + DSA-069 + + Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attacker to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field. + + + + + + + + + cpe:/a:dynfx:dynfx_mailserver:2.10 + + CVE-2001-0776 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:54.300-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dynfx-mailserver-pop3-bo(6615) + + + BID + 2781 + + + BUGTRAQ + 20010526 DynFX POPd Denial of Service Vulnerability + + Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service. + + + + + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.0.8 + cpe:/a:omnicron:omnihttpd:2.0.5 + cpe:/a:omnicron:omnihttpd:2.0.4 + cpe:/a:omnicron:omnihttpd:2.0.7 + cpe:/a:omnicron:omnihttpd:2.0.6 + + CVE-2001-0777 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:54.440-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + omnihttpd-php-request-dos(6620) + + + BID + 2783 + + + BUGTRAQ + 20010526 Remote vulnerabilities in OmniHTTPd + + Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts. + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.0.8 + + CVE-2001-0778 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:54.660-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + omnihttpd-reveal-source-code(6621) + + + CONFIRM + http://www.omnicron.ca/httpd/docs/release.html + + + BUGTRAQ + 20010525 Remote vulnerabilities in OmniHTTPd + + OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-0779 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:54.800-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT-VN + VU#327281 + + + XF + solaris-yppasswd-bo(6629) + + + BID + 2763 + + + BUGTRAQ + 20011004 Patches for Solaris rpc.yppasswdd available + + + BUGTRAQ + 20010528 solaris 2.6, 7 yppasswd vulnerability + + + CIAC + M-008 + + + SUN + 00209 + + + + + + + + Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username. + + + + + + + + + cpe:/a:cosmicperl:directory_pro:2.0 + + CVE-2001-0780 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:54.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2793 + + + BUGTRAQ + 20010527 directorypro.cgi , directory traversal + + Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attacker to gain sensitive information via a .. (dot dot) in the SHOW parameter. + + + + + + + + + cpe:/a:pi-soft:spoonftp:1.0.0.12 + + CVE-2001-0781 + 2001-05-30T00:00:00.000-04:00 + 2008-09-05T16:24:55.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + spoonftp-cwd-list-bo(6630) + + + BUGTRAQ + 20010530 SpoonFTP Buffer Overflow Vulnerabilities + + Buffer overflow in SpoonFTP 1.0.0.12 allows remote attacker to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST. + + + + + + + + + cpe:/a:kde:ktv:0.1.1.271 + + CVE-2001-0782 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.253-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ktvision-symlink(6741) + + + BUGTRAQ + 20010622 Symlinks symlinks...this time KTVision + + KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file. + + + + + + + + + cpe:/a:cisco:tftp_server:1.1 + + CVE-2001-0783 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.393-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010618 Cisco TFTPD 1.1 Vulerablity + + + BID + 2886 + + + XF + cisco-tftp-directory-traversal(6722) + + + MISC + http://www.sentry-labs.com/files/cisco0201061701.txt + + Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. + + + + + + + + + + + cpe:/a:icecast:icecast:1.3.8_beta2 + cpe:/a:icecast:icecast:1.310::linux + cpe:/a:icecast:icecast:1.3.7 + + CVE-2001-0784 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.537-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2932 + + + BUGTRAQ + 20010626 Advisory + + + XF + icecast-dot-directory-traversal(6752) + + + REDHAT + RHSA-2002:063 + + + REDHAT + RHSA-2001:105 + + + OSVDB + 1883 + + + DEBIAN + DSA-089 + + Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack using encoded URL characters. + + + + + + + + + cpe:/a:internet_software_solutions:air_messenger_lan_server:3.4.2 + + CVE-2001-0785 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.690-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2883 + + + BUGTRAQ + 20010618 Multiple Vulnerabilities In AMLServer + + Directory traversal in Webpaging interface in Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows allows remote attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:internet_software_solutions:air_messenger_lan_server:3.4.2 + + CVE-2001-0786 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.833-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2882 + + + BUGTRAQ + 20010618 Multiple Vulnerabilities In AMLServer + + Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 stores user passwords in plaintext in the pUser.Dat file. + + + + + + + + + + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0787 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:55.987-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:077 + + + XF + lprng-supplementary-groups(6703) + + + BID + 2865 + + + CIAC + L-096 + + LPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, which could allow a local user to elevate privileges. + + + + + + + + + cpe:/a:internet_software_solutions:air_messenger_lan_server:3.4.2 + + CVE-2001-0788 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:56.130-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2881 + + + BUGTRAQ + 20010618 Multiple Vulnerabilities In AMLServer + + Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header. + + + + + + + + + cpe:/a:kaspersky_lab:kaspersky_anti-virus:3.5.132.2::sendmail + + CVE-2001-0789 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:56.270-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010621 SECURITY.NNOV: KAV (AVP) for sendmail format string vulnerability + + Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attacker to cause a denial of service or possibly execute arbitrary code via a malformed mail message. + + + + + + + + + + cpe:/a:specter:specter_ids:5.0 + cpe:/a:specter:specter_ids:4.5 + + CVE-2001-0790 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:56.410-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + WIN2KSEC + 20010527 + + Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall + + CVE-2001-0791 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:56.567-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010531 [SNS Advisory No.28]InterScan VirusWall for NT remote configuration + + Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access. + + + + + + + + + cpe:/a:xchat:xchat:1.2.x + + CVE-2001-0792 + 2001-10-18T00:00:00.000-04:00 + 2011-03-07T21:05:48.970-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/exploits/5AP0Q2A4AQ.html + + + XF + xchat-nickname-format-string(7416) + + Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname. + + + + + + + + + cpe:/a:a-ftp:anonymous_ftp_server + + CVE-2001-0794 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:56.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010621 A-FTP Anonymous FTP Server Remote DoS attack Vulnerability + + Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command. + + + + + + + + + cpe:/a:perception:liteserve:1.25 + + CVE-2001-0795 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:24:57.003-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2926 + + + BUGTRAQ + 20010625 Perception LiteServe MS-DOS filename vulnerability + + Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names. + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12f + cpe:/o:freebsd:freebsd:3.0 + + CVE-2001-0796 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:57.143-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20011001-01-P + + + CONFIRM + http://www.freebsd.org/cgi/query-pr.cgi?pr=8990 + + + XF + irix-igmp-dos(7332) + + + BID + 3463 + + SGI IRIX 6.5 through 6.5.12f and possibly earlier versions, and FreeBSD 3.0, allows remote attackers to cause a denial of service via a malformed IGMP multicast packet with a small response delay. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:hp:hp-ux:10.00 + cpe:/o:ibm:aix:4.3 + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:solaris:8.0 + cpe:/o:sco:openserver:5.0.6a + cpe:/o:sgi:irix:3.2 + cpe:/o:sgi:irix:3.3 + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.2 + cpe:/o:sco:openserver:5.0.6 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:sco:openserver:5.0.3 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sgi:irix:3.3.3 + cpe:/o:sco:openserver:5.0.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sgi:irix:3.3.2 + cpe:/o:ibm:aix:5.1 + cpe:/o:sgi:irix:3.3.1 + cpe:/o:hp:hp-ux:11.0.4 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sco:openserver:5.0 + + CVE-2001-0797 + 2001-12-12T00:00:00.000-05:00 + 2008-09-05T16:24:57.300-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT + CA-2001-34 + + + CERT-VN + VU#569272 + + + XF + telnet-tab-bo(7284) + + + ISS + 20011212 Buffer Overflow in /bin/login + + + BID + 3681 + + + BUGTRAQ + 20011219 Linux distributions and /bin/login overflow + + + AIXAPAR + IY26221 + + + SUN + 00213 + + + BUGTRAQ + 20011214 Sun Solaris login bug patches out + + + CALDERA + CSSA-2001-SCO.40 + + + SGI + 20011201-01-I + + + + + Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin. + + + + + + + + + cpe:/o:sgi:irix:6.5.13f + + CVE-2001-0799 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:57.550-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20011003-02-P + + + MISC + http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2 + + + XF + irix-lpsched-bo(7641) + + + OSVDB + 8572 + + Buffer overflows in lpsched in IRIX 6.5.13f and earlier allow remote attackers to execute arbitrary commands via a long argument. + + + + + + + + + cpe:/o:sgi:irix:6.5.13f + + CVE-2001-0800 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:57.690-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20011003-02-P + + + MISC + http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2 + + + BID + 27566 + + lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + cpe:/o:sgi:irix:6.5.13f + + CVE-2001-0801 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:57.833-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20011003-02-P + + + XF + irix-lpstat-net-type-library(7639) + + + MISC + http://www.lsd-pl.net/files/get?IRIX/irx_lpstat2 + + lpstat in IRIX 6.5.13f and earlier allows local users to gain root privileges by specifying a Trojan Horse nettype shared library. + + + + + + + + + + + + + + cpe:/a:open_group:cde_common_desktop_environment:1.0.1 + cpe:/a:open_group:cde_common_desktop_environment:1.1 + cpe:/a:open_group:cde_common_desktop_environment:1.2 + cpe:/a:open_group:cde_common_desktop_environment:2.0 + cpe:/a:open_group:cde_common_desktop_environment:2.1 + cpe:/a:open_group:cde_common_desktop_environment:1.0.2 + + CVE-2001-0803 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + CERT-VN + VU#172583 + + + CERT + CA-2002-01 + + + CERT + CA-2001-31 + + + BID + 3517 + + + HP + HPSBUX0111-175 + + + XF + cde-dtspcd-bo(7396) + + + ISS + 20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service + + + SUN + 00214 + + + COMPAQ + SSRT541 + + + CALDERA + CSSA-2001-SCO.30 + + + SGI + 20011107-01-P + + + + + + + + Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. + + + + + + + + + cpe:/a:valerie_mates:interactive_story:1.3 + + CVE-2001-0804 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:58.127-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + interactive-story-next-directory-traversal(6843) + + + CONFIRM + http://www.valeriemates.com/story_download.html + + + BID + 3028 + + + BUGTRAQ + 20010715 Interactive Story File Disclosure Vulnerability + + + OSVDB + 683 + + Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot) attack on the "next" parameter. + + + + + + + + + + cpe:/a:tarantella:tarantella_enterprise:3.01 + cpe:/a:tarantella:tarantella_enterprise:3.0 + + CVE-2001-0805 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:58.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tarantella-ttawebtop-read-files(6723) + + + BID + 2890 + + + BUGTRAQ + 20010619 Re: SCO Tarantella Remote file read via ttawebtop.cgi + + + BUGTRAQ + 20010618 SCO Tarantella Remote file read via ttawebtop.cgi + + Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter. + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.1 + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/o:apple:mac_os_x:10.0.2 + + CVE-2001-0806 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:58.427-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2930 + + + BUGTRAQ + 20010626 MacOSX 10.0.X Permissions uncorrectly set + + + BUGTRAQ + 20010704 Re: MacOSX 10.0.X Permissions uncorrectly set - I got it + + + XF + macos-desktop-insecure-permissions(6750) + + + OSVDB + 1882 + + + BUGTRAQ + 20011007 OS X 10.1 and localized desktop folder still vulnerable + + Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages. + + + + + + + + + cpe:/a:microsoft:ie:5.0 + + CVE-2001-0807 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:58.583-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-local-file-disclosure(6688) + + + BUGTRAQ + 20010606 security bug Internet Explorer 5 + + Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file. + + + + + + + + + + + + cpe:/a:yngve_svendsen:gnatsweb:3.95:gnats_4 + cpe:/a:yngve_svendsen:gnatsweb:2.8.1 + cpe:/a:yngve_svendsen:gnatsweb:2.8.0 + cpe:/a:yngve_svendsen:gnatsweb:2.7_beta + + CVE-2001-0808 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:58.737-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + gnatsweb-helpfile-execute-commands(6753) + + + CONFIRM + http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html + + + BUGTRAQ + 20010627 gnats update + + gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + + CVE-2001-0809 + 2001-12-06T00:00:00.000-05:00 + 2009-03-04T00:08:50.860-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + HP + HPSBUX0106-155 + + + + + Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources. + + + + + + + + + cpe:/a:activestate:activeperl:5.6.1.629 + + CVE-2001-0815 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:59.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3526 + + + BUGTRAQ + 20011115 NSFOCUS SA2001-07 : ActivePerl PerlIS.dll Remote Buffer Overflow Vulnerability + + + CONFIRM + http://bugs.activestate.com/show_bug.cgi?id=18062 + + + XF + activeperl-perlis-filename-bo(7539) + + + OSVDB + 678 + + Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to exute arbitrary code via an HTTP request for a long filename that ends in a .pl extension. + + + + + + + + + cpe:/a:openbsd:openssh:2.9.9 + + CVE-2001-0816 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:59.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010918 OpenSSH: sftp & bypassing keypair auth restrictions + + + XF + openssh-sftp-bypass-restrictions(7634) + + + REDHAT + RHSA-2001:154 + + + OSVDB + 5536 + + + IMMUNIX + IMNX-2001-70-034-01 + + + CONECTIVA + CLSA-2001:431 + + OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-0817 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:59.333-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#638011 + + + CERT + CA-2001-32 + + + XF + hpux-rlpdaemon-logic-flaw(7234) + + + ISS + 20011120 Remote Logic Flaw Vulnerability in HP-UX Line Printer Daemon + + + HP + HPSBUX0111-176 + + + BID + 3561 + + + CIAC + M-021 + + Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request. + + + + + + + + + + + + + cpe:/a:marty_bochane:mdbms:0.99b9 + cpe:/a:marty_bochane:mdbms:0.99b5 + cpe:/a:marty_bochane:mdbms:0.99b6 + cpe:/a:marty_bochane:mdbms:0.96b6 + cpe:/a:marty_bochane:mdbms:0.99b4 + + CVE-2001-0818 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:59.473-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mdbms-query-display-bo(6700) + + + BID + 2867 + + + BUGTRAQ + 20010612 Remote buffer overflow in MDBMS. + + A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a large amount of data. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2001-0819 + 2001-12-06T00:00:00.000-05:00 + 2011-02-15T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + fetchmail-long-header-bo(6704) + + + BID + 2877 + + + ENGARDE + ESA-20010620-01 + + + DEBIAN + DSA-060 + + + REDHAT + RHSA-2001:103 + + + SUSE + SuSE-SA:2001:026 + + + MANDRAKE + MDKSA-2001:063 + + + CALDERA + CSSA-2001-022.1 + + + IMMUNIX + IMNX-2001-70-025-01 + + + CONECTIVA + CLA-2001:403 + + + FREEBSD + FreeBSD-SA-01:43 + + A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header. + + + + + + + + + cpe:/a:gaztek:ghttp:1.4 + + CVE-2001-0820 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:24:59.877-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010630 Advisory Ghttp 1.4 + + + XF + gaztek-ghttpd-bo(6702) + + + BID + 2965 + + + BID + 2879 + + + BUGTRAQ + 20010617 Buffer Overflow in GazTek HTTP Daemon v1.4 (ghttpd) + + Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. + + + + + + + + + cpe:/a:dcscripts:dcshop:1.002_beta + + CVE-2001-0821 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:00.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2889 + + + CONFIRM + http://www.dcscripts.com/dcforum/dcshop/44.html + + + XF + dcshop-cgi-retrieve-information(6707) + + + BUGTRAQ + 20010618 DCShop vulnerability + + The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. + + + + + + + + + cpe:/a:packet_knights:fpf_linux_kernel_module:1.0 + + CVE-2001-0822 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:00.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-fpf-kernel-dos(6659) + + + BID + 2816 + + + CONFIRM + http://www.pkcrew.org/news.php + + + BUGTRAQ + 20010602 fpf module and packet fragmentation:local/remote DoS. + + FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets. + + + + + + + + + + + + + + + + + + + + cpe:/a:sgi:performance_co-pilot:2.1.7 + cpe:/a:sgi:performance_co-pilot:2.1.6 + cpe:/a:sgi:performance_co-pilot:2.1.11 + cpe:/a:sgi:performance_co-pilot:2.1.9 + cpe:/a:sgi:performance_co-pilot:2.1.8 + cpe:/a:sgi:performance_co-pilot:2.1.10 + cpe:/a:sgi:performance_co-pilot:2.1.1 + cpe:/a:sgi:performance_co-pilot:2.1.3 + cpe:/a:sgi:performance_co-pilot:2.1.2 + cpe:/a:sgi:performance_co-pilot:2.1.5 + cpe:/a:sgi:performance_co-pilot:2.2 + cpe:/a:sgi:performance_co-pilot:2.1.4 + + CVE-2001-0823 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:00.317-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + irix-pcp-pmpost-symlink(6724) + + + BID + 2887 + + + BUGTRAQ + 20010619 Re: pmpost - another nice symlink follower + + + SGI + 20010601-01-A + + + BUGTRAQ + 20010618 pmpost - another nice symlink follower + + The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR). + + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.5 + cpe:/a:ibm:websphere_application_server:3.0.2 + + CVE-2001-0824 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:01.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2969 + + + BUGTRAQ + 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability + + Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page. + + + + + + + + + + + + cpe:/a:xinetd:xinetd:2.3.1 + cpe:/a:xinetd:xinetd:2.3.0 + cpe:/a:xinetd:xinetd:2.1.8.9 + cpe:/a:xinetd:xinetd:2.1.8.8 + + CVE-2001-0825 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:01.663-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2971 + + + REDHAT + RHSA-2001:092 + + + CONECTIVA + CLA-2001:406 + + + XF + xinetd-zero-length-bo(6804) + + + IMMUNIX + IMNX-2001-70-029-01 + + Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check. + + + + + + + + + cpe:/a:aclogic:cesarftp:0.98b + + CVE-2001-0826 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:01.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2972 + + + BUGTRAQ + 20010630 cesarFTP v0.98b 'HELP' buffer overflow + + + BUGTRAQ + 20010704 CesarFTPd, Cerberus FTPd + + Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD. + + + + + + + + + + + + + + + cpe:/a:grant_averett:ceberus_ftp_server:1.0 + cpe:/a:grant_averett:ceberus_ftp_server:1.01 + cpe:/a:grant_averett:ceberus_ftp_server:1.5 + cpe:/a:grant_averett:ceberus_ftp_server:1.2 + cpe:/a:grant_averett:ceberus_ftp_server:1.1 + cpe:/a:grant_averett:ceberus_ftp_server:1.3 + cpe:/a:grant_averett:ceberus_ftp_server:1.22 + + CVE-2001-0827 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:01.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2976 + + + BUGTRAQ + 20010704 CesarFTPd, Cerberus FTPd + + Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests. + + + + + + + + + + cpe:/a:caucho_technology:resin:1.2.2 + cpe:/a:caucho_technology:resin:1.2.4 + + CVE-2001-0828 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:02.210-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#981651 + + + BID + 2981 + + + CONFIRM + http://www.caucho.com/products/resin/changes.xtp + + + XF + java-servlet-crosssite-scripting(6793) + + + OSVDB + 1890 + + + BUGTRAQ + 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability + + A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript. + + + + + + + + + cpe:/a:apache:tomcat:3.2.1 + + CVE-2001-0829 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:02.477-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2982 + + + MISC + http://jakarta.apache.org/tomcat/tomcat-3.2-doc/readme + + + BUGTRAQ + 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability + + A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message. + + + + + + + + + cpe:/a:pld:6tunnel:0.08 + + CVE-2001-0830 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:01.393-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011023 Remote DoS in 6tunnel + + + CONFIRM + ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz + + + XF + 6tunnel-open-socket-dos(7337) + + + BID + 3467 + + 6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server. + + + + + + + + + + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:oracle:database_server:9.0.1 + + CVE-2001-0831 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:01.537-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/OLS817alert.pdf + + + BUGTRAQ + 20011023 FW: ASI Oracle Security Alert: 3 new security alerts + + + BID + 3465 + + + XF + oracle-label-security-access(7344) + + Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access. + + + + + + + + + + + cpe:/a:oracle:database_server:8.0 + cpe:/a:oracle:database_server:9.0.1 + cpe:/a:oracle:database_server:8.1 + + CVE-2001-0832 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:01.690-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf + + + BUGTRAQ + 20011023 FW: ASI Oracle Security Alert: 3 new security alerts + + Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability." + + + + + + + + + + + cpe:/a:oracle:database_server:8.0 + cpe:/a:oracle:database_server:9.0.1 + cpe:/a:oracle:database_server:8.1 + + CVE-2001-0833 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:01.847-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf + + + BUGTRAQ + 20011023 FW: ASI Oracle Security Alert: 3 new security alerts + + + XF + oracle-binary-symlink(6940) + + + BID + 3139 + + + CIAC + M-011 + + + BUGTRAQ + 20011024 Oracle Trace Collection Security Vulnerability + + + BUGTRAQ + 20010802 vulnerability in otrcrep binary in Oracle 8.0.5. + + Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability." + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:6.0 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:7.3 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:conectiva:linux:7.0 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/a:htdig:htdig:3.1.5 + cpe:/o:conectiva:linux:5.0 + cpe:/o:conectiva:linux:5.1 + + CVE-2001-0834 + 2001-12-06T00:00:00.000-05:00 + 2011-03-07T21:05:55.360-05:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-080 + + + BUGTRAQ + 20011007 Re: Bug found in ht://Dig htsearch CGI + + + CONECTIVA + CLA-2001:429 + + + MISC + http://sourceforge.net/tracker/index.php?func=detail&aid=458013&group_id=4593&atid=104593 + + + XF + htdig-htsearch-retrieve-files(7263) + + + XF + htdig-htsearch-infinite-loop(7262) + + + BID + 3410 + + + REDHAT + RHSA-2001:139 + + + SUSE + SuSE-SA:2001:035 + + + MANDRAKE + MDKSA-2001:083 + + + CALDERA + CSSA-2001-035.0 + + htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file. + + + + + + + + + cpe:/a:bradford_barrett:webalizer:2.0.6 + + CVE-2001-0835 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3473 + + + REDHAT + RHSA-2001:141 + + + CONFIRM + http://www.mrunix.net/webalizer/news.html + + + BUGTRAQ + 20011024 Cross-site Scripting Flaw in webalizer + + + SUSE + SuSE-SA:2001:040 + + + XF + webalizer-html-tags-keywords(7351) + + + XF + webalizer-html-tag-host(7350) + + + REDHAT + RHSA-2001:140 + + + ENGARDE + ESA-20011101-01 + + Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + + CVE-2001-0836 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#649979 + + + CERT + CA-2001-29 + + + BUGTRAQ + 20011024 Oracle9iAS Web Cache Overflow Vulnerability + + + BUGTRAQ + 20011018 def-2001-30 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/webcache.pdf + + + XF + oracle-appserver-http-bo(7306) + + + OSVDB + 5534 + + Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + cpe:/a:deltathree:pc-to-phone:3.0.3 + + CVE-2001-0837 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.473-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pc2phone-temp-account-readable(7393) + + + BID + 3475 + + + BUGTRAQ + 20011025 Pc-to-Phone vulnerability - broken by design + + DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder. + + + + + + + + + cpe:/a:network_solutions:rwhoisd:1.5.x + + CVE-2001-0838 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.613-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011025 RWhoisd remote format string vulnerability + + Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command. + + + + + + + + + cpe:/a:ibill_internet_billing_company:processing_plus + + CVE-2001-0839 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.753-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ibillpm-cgi-insecure-password(7352) + + + BID + 3476 + + + BUGTRAQ + 20011025 Weak authentication in iBill's Password Management CGI + + ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. + + + + + + + + + + + + cpe:/a:compaq:insight_manager_xe:1.21 + cpe:/a:compaq:insight_manager_xe:2.1b + cpe:/a:compaq:insight_manager_xe:1.0 + cpe:/a:compaq:insight_manager_xe:2.1 + + CVE-2001-0840 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:02.910-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#908611 + + + BID + 3482 + + + COMPAQ + SSRT0766 + + + XF + compaq-insightmanager-xe-bo(7411) + + Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI. + + + + + + + + + cpe:/a:ikonboard.com:ikonboard:ib219 + + CVE-2001-0841 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:04.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011030 Ikonboard Cookie filter vulnerability + + + BID + 3486 + + + XF + ikonboard-cookie-auth-privileges(7433) + + Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. + + + + + + + + + cpe:/a:leoboard:lb5000:1029 + + CVE-2001-0842 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T19:58:35.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011030 LB5000 Cookie filter vulnerability + + + BID + 3484 + + + XF + leoboard-cookie-auth-privileges(7436) + + Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. + + + + + + + + + cpe:/a:squid:squid_web_proxy:2.4 + + CVE-2001-0843 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:04.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:113 + + + BUGTRAQ + 20010921 squid DoS + + + XF + squid-mkdir-put-dos(7157) + + + BID + 3354 + + + SUSE + SuSE-SA:2001:037 + + + MANDRAKE + MDKSA-2001:088 + + + DEBIAN + DSA-077 + + + CONECTIVA + CLA-2001:426 + + Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request. + + + + + + + + + + cpe:/a:seth_leonard:book_of_guests + cpe:/a:seth_leonard:post_it + + CVE-2001-0844 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:04.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011030 cgi vulnerability + + + BID + 3485 + + + BID + 3483 + + + XF + postit-cgi-command-execution(7435) + + + XF + bookofguests-cgi-command-execution(7434) + + Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter. + + + + + + + + + + + + + + + + + + + cpe:/a:dec:dec_openvms:7.2_vax + cpe:/a:dec:dec_openvms:7.1_vax + cpe:/a:dec:sevms:6.2 + cpe:/a:dec:dec_openvms_alpha:7.2.1h1 + cpe:/a:dec:dec_openvms_alpha:7.2.2 + cpe:/a:dec:dec_openvms:7.3_vax + cpe:/a:dec:sevms_alpha:6.2 + cpe:/a:dec:dec_openvms_alpha:7.3 + cpe:/a:dec:dec_openvms_alpha:7.1.2 + cpe:/a:dec:dec_openvms_alpha:6.2 + cpe:/a:dec:dec_openvms:6.2_vax + + CVE-2001-0845 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:04.647-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + COMPAQ + SSRT0738 + + + XF + openvms-dms-unauthorized-access(7425) + + + BID + 3492 + + Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino:5.0 + cpe:/a:lotus:domino:5.0.2c + cpe:/a:lotus:domino:5.0.5 + cpe:/a:lotus:domino:5.0.4 + cpe:/a:lotus:domino:5.0.2a + cpe:/a:lotus:domino:5.0.7 + cpe:/a:lotus:domino:5.0.6 + cpe:/a:lotus:domino:5.0.1 + cpe:/a:lotus:domino:5.0.3 + cpe:/a:lotus:domino:5.0.2 + cpe:/a:lotus:domino:5.0.4a + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:5.0.6a + cpe:/a:lotus:domino:5.0.7a + + CVE-2001-0846 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:03.817-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011030 Lotus Domino Web Administrator Template ReplicaID Access (#NISR29102001A) + + + XF + lotus-domino-replicaid-access(7424) + + + OSVDB + 1979 + + + BID + 3491 + + Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf). + + + + + + + + + cpe:/a:lotus:domino_web_server:5.x + + CVE-2001-0847 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:04.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011031 Lotus Domino Default Navigator Protection By-pass (#NISR29102001B) + + + XF + lotus-domino-navigator-access(7423) + + + BID + 3488 + + Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID. + + + + + + + + + cpe:/a:e-zone_media:fuse_talk + + CVE-2001-0848 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:04.143-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011101 Fuse Talk vulnerability + + + BID + 3496 + + + XF + fusetalk-joincfm-sql-execution(7445) + + join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable. + + + + + + + + + + + cpe:/a:duncan_hall:viralator:0.9_pre1 + cpe:/a:duncan_hall:viralator:0.8 + cpe:/a:duncan_hall:viralator:0.7 + + CVE-2001-0849 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:04.283-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + viralator-cgi-command-execution(7440) + + + BID + 3495 + + + MISC + http://viralator.loddington.com/changes.html + + + BUGTRAQ + 20011101 Vulnerability in Viralator proxy extension + + viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget. + + + + + + + + + cpe:/o:caldera:openlinux:3.1 + + CVE-2001-0850 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:04.440-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-2001-037.0 + + + XF + openlinux-libdb-bo(7427) + + A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:caldera:openlinux:2.3 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:suse:suse_linux:7.3 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:caldera:openlinux_eserver:2.3.1 + cpe:/a:caldera:openlinux_server:3.1 + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/o:caldera:openlinux_edesktop:2.4 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.0 + + CVE-2001-0851 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:05.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ENGARDE + ESA-20011106-01 + + + CALDERA + CSSA-2001-38.0 + + + XF + linux-syncookie-bypass-filter(7461) + + + REDHAT + RHSA-2001:142 + + + SUSE + SuSE-SA:2001:039 + + + MANDRAKE + MDKSA-2001:082 + + + CONECTIVA + CLA-2001:432 + + Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. + + + + + + + + + cpe:/o:redhat:linux:7.2 + + CVE-2001-0852 + 2001-12-06T00:00:00.000-05:00 + 2011-03-07T21:05:57.080-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://marc.theaimsgroup.com/?l=tux-list&m=100584714702328&w=2 + + + BUGTRAQ + 20011105 RH Linux Tux HTTPD DoS + + + REDHAT + RHSA-2001:142 + + + XF + tux-http-host-dos(7464) + + + BID + 3506 + + TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. + + + + + + + + + cpe:/a:entrust:getaccess:all_versions + + CVE-2001-0853 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:04.973-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#243243 + + + BUGTRAQ + 20011105 Entrust Bulletin E01-005: GetAccess Access Service vulnerability + + + XF + getaccess-shellscripts-retrieve-files(7474) + + + BID + 3508 + + + BUGTRAQ + 20011105 New getAccess[tm] Vulnerability + + Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.2 + + CVE-2001-0854 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:05.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011105 Copying and Deleting Files Using PHP-Nuke + + + BID + 3510 + + + XF + phpnuke-filemanager-gain-privileges(7478) + + PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user. + + + + + + + + + + + + cpe:/a:rational_software:clearcase:3.2_plus + cpe:/a:rational_software:clearcase:4.1 + cpe:/a:rational_software:clearcase:4.2 + cpe:/a:rational_software:clearcase:4.0 + + CVE-2001-0855 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:05.270-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011109 ClearCase db_loader TERM environment variable buffer overflow vulnerability + + + BID + 3523 + + + XF + clearcase-dbloader-term-bo(7488) + + Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable. + + + + + + + + + cpe:/h:ibm:4758 + + CVE-2001-0856 + 2001-12-06T00:00:00.000-05:00 + 2008-09-10T15:09:06.117-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.cl.cam.ac.uk/~rnc1/descrack/ + + + MISC + http://www.cl.cam.ac.uk/~rnc1/descrack/attack.html + + + BUGTRAQ + 20011109 Extracting a 3DES key from an IBM 4758 + + + BID + 3524 + + Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key. + + + + + + + + + cpe:/a:imp:webmail:2.2.6 + + CVE-2001-0857 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:05.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011110 IMP 2.2.7 (SECURITY) released + + + BUGTRAQ + 20011109 Imp Webmail session hijacking vulnerability + + + XF + imp-css-steal-cookies(7496) + + + BID + 3525 + + + OSVDB + 668 + + + CALDERA + CSSA-2001-039.0 + + + CONECTIVA + CLA-2001:437 + + Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter. + + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + cpe:/a:caldera:unixware:7.1.0 + + CVE-2001-0858 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:05.723-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011113 Security Update: [CSSA-2001-SCO.32] Open UNIX, UnixWare 7: buffer overflow in ppp utilities + + + CALDERA + CSSA-2001-SCO.32 + + + XF + unixware-openunix-ppp-bo(7570) + + Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges. + + + + + + + + + cpe:/o:redhat:linux:7.1 + + CVE-2001-0859 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:05.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:148 + + + XF + linux-korean-default-umask(7549) + + + BID + 3527 + + + HP + HPSBTL0112-006 + + 2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions. + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_2000 + + CVE-2001-0860 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011114 Xato Advisory: Win2k/XP Terminal Services IP Spoofing + + + XF + win-terminal-spoof-address(7538) + + + BID + 3541 + + Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT). + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0861 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.160-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20011114 ICMP Unreachable Vulnerability in Cisco 12000 Series Internet Router + + + XF + cisco-icmp-unreachable-dos(7536) + + + BID + 3534 + + + OSVDB + 794 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0862 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + XF + cisco-acl-noninital-dos(7550) + + + BID + 3535 + + + OSVDB + 1985 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0863 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.457-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + XF + cisco-acl-outgoing-fragment(7551) + + + BID + 3539 + + + OSVDB + 1987 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0864 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.613-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + XF + cisco-acl-deny-ip(7553) + + + BID + 3536 + + + OSVDB + 1986 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0865 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.753-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + XF + cisco-turbo-acl-dos(7552) + + + BID + 3540 + + + OSVDB + 1988 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0866 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:06.910-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + BID + 3537 + + + OSVDB + 1984 + + + XF + cisco-input-acl-configured(7554) + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls. + + + + + + + + + cpe:/h:cisco:12000_router + + CVE-2001-0867 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:25:07.050-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router + + + XF + cisco-acl-fragment-bypass(7555) + + + BID + 3538 + + + OSVDB + 1989 + + + CIAC + M-018 + + + + + Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls. + + + + + + + + + + cpe:/a:redhat:stronghold:3.0 + cpe:/a:redhat:stronghold:2.3 + + CVE-2001-0868 + 2001-11-28T00:00:00.000-05:00 + 2012-09-12T21:10:26.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011123 Redhat Stronghold Secure Server File System Disclosure Vulnerability + + + XF + apache-strongholdstatus-info-disclosure(51951) + + + XF + apache-strongholdinfo-info-disclosure(51950) + + + XF + stronghold-webserver-obtain-information(7582) + + + BID + 3577 + + Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status. + + + + + + + + + + + + + + + + + + + + + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/o:caldera:openlinux_eserver:3.1 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/a:redhat:linux_powertools:6.2 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:7.3 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0869 + 2001-12-21T00:00:00.000-05:00 + 2008-09-10T15:09:08.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:151 + + + REDHAT + RHSA-2001:150 + + + SUSE + SuSE-SA:2001:042 + + + XF + cyrus-sasl-format-string(7443) + + + BID + 3498 + + + CALDERA + CSSA-2001-040.0 + + + MANDRAKE + MDKSA-2002:018 + + + CONECTIVA + CLA-2001:444 + + + FREEBSD + FreeBSD-SA-02:15 + + Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands. + + + + + + + + + + + + + + + + + + cpe:/a:alchemy_lab:alchemy_eye:2.3 + cpe:/a:alchemy_lab:alchemy_eye:2.2 + cpe:/a:alchemy_lab:alchemy_eye:2.5 + cpe:/a:alchemy_lab:alchemy_eye:2.4 + cpe:/a:alchemy_lab:alchemy_eye:2.6 + cpe:/a:alchemy_lab:alchemy_eye:1.9 + cpe:/a:dek_software:alchemy_network_monitor:2.6.18 + cpe:/a:alchemy_lab:alchemy_eye:2.6.18 + cpe:/a:alchemy_lab:alchemy_eye:2.0 + cpe:/a:alchemy_lab:alchemy_eye:2.1 + + CVE-2001-0870 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:07.520-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3598 + + + BUGTRAQ + 20011130 Rapid 7 Advisory R7-0002: Alchemy Eye Remote Unauthenticated Log Viewing + + + XF + alchemy-http-view-log(7630) + + HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file. + + + + + + + + + + + + + + + + + + + + cpe:/a:dek_software:alchemy_network_monitor:3.0.10 + cpe:/a:alchemy_lab:alchemy_eye:2.3 + cpe:/a:alchemy_lab:alchemy_eye:2.2 + cpe:/a:alchemy_lab:alchemy_eye:3.0 + cpe:/a:alchemy_lab:alchemy_eye:2.5 + cpe:/a:alchemy_lab:alchemy_eye:2.4 + cpe:/a:alchemy_lab:alchemy_eye:3.0.10 + cpe:/a:alchemy_lab:alchemy_eye:2.6 + cpe:/a:alchemy_lab:alchemy_eye:2.6.18 + cpe:/a:alchemy_lab:alchemy_eye:2.6.19 + cpe:/a:alchemy_lab:alchemy_eye:2.0 + cpe:/a:alchemy_lab:alchemy_eye:2.1 + + CVE-2001-0871 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:07.690-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#220715 + + + BUGTRAQ + 20011129 Rapid 7 Advisory R7-0001: Alchemy Eye HTTP Remote Command Execution + + + XF + alchemy-http-dot-variant(7626) + + + BID + 3599 + + + XF + alchemy-http-dot-commands(7625) + + Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10. + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/a:openbsd:openssh:3.0.1 + cpe:/o:suse:suse_linux:7.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0872 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:07.863-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#157447 + + + REDHAT + RHSA-2001:161 + + + BUGTRAQ + 20011204 [Fwd: OpenSSH 3.0.2 fixes UseLogin vulnerability] + + + SUSE + SuSE-SA:2001:045 + + + CONFIRM + http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=100747128105913&w=2 + + + XF + openssh-uselogin-execute-code(7647) + + + HP + HPSBUX0112-005 + + + BID + 3614 + + + OSVDB + 688 + + + DEBIAN + DSA-091 + + + CIAC + M-026 + + + MANDRAKE + MDKSA-2001:092 + + + CONECTIVA + CLA-2001:446 + + + CALDERA + CSSA-2001-042.1 + + OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges. + + + + + + + + + cpe:/a:ian_lance_taylor:taylor_uucp:1.0.6 + + CVE-2001-0873 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:08.033-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3312 + + + CALDERA + CSSA-2001-033.0 + + + CONECTIVA + CLA-2001:425 + + + BUGTRAQ + 20010908 Multiple vendor 'Taylor UUCP' problems. + + + BUGTRAQ + 20011130 Redhat 7.0 local root (via uucp) (attempt 2) + + + XF + uucp-argument-gain-privileges(7099) + + + SUSE + SuSE-SA:2001:38 + + + DEBIAN + DSA-079 + + + REDHAT + RHSA-2001:165 + + uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0874 + 2001-12-13T00:00:00.000-05:00 + 2008-09-05T16:25:08.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-frame-verification-variant2(7702) + + + BID + 3693 + + + MS + MS01-058 + + + CIAC + M-027 + + Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain, a variant of the "Frame Domain Verification" vulnerability. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0875 + 2001-11-26T00:00:00.000-05:00 + 2008-09-05T16:25:08.330-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + XF + ie-file-download-ext-spoof(7636) + + + BID + 3597 + + + BUGTRAQ + 20011126 File extensions spoofable in MSIE download dialog + + + MS + MS01-058 + + + + + Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download. + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_me + + CVE-2001-0876 + 2001-12-20T00:00:00.000-05:00 + 2008-09-05T16:25:08.487-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2001-37 + + + CERT-VN + VU#951555 + + + XF + win-upnp-notify-bo(7721) + + + BID + 3723 + + + MS + MS01-059 + + + BUGTRAQ + 20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities + + + CIAC + M-030 + + + NTBUGTRAQ + 20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities + + Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL. + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_me + + CVE-2001-0877 + 2001-12-20T00:00:00.000-05:00 + 2008-09-05T16:25:08.643-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2001-37 + + + CERT-VN + VU#411059 + + + XF + win-upnp-udp-dos(7722) + + + MS + MS01-059 + + + BUGTRAQ + 20020109 UPNP Denial of Service + + + BUGTRAQ + 20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities + + + BID + 3724 + + + CIAC + M-030 + + + NTBUGTRAQ + 20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities + + Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system. + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt + cpe:/a:microsoft:sql_server:2000 + + CVE-2001-0879 + 2001-12-20T00:00:00.000-05:00 + 2008-09-05T16:25:08.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + mssql-c-runtime-format-string(7725) + + + BID + 3732 + + + MS + MS01-060 + + + ATSTAKE + A122001-1 + + + BUGTRAQ + 20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server + + + + + Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service. + + + + + + + + + + + + + cpe:/a:gnu:mailman:7.0 + cpe:/a:gnu:mailman:6.0 + cpe:/a:gnu:mailman:5.1 + cpe:/a:gnu:mailman:5.0 + cpe:/a:gnu:mailman + + CVE-2001-0884 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:08.957-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011128 Cgisecurity.com Advisory #7: Mailman Email Archive Cross Site Scripting + + + CONECTIVA + CLA-2001:445 + + + XF + mailman-java-css(7617) + + + BID + 3602 + + + REDHAT + RHSA-2001:170 + + + REDHAT + RHSA-2001:169 + + + REDHAT + RHSA-2001:168 + + Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users. + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.1 + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2001-0886 + 2001-12-21T00:00:00.000-05:00 + 2011-03-07T21:06:00.377-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:160 + + + MISC + http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html + + + XF + glibc-glob-bo(7705) + + + HP + HPSBTL0112-008 + + + BID + 3707 + + + BUGTRAQ + 20011217 [Global InterSec 2001121001] glibc globbing issues. + + + ENGARDE + ESA-20011217-01 + + + MANDRAKE + MDKSA-2001:095 + + + DEBIAN + DSA-103 + + + CIAC + M-029 + + + IMMUNIX + IMNX-2001-70-037-01 + + + CONECTIVA + CLA-2002:447 + + Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character. + + + + + + + + + cpe:/a:oliver_rauch:xsane:0.81 + + CVE-2001-0887 + 2002-01-15T00:00:00.000-05:00 + 2008-09-05T16:25:09.267-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3700 + + + FREEBSD + FreeBSD-SA-01:68 + + + XF + xsane-temp-symlink(7714) + + + REDHAT + RHSA-2001:172 + + + REDHAT + RHSA-2001:171 + + xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files. + + + + + + + + + + + cpe:/h:netgear:me102:1.3 + cpe:/h:linksys:wap11:1.3 + cpe:/h:atmel:firmware:1.3 + + CVE-2001-0888 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:09.410-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011221 VIGILANTe advisory 2001003 : Atmel SNMP Non Public Community String DoS Vulnerability + + + XF + atmel-snmp-community-dos(7734) + + + BID + 3734 + + Atmel Firmware 1.3 Wireless Access Point (WAP) allows remote attackers to cause a denial of service via a SNMP request with (1) a community string other than "public" or (2) an unknown OID, which causes the WAP to deny subsequent SNMP requests. + + + + + + + + + + + + + + cpe:/o:redhat:linux + cpe:/a:university_of_cambridge:exim:3.22 + + CVE-2001-0889 + 2001-12-19T00:00:00.000-05:00 + 2008-09-05T16:25:09.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#283723 + + + REDHAT + RHSA-2001:176 + + + BUGTRAQ + 20011219 [ph10@cus.cam.ac.uk: [Exim] Potential security problem] + + + XF + exim-pipe-hostname-commands(7738) + + + BID + 3728 + + + DEBIAN + DSA-097 + + Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + + + + + + cpe:/a:sane:sane:1.0.0 + cpe:/a:sane:sane:1.0.6 + cpe:/a:sane:sane:1.0.5 + cpe:/a:sane:sane:1.0.2 + cpe:/a:sane:sane:1.0.1 + cpe:/a:sane:sane:1.0.4 + cpe:/a:sane:sane:1.0.3 + + CVE-2001-0890 + 2001-12-11T00:00:00.000-05:00 + 2008-09-10T15:09:09.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xsane-temp-symlink(7714) + + + REDHAT + RHSA-2001:171 + + + BID + 3987 + + Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files. + + + + + + + + + + + + + + cpe:/a:sgi:nqsdaemon:3.3.0.16 + cpe:/o:cray:unicos + + CVE-2001-0891 + 2002-01-31T00:00:00.000-05:00 + 2008-09-05T16:25:09.877-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20020101-01-I + + + BUGTRAQ + 20011127 UNICOS LOCAL HOLE ALL VERSIONS + + + XF + unicos-nqsd-format-string(7618) + + + BID + 3590 + + + OSVDB + 3275 + + Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters. + + + + + + + + + cpe:/a:acme_labs:thttpd:2.22 + + CVE-2001-0892 + 2001-11-13T00:00:00.000-05:00 + 2008-09-05T16:25:10.033-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln + + + CONFIRM + http://www.acme.com/software/thttpd/ + + Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. + + + + + + + + + cpe:/a:acme_labs:mini_httpd:1.16 + + CVE-2001-0893 + 2001-11-13T00:00:00.000-05:00 + 2008-09-10T15:09:10.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + httpd-bypass-permissions(7541) + + + CONFIRM + http://www.acme.com/software/mini_httpd/ + + + BUGTRAQ + 20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln + + Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. + + + + + + + + + + + cpe:/a:wietse_venema:postfix:1999-09-06 + cpe:/a:wietse_venema:postfix:2000-02-28 + cpe:/a:wietse_venema:postfix:1999-12-31 + + CVE-2001-0894 + 2001-11-11T00:00:00.000-05:00 + 2008-09-10T15:09:10.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + postfix-smtp-log-dos(7568) + + + BID + 3544 + + + DEBIAN + DSA-093 + + + BUGTRAQ + 20011115 Postfix session log memory exhaustion bugfix + + + REDHAT + RHSA-2001:156 + + + MANDRAKE + MDKSA-2001:089 + + + CONECTIVA + CLA-2001:439 + + Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large. + + + + + + + + + + + + + + + + + + + cpe:/h:cisco:catalyst_2950 + cpe:/h:cisco:catalyst_3550 + cpe:/h:cisco:catalyst_6000 + cpe:/h:cisco:catalyst_5000 + cpe:/h:cisco:catalyst_2900xl + cpe:/h:cisco:catalyst_4908g-l3 + cpe:/h:cisco:catalyst_8500 + cpe:/h:cisco:distributed_director + cpe:/h:cisco:catalyst_4000 + cpe:/h:cisco:catalyst_3500xl + cpe:/h:cisco:catalyst_2948g-l3 + + CVE-2001-0895 + 2001-11-15T00:00:00.000-05:00 + 2008-09-05T16:25:10.487-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#399355 + + + CISCO + 20011115 Cisco IOS ARP Table Overwrite Vulnerability + + + XF + cisco-arp-overwrite-table(7547) + + + BID + 3547 + + + OSVDB + 807 + + + + + Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table. + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + + CVE-2001-0896 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:25:10.660-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CALDERA + CSSA-2001-SCO.33 + + + XF + openserver-nmap-po-option(7571) + + + BUGTRAQ + 20020205 nmap vs. inetd on Caldera (ex-SCO) OpenServer, Re: DoS bug on Tru64 + + + BUGTRAQ + 20020201 RE: DoS bug on Tru64 + + Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO. + + + + + + + + + cpe:/a:infopop:ultimate_bulletin_board:5.47e + + CVE-2001-0897 + 2001-11-15T00:00:00.000-05:00 + 2008-09-05T16:25:10.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011115 Re: UBB vulnerablietis + about: using example + + + BUGTRAQ + 20011115 UBB vulnerablietis + about: using example + + Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0 + + CVE-2001-0898 + 2001-11-15T00:00:00.000-05:00 + 2008-09-05T16:25:10.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3553 + + + XF + opera-java-cross-site(7567) + + + BUGTRAQ + 20011116 Re: Several javascript vulnerabilities in Opera + + + BUGTRAQ + 20011115 Several javascript vulnerabilities in Opera + + Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache. + + + + + + + + + + cpe:/a:php-nuke:php-nuke + cpe:/a:rick_fournier:network_tools:0.2 + + CVE-2001-0899 + 2001-11-16T00:00:00.000-05:00 + 2011-03-07T21:06:03.500-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://phpnukerz.org/modules.php?name=Downloads&d_op=viewsdownload&sid=32 + + + BUGTRAQ + 20011116 Network Tool 0.2 Addon for PHPNuke vulnerable to remote command execution + + + XF + phpnuke-nettools-command-execution(7578) + + Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. + + + + + + + + + cpe:/a:francisco_burzi:gallery:1.2.3 + + CVE-2001-0900 + 2001-11-18T00:00:00.000-05:00 + 2008-09-05T16:25:11.267-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011118 Gallery Addon for PhpNuke remote file viewing vulnerability + + + XF + phpnuke-gallery-directory-traversal(7580) + + + BID + 3554 + + + OSVDB + 677 + + Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter. + + + + + + + + + cpe:/a:hypermail_development:hypermail + + CVE-2001-0901 + 2001-11-19T00:00:00.000-05:00 + 2008-09-05T16:25:11.410-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011119 Hypermail SSI Vulnerability + + + CONFIRM + http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz + + + XF + hypermail-ssi-execute-commands(7576) + + Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-0902 + 2001-11-20T00:00:00.000-05:00 + 2008-09-05T16:25:11.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + iis-fake-log-entry(7613) + + + BID + 6795 + + + BUGTRAQ + 20011120 IIS logging issue + + + NTBUGTRAQ + 20011120 IIS logging issue + + Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters. + + + + + + + + + cpe:/a:intel:high-bandwidth_digital_content_protection:1.0 + + CVE-2001-0903 + 2001-11-20T00:00:00.000-05:00 + 2008-09-05T16:25:11.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3558 + + + XF + hdcp-authentication-keys(7612) + + + BUGTRAQ + 20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System + + Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-0904 + 2001-11-20T00:00:00.000-05:00 + 2008-09-05T16:25:11.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011120 MSIE 5.5/6 Q312461 patch disclose patch information + + + BID + 3556 + + + XF + ie-q312461-patch-existence(7581) + + Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients. + + + + + + + + + cpe:/a:procmail:procmail:3.20 + + CVE-2001-0905 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:25:12.003-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3071 + + + REDHAT + RHSA-2001:093 + + + MANDRAKE + MDKSA-2001:085 + + + DEBIAN + DSA-083 + + + FREEBSD + FreeBSD-SA-01:60 + + + XF + procmail-signal-handling-race(6872) + + + CONECTIVA + CLA-2001:433 + + Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running. + + + + + + + + + cpe:/a:tetex:tetex:1.0.7.7 + + CVE-2001-0906 + 2001-06-22T00:00:00.000-04:00 + 2008-09-05T16:25:12.143-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + tetex-lprng-tmp-race(6785) + + + BID + 2974 + + + REDHAT + RHSA-2001:102 + + + MANDRAKE + MDKSA-2001:086 + + + BUGTRAQ + 20010622 LPRng + tetex tmpfile race - uid lp exploit + + + IMMUNIX + IMNX-2001-70-030-01 + + teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.4.10 + + CVE-2001-0907 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:09:12.147-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3444 + + + SUSE + SuSE-SA:2001:036 + + + ENGARDE + ESA-20011019-02 + + + MANDRAKE + MDKSA-2001:082 + + + XF + linux-multiple-symlink-dos(7312) + + + BUGTRAQ + 20011019 TSLSA-2001-0028 + + + BUGTRAQ + 20011018 Flaws in recent Linux kernels + + + MANDRAKE + MDKSA-2001:079 + + + IMMUNIX + IMNX-2001-70-035-01 + + + CALDERA + CSSA-2001-036.0 + + Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link. + + + + + + + + + cpe:/a:citrix:metaframe:1.8 + + CVE-2001-0908 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:12.503-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + win-terminal-spoof-address(7538) + + + BID + 3566 + + + BUGTRAQ + 20011121 CITRIX & Microsoft Windows Terminal Services False IP Address Vulnerability + + CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT). + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + + CVE-2001-0909 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:12.643-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + winxp-helpctr-bo(7605) + + + BID + 6802 + + + BUGTRAQ + 20011121 Buffer overflow in Windows XP "helpctr.exe" + + Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL. + + + + + + + + + cpe:/a:emc:networker:6.0 + + CVE-2001-0910 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:12.783-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + networker-reverse-dns-bypass-auth(7601) + + + BID + 3564 + + + BUGTRAQ + 20011121 Legato Networker vulnerability + + Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup. + + + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.2 + cpe:/a:francisco_burzi:php-nuke:5.1 + cpe:/a:postnuke_software_foundation:postnuke:0.64 + cpe:/a:francisco_burzi:php-nuke:5.3.1 + + CVE-2001-0911 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:12.940-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + phpnuke-postnuke-insecure-passwords(7596) + + + BID + 3567 + + + BUGTRAQ + 20011121 PhpNuke Admin password can be stolen ! + + PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it. + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:8.1 + + CVE-2001-0912 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:25:13.080-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-expect-unauth-root(7604) + + + MANDRAKE + MDKSA-2001:087 + + Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges. + + + + + + + + + + + + + + + + + cpe:/a:network_solutions:rwhoisd:1.5.2 + cpe:/a:network_solutions:rwhoisd:1.5.3 + cpe:/a:network_solutions:rwhoisd:1.5.6 + cpe:/a:network_solutions:rwhoisd:1.5.1a + cpe:/a:network_solutions:rwhoisd:1.5.5 + cpe:/a:network_solutions:rwhoisd:1.5.7.2 + cpe:/a:network_solutions:rwhoisd:1.5.7 + cpe:/a:network_solutions:rwhoisd:1.5 + cpe:/a:network_solutions:rwhoisd:1.5.7.1 + + CVE-2001-0913 + 2001-11-22T00:00:00.000-05:00 + 2008-09-05T16:25:13.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html + + + BUGTRAQ + 20011122 [NetGuard Security] NSI Rwhoisd another Remote Format String Vulnerability + + Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.11:pre3 + cpe:/o:suse:suse_linux:7.3 + + CVE-2001-0914 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:13.393-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011122 Re: SuSE 7.3 : Kernel 2.4.10-4GB Bug + + + XF + linux-vmlinux-dos(7591) + + + BID + 3570 + + + BUGTRAQ + 20011121 SuSE 7.3 : Kernel 2.4.10-4GB Bug + + Linux kernel before 2.4.11pre3 in multiple Linux distributions allows local users to cause a denial of service (crash) by starting the core vmlinux kernel, possibly related to poor error checking during ELF loading. + + + + + + + + + cpe:/a:berkeley:pmake:2.1.33 + + CVE-2001-0915 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:13.533-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011121 Advisory: Berkeley pmake + + + BID + 3572 + + + XF + pmake-shell-format-string(7602) + + Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition. + + + + + + + + + cpe:/a:berkeley:pmake:2.1.33 + + CVE-2001-0916 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:13.690-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011121 Advisory: Berkeley pmake + + + BID + 3573 + + + XF + pmake-shell-bo(7603) + + Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition. + + + + + + + + + cpe:/a:apache:tomcat:4.0.1 + + CVE-2001-0917 + 2001-11-22T00:00:00.000-05:00 + 2008-09-05T16:25:13.830-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://marc.theaimsgroup.com/?l=tomcat-dev&m=100658457507305&w=2 + + + BUGTRAQ + 20011122 Hi + + + XF + tomcat-reveal-install-path(7599) + + Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension. + + + + + + + + + + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:7.3 + + CVE-2001-0918 + 2001-11-22T00:00:00.000-05:00 + 2008-09-10T15:09:13.523-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + susehelp-cgi-command-execution(7583) + + + BID + 3576 + + + SUSE + SuSE-SA:2001:041 + + Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by not opening files securely. + + + + + + + + + cpe:/a:microsoft:ie:5.5 + + CVE-2001-0919 + 2001-11-26T00:00:00.000-05:00 + 2008-09-05T16:25:14.127-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011126 Javascript can bypass user preference for cookie prompt in IE5.50.4134.0100 + + Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. + + + + + + + + + + + + + cpe:/a:patrick_schemitz:autonice_daemon:1.0.1 + cpe:/a:patrick_schemitz:autonice_daemon:1.0.0 + cpe:/a:patrick_schemitz:autonice_daemon:1.0.3 + cpe:/a:patrick_schemitz:autonice_daemon:1.0.2 + cpe:/a:patrick_schemitz:autonice_daemon:1.0.4 + + CVE-2001-0920 + 2001-11-26T00:00:00.000-05:00 + 2008-09-05T16:25:14.267-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + and-format-string(7606) + + + BID + 3580 + + + BUGTRAQ + 20011126 [CERT-intexxia] Auto Nice Daemon Format String Vulnerability + + + CONFIRM + http://and.sourceforge.net/ + + Format string vulnerability in auto nice daemon (AND) 1.0.4 and earlier allows a local user to possibly execute arbitrary code via a process name containing a format string. + + + + + + + + + cpe:/a:netscape:communicator:4.77::macos + + CVE-2001-0921 + 2001-11-21T00:00:00.000-05:00 + 2008-09-05T16:25:14.440-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + macos-netscape-print-passwords(7593) + + + BID + 3565 + + + BUGTRAQ + 20011121 Mac Netscape password fields + + + OSVDB + 5524 + + Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext. + + + + + + + + + + + + + cpe:/a:sun:netdynamics:4.1 + cpe:/a:sun:netdynamics:5.0 + cpe:/a:sun:netdynamics:4.0 + cpe:/a:sun:netdynamics:4.1.2 + cpe:/a:sun:netdynamics:4.1.3 + + CVE-2001-0922 + 2001-11-26T00:00:00.000-05:00 + 2008-09-05T16:25:14.580-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3583 + + + XF + netdynamics-session-hijacking(7620) + + + BUGTRAQ + 20011126 NMRC Advisory - NetDynamics Session ID is Reusable + + ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in. + + + + + + + + + + cpe:/a:redhat:redhat_package_manager:4.0.2-72 + cpe:/a:redhat:redhat_package_manager:4.0.2-71 + + CVE-2001-0923 + 2001-10-25T00:00:00.000-04:00 + 2008-09-05T16:25:14.737-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + Linux-rpm-execute-code(7349) + + + BID + 3472 + + + BUGTRAQ + 20011025 Advisory: Corrupt RPM Query Vulnerability + + + CONECTIVA + CLA-2001:440 + + RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried. + + + + + + + + + + + + + + + + cpe:/a:ibm:informix_web_datablade:4.12 + cpe:/a:ibm:informix_web_datablade:4.11 + cpe:/a:ibm:informix_web_datablade:4.10 + cpe:/a:ibm:informix_web_datablade:3.4 + cpe:/a:ibm:informix_web_datablade:3.3 + cpe:/a:ibm:informix_web_datablade:3.6 + cpe:/a:ibm:informix_web_datablade:3.5 + cpe:/a:ibm:informix_web_datablade:3.7 + + CVE-2001-0924 + 2001-11-22T00:00:00.000-05:00 + 2008-09-05T16:25:14.893-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3575 + + + XF + informix-web-datablade-directory-traversal(7585) + + + BUGTRAQ + 20011127 Re: double dot vulnerability on a site running Informix database. + + + BUGTRAQ + 20011122 double dot vulnerability on a site running Informix database. + + Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter. + + + + + + + + + cpe:/a:apache:http_server:1.3.19 + + CVE-2001-0925 + 2001-03-12T00:00:00.000-05:00 + 2008-09-05T16:25:15.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + apache-slash-directory-listing(6921) + + + BID + 2503 + + + BUGTRAQ + 20010312 FORW: [ANNOUNCE] Apache 1.3.19 Released + + + MANDRAKE + MDKSA-2001:077 + + + BUGTRAQ + 20010726 Apache Artificially Long Slash Path Directory Listing Vulnerabili ty -- FILE READ ACCESS + + + BUGTRAQ + 20010624 Fw: Bugtraq ID 2503 : Apache Artificially Long Slash Path Directory Listing Exploit + + + BUGTRAQ + 20010419 OpenBSD 2.8patched Apache vuln! + + + ENGARDE + ESA-20010620-02 + + + DEBIAN + DSA-067 + + + CONFIRM + http://www.apacheweek.com/features/security-13 + + The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. + + + + + + + + + + + cpe:/a:macromedia:jrun:2.3.3 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-0926 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:15.253-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3589 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full + + + BUGTRAQ + 20011128 JRun SSI Request Body Parsing + + + XF + allaire-jrun-view-source(7622) + + SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement. + + + + + + + + + + + + cpe:/a:gnome:libgtop_daemon:1.0.7 + cpe:/a:gnome:libgtop_daemon:1.0.9 + cpe:/a:gnome:libgtop_daemon:1.0.6 + cpe:/a:gnome:libgtop_daemon:1.0.12 + + CVE-2001-0927 + 2001-11-27T00:00:00.000-05:00 + 2008-09-10T15:09:15.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-098 + + + BUGTRAQ + 20011127 [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability + + Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions. + + + + + + + + + + + + + cpe:/a:gnome:libgtop_daemon:1.0.7 + cpe:/a:gnome:libgtop_daemon:1.0.9 + cpe:/a:gnome:libgtop_daemon:1.0.6 + cpe:/a:gnome:libgtop_daemon:1.0.13 + cpe:/a:gnome:libgtop_daemon:1.0.12 + + CVE-2001-0928 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:15.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#705771 + + + DEBIAN + DSA-301 + + + DEBIAN + DSA-098 + + + BID + 3594 + + + BUGTRAQ + 20011128 Re: [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability + + Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data. + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:11.3t + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:11.2p + + CVE-2001-0929 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:15.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#362483 + + + CISCO + 20011128 A Vulnerability in IOS Firewall Feature Set + + + XF + ios-cbac-bypass-acl(7614) + + + BID + 3588 + + + OSVDB + 808 + + + + + Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists. + + + + + + + + + cpe:/a:sendpage:sendpage.pl + + CVE-2001-0930 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:15.877-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + sendpage-message-command-execution(7609) + + + BUGTRAQ + 20011128 Sendpage (Perl CGI) Remote Execution Vulnerability + + Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters. + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + + CVE-2001-0931 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:16.017-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + powerftp-dot-directory-traversal(7615) + + + BID + 3593 + + + BUGTRAQ + 20011128 PowerFTP-server-Bugs&Exploits-Remotes + + Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET. + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + + CVE-2001-0932 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:16.160-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011128 PowerFTP-server-Bugs&Exploits-Remotes + + + XF + powerftp-long-command-dos(7616) + + + BID + 3595 + + Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command. + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + + CVE-2001-0933 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:16.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011128 PowerFTP-server-Bugs&Exploits-Remotes + + Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:". + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + + CVE-2001-0934 + 2001-11-28T00:00:00.000-05:00 + 2008-09-05T16:25:16.457-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011128 PowerFTP-server-Bugs&Exploits-Remotes + + Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname. + + + + + + + + + + + cpe:/a:washington_university:wu-ftpd:2.4 + cpe:/a:washington_university:wu-ftpd:2.6.0 + cpe:/a:washington_university:wu-ftpd:2.6.1 + + CVE-2001-0935 + 2001-11-28T00:00:00.000-05:00 + 2008-09-10T15:09:16.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SUSE + SuSE-SA:2001:043 + + Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550. + + + + + + + + + + + + + + + cpe:/a:frox:frox:0.6.0 + cpe:/a:frox:frox:0.6.1 + cpe:/a:frox:frox:0.6.2 + cpe:/a:frox:frox:0.6.3 + cpe:/a:frox:frox:0.6.4 + cpe:/a:frox:frox:0.6.5 + cpe:/a:frox:frox:0.6.6 + + CVE-2001-0936 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:25:16.737-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + frox-ftp-proxy-bo(7632) + + + BID + 3606 + + + BUGTRAQ + 20011130 Alert: Vulnerability in frox transparent ftp proxy. + + + CONFIRM + http://frox.sourceforge.net/security.txt + + Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an MDTM request. + + + + + + + + + cpe:/a:matt_wright:pgpmail.pl:1.31 + + CVE-2001-0937 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:25:16.910-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011130 Vulnerabilities in PGPMail.pl + + + VULN-DEV + 20011129 PGPMail.pl possible remote command execution + + PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters. + + + + + + + + + cpe:/a:persits:aspupload:2.1 + + CVE-2001-0938 + 2001-11-30T00:00:00.000-05:00 + 2008-09-10T15:09:17.227-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011130 Aspupload installs exploitable scripts + + + BID + 3608 + + + XF + aspupload-directory-browsing-download(7629) + + + XF + aspupload-upload-directory-traversal(7628) + + Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp. + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:5.0 + cpe:/a:lotus:domino:5.0.5 + cpe:/a:lotus:domino:5.0.4 + cpe:/a:lotus:domino:5.0.7 + cpe:/a:lotus:domino:5.0.6 + cpe:/a:lotus:domino:5.0.1 + cpe:/a:lotus:domino:5.0.3 + cpe:/a:lotus:domino:5.0.2 + + CVE-2001-0939 + 2001-11-30T00:00:00.000-05:00 + 2008-09-05T16:25:17.190-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3607 + + + CONFIRM + http://www-1.ibm.com/support/manager.wss?rs=0&rt=0&org=sims&doc=4C8E450DBF2E7F1885256B200079FA88 + + + BUGTRAQ + 20011130 Denial of Service in Lotus Domino 5.08 and earlier HTTP Server + + + XF + lotus-domino-nhttp-dos(7631) + + + OSVDB + 1998 + + Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443. + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + + CVE-2001-0940 + 2001-09-21T00:00:00.000-04:00 + 2008-09-05T16:25:17.347-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + WIN2KSEC + 20010921 Check Point FireWall-1 GUI Buffer Overflow + + + BUGTRAQ + 20011128 Firewall-1 remote SYSTEM shell buffer overflow + + + XF + fw1-log-viewer-bo(7145) + + + BID + 3336 + + + OSVDB + 1951 + + + CHECKPOINT + 20010919 GUI Buffer Overflow + + + BUGTRAQ + 20010919 Check Point FireWall-1 GUI Log Viewer vulnerability (vuldb 3336) + + + BUGTRAQ + 20011130 Fw: Firewall-1 remote SYSTEM shell buffer overflow + + Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name. + + + + + + + + + + + + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:oracle:database_server:8.1.6 + cpe:/a:oracle:database_server:9.0.1 + cpe:/a:oracle:database_server:8.0.6 + + CVE-2001-0941 + 2001-11-30T00:00:00.000-05:00 + 2008-09-10T15:09:17.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf + + + BUGTRAQ + 20011130 ASI Oracle Security Alert: Oracle Home Environment Variable Buffer Overflow + + + XF + oracle-dbsnmp-home-bo(7643) + + + BID + 3138 + + Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. + + + + + + + + + + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:oracle:database_server:8.1.6 + + CVE-2001-0942 + 2001-11-29T00:00:00.000-05:00 + 2008-09-10T15:09:17.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf + + + XF + oracle-dbsnmp-home-validation(7645) + + + BID + 3137 + + + BUGTRAQ + 20011130 ASI Oracle Security Alert: Oracle Home Environment Variable Validation Vulnerability + + dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp. + + + + + + + + + + cpe:/a:oracle:database_server:8.0.5 + cpe:/a:oracle:database_server:8.1.5 + + CVE-2001-0943 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:17.800-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3129 + + + BUGTRAQ + 20010801 Oracle 8.1.5 dbnsmp vulnerability + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf + + + BUGTRAQ + 20011130 ASI Oracle Security Alert: CHOWN Path Environment Variable Vulnerability + + dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs. + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc + + CVE-2001-0944 + 2001-12-02T00:00:00.000-05:00 + 2008-09-05T16:25:17.940-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011202 mIRC bug? + + DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process. + + + + + + + + + + + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook_express:5.0.1 + cpe:/a:microsoft:outlook_express:5.0.2 + + CVE-2001-0945 + 2001-12-03T00:00:00.000-05:00 + 2008-09-05T16:25:18.097-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011203 Buffer over flow on Outlook express for Macintosh + + + BID + 3611 + + + XF + macos-outlook-long-message-bo(7648) + + Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. + + + + + + + + + cpe:/o:redhat:linux:7.2 + + CVE-2001-0946 + 2001-12-04T00:00:00.000-05:00 + 2008-09-05T16:25:18.237-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=56389 + + + BUGTRAQ + 20011204 Symlink attack with apmd of RH 7.2 + + + XF + apmd-apmscript-symlink(8268) + + + OSVDB + 5493 + + apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins. + + + + + + + + + + + + + + + + + + + cpe:/a:valicert:enterprise_validation_authority:4.2.1 + cpe:/a:valicert:enterprise_validation_authority:3.3 + cpe:/a:valicert:enterprise_validation_authority:3.4 + cpe:/a:valicert:enterprise_validation_authority:4.0 + cpe:/a:valicert:enterprise_validation_authority:3.5 + cpe:/a:valicert:enterprise_validation_authority:4.1 + cpe:/a:valicert:enterprise_validation_authority:3.6 + cpe:/a:valicert:enterprise_validation_authority:4.2 + cpe:/a:valicert:enterprise_validation_authority:3.7 + cpe:/a:valicert:enterprise_validation_authority:3.8 + cpe:/a:valicert:enterprise_validation_authority:3.9 + + CVE-2001-0947 + 2001-12-04T00:00:00.000-05:00 + 2008-09-05T16:25:18.393-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eva-forms-reveal-path(7649) + + + BID + 3615 + + + CONFIRM + http://www.valicert.com/support/security_advisory_eva.html + + + BUGTRAQ + 20011204 NMRC Advisory - Multiple Valicert Problems + + Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path. + + + + + + + + + + + + + + + + + + + cpe:/a:valicert:enterprise_validation_authority:4.2.1 + cpe:/a:valicert:enterprise_validation_authority:3.3 + cpe:/a:valicert:enterprise_validation_authority:3.4 + cpe:/a:valicert:enterprise_validation_authority:4.0 + cpe:/a:valicert:enterprise_validation_authority:3.5 + cpe:/a:valicert:enterprise_validation_authority:4.1 + cpe:/a:valicert:enterprise_validation_authority:3.6 + cpe:/a:valicert:enterprise_validation_authority:4.2 + cpe:/a:valicert:enterprise_validation_authority:3.7 + cpe:/a:valicert:enterprise_validation_authority:3.8 + cpe:/a:valicert:enterprise_validation_authority:3.9 + + CVE-2001-0948 + 2001-12-04T00:00:00.000-05:00 + 2008-09-05T16:25:18.550-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eva-admin-script-injection(7650) + + + BID + 3619 + + + CONFIRM + http://www.valicert.com/support/security_advisory_eva.html + + + BUGTRAQ + 20011204 NMRC Advisory - Multiple Valicert Problems + + Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed. + + + + + + + + + + + + + + + + + + + cpe:/a:valicert:enterprise_validation_authority:4.2.1 + cpe:/a:valicert:enterprise_validation_authority:3.3 + cpe:/a:valicert:enterprise_validation_authority:3.4 + cpe:/a:valicert:enterprise_validation_authority:4.0 + cpe:/a:valicert:enterprise_validation_authority:3.5 + cpe:/a:valicert:enterprise_validation_authority:4.1 + cpe:/a:valicert:enterprise_validation_authority:3.6 + cpe:/a:valicert:enterprise_validation_authority:4.2 + cpe:/a:valicert:enterprise_validation_authority:3.7 + cpe:/a:valicert:enterprise_validation_authority:3.8 + cpe:/a:valicert:enterprise_validation_authority:3.9 + + CVE-2001-0949 + 2001-12-04T00:00:00.000-05:00 + 2008-09-05T16:25:18.720-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eva-forms-bo(7652) + + + BID + 3621 + + + CONFIRM + http://www.valicert.com/support/security_advisory_eva.html + + + BID + 3636 + + + BID + 3635 + + + BID + 3634 + + + BID + 3633 + + + BID + 3632 + + + BID + 3631 + + + BID + 3630 + + + BID + 3629 + + + BID + 3628 + + + BID + 3627 + + + BID + 3625 + + + BID + 3624 + + + BID + 3622 + + + BUGTRAQ + 20011204 NMRC Advisory - Multiple Valicert Problems + + Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length. + + + + + + + + + + + + + + + + + + + cpe:/a:valicert:enterprise_validation_authority:4.2.1 + cpe:/a:valicert:enterprise_validation_authority:3.3 + cpe:/a:valicert:enterprise_validation_authority:3.4 + cpe:/a:valicert:enterprise_validation_authority:4.0 + cpe:/a:valicert:enterprise_validation_authority:3.5 + cpe:/a:valicert:enterprise_validation_authority:4.1 + cpe:/a:valicert:enterprise_validation_authority:3.6 + cpe:/a:valicert:enterprise_validation_authority:4.2 + cpe:/a:valicert:enterprise_validation_authority:3.7 + cpe:/a:valicert:enterprise_validation_authority:3.8 + cpe:/a:valicert:enterprise_validation_authority:3.9 + + CVE-2001-0950 + 2001-12-04T00:00:00.000-05:00 + 2008-09-05T16:25:18.893-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eva-insecure-key-generation(7653) + + + XF + eva-insecure-key-storage(7651) + + + BID + 3620 + + + BID + 3618 + + + CONFIRM + http://www.valicert.com/support/security_advisory_eva.html + + + BUGTRAQ + 20011204 NMRC Advisory - Multiple Valicert Problems + + ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-0951 + 2001-12-07T00:00:00.000-05:00 + 2008-09-05T16:25:19.050-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011211 UDP DoS attack in Win2k via IKE + + + BUGTRAQ + 20011207 UDP DoS attack in Win2k via IKE + + + XF + win2k-ike-dos(7667) + + + BID + 3652 + + Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters. + + + + + + + + + + cpe:/a:volition:red_faction:1.1 + cpe:/a:volition:red_faction:1.0 + + CVE-2001-0952 + 2001-12-07T00:00:00.000-05:00 + 2008-09-05T16:25:19.207-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + red-faction-udp-dos(7672) + + + BID + 3651 + + + BUGTRAQ + 20011207 Red Faction Server/Client DOS + + THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755. + + + + + + + + + + cpe:/a:nara_vision:kebi_community:1.0_enterprise + cpe:/a:nara_vision:kebi_community:1.0_academy + + CVE-2001-0953 + 2001-12-08T00:00:00.000-05:00 + 2008-09-05T16:25:19.347-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011208 kebi-Webmail Solution vulnerability (Tested) + + + XF + kebi-webmail-admin-dir-access(7674) + + + BID + 3655 + + Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root. + + + + + + + + + + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:5.0.5 + + CVE-2001-0954 + 2001-12-07T00:00:00.000-05:00 + 2008-09-05T16:25:19.487-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-database-dos(7684) + + + BID + 3656 + + + BUGTRAQ + 20011207 Lotus Domino Web server vulnerability + + + OSVDB + 2000 + + + CONFIRM + http://www-1.ibm.com/support/manager.wss?rs=1&rt=0&org=sims&doc=255CC03D83CFF50C85256B1E005E349B + + Lotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have not been previously accessed) via a URL that includes the . (dot) directory. + + + + + + + + + + + cpe:/a:xfree86_project:x11r6:4.0 + cpe:/a:xfree86_project:x11r6:4.0.1 + cpe:/a:xfree86_project:x11r6:4.0.3 + + CVE-2001-0955 + 2001-09-22T00:00:00.000-04:00 + 2008-09-05T16:25:19.643-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3657 + + + XF + xfree86-xterm-title-bo(7683) + + + XF + xfree86-konqueror-bo(7673) + + + CONFIRM + http://www.xfree86.org/security/ + + + CONFIRM + http://www.xfree86.org/4.2.0/RELNOTES2.html#2 + + + BID + 3663 + + + VULN-DEV + 20010922 XFree86 DOS / Buffer overflow local and remote. + + + BUGTRAQ + 20011207 Crashing X + + + MISC + http://cvsweb.xfree86.org/cvsweb/xc/programs/Xserver/fb/fbglyph.c + + + BUGTRAQ + 20011208 Re: Crashing X + + Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title. + + + + + + + + + cpe:/a:speechio:speechd:0.54 + + CVE-2001-0956 + 2001-09-11T00:00:00.000-04:00 + 2008-09-05T16:25:19.800-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + speechd-execute-commands(7121) + + + BID + 3326 + + + BUGTRAQ + 20010911 security alert: speechd from speechio.org + + + CONFIRM + http://www.speechio.org/speechd.html + + speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + + + + + cpe:/a:trend_micro:interscan_emanager:3.51_j + cpe:/a:trend_micro:interscan_emanager:3.51 + cpe:/a:trend_micro:interscan_viruswall:3.32 + cpe:/a:trend_micro:interscan_viruswall:3.3 + cpe:/a:trend_micro:interscan_viruswall:3.2.3 + cpe:/a:trend_micro:interscan_viruswall:3.0.1 + + CVE-2001-0958 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:19.940-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + interscan-emanager-bo(7104) + + + BID + 3327 + + + BUGTRAQ + 20010912 [SNS Advisory No.42] Trend Micro InterScan eManager for NT Multiple Program Buffer Overflow Vulnerability + + + MISC + http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=3142 + + Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll, (6) SpamExcp.dll, and (7) spamrule.dll. + + + + + + + + + + + cpe:/a:ca:arcserve_backup_2000 + cpe:/a:ca:arcserve_backup:6.61:sp2a + cpe:/a:ca:arcserve_backup_2000:::advanced + + CVE-2001-0959 + 2001-09-15T00:00:00.000-04:00 + 2008-09-05T16:25:20.113-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3342 + + + MISC + http://support.ca.com/Download/patches/asitnt/QO00945.html + + + BUGTRAQ + 20010915 ARCserve 6.61 Share Access Vulnerability + + + XF + arcserve-aremote-plaintext(7122) + + + OSVDB + 5483 + + Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files. + + + + + + + + + + + cpe:/a:ca:arcserve_backup_2000 + cpe:/a:ca:arcserve_backup:6.61:sp2a + cpe:/a:ca:arcserve_backup_2000:::advanced + + CVE-2001-0960 + 2001-09-15T00:00:00.000-04:00 + 2008-09-10T15:09:20.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3343 + + + MISC + http://support.ca.com/Download/patches/asitnt/QO00945.html + + + BUGTRAQ + 20010915 ARCserve 6.61 Share Access Vulnerability + + + XF + arcserve-aremote-plaintext(7122) + + Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges. + + + + + + + + + + + + + + + cpe:/a:john_e._davis:most:4.6 + cpe:/a:john_e._davis:most:4.7 + cpe:/a:john_e._davis:most:4.9.0 + cpe:/a:john_e._davis:most:4.9.1 + cpe:/a:john_e._davis:most:4.41 + cpe:/a:john_e._davis:most:4.5 + cpe:/a:john_e._davis:most:4.4 + + CVE-2001-0961 + 2001-09-18T00:00:00.000-04:00 + 2008-09-05T16:25:20.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + most-file-create-bo(7149) + + + BID + 3347 + + + DEBIAN + DSA-076 + + Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most. + + + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.5.3 + cpe:/a:ibm:websphere_commerce_suite:3.1.2 + cpe:/a:ibm:websphere_commerce_suite:3.2 + + CVE-2001-0962 + 2001-09-19T00:00:00.000-04:00 + 2011-03-07T21:06:24.033-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ibm-websphere-seq-predict(7153) + + + BUGTRAQ + 20010928 Re: Websphere cookie/sessionid predictable + + + CONFIRM + http://www14.software.ibm.com/webapp/download/postconfig.jsp?id=4000805&pf=Multi-Platform&v=3.0.2&e=Standard+%26+Advanced+Editions&cat=&s=p + + + OSVDB + 5492 + + IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing. + + + + + + + + + cpe:/a:pi-soft:spoonftp:1.1 + + CVE-2001-0963 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:25:20.720-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + spoonftp-dot-directory-traversal(7147) + + + CONFIRM + http://www.pi-soft.com/spoonftp/index.shtml + + + BUGTRAQ + 20010920 Vulnerability in SpoonFTP + + + BID + 3351 + + + OSVDB + 1953 + + Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command. + + + + + + + + + cpe:/a:valve_software:half-life:1.1.0.8 + + CVE-2001-0964 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:25:20.877-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + halflife-connect-bo(7148) + + + BUGTRAQ + 20010920 Advisory: Half-Life remote buffer overflow vulnerability + + Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command. + + + + + + + + + + + + + + + + + cpe:/a:glftpd:glftpd:1.22b + cpe:/a:glftpd:glftpd:1.19 + cpe:/a:glftpd:glftpd:1.13.6 + cpe:/a:glftpd:glftpd:1.18a + cpe:/a:glftpd:glftpd:1.20 + cpe:/a:glftpd:glftpd:1.16.9 + cpe:/a:glftpd:glftpd:1.17.2 + cpe:/a:glftpd:glftpd:1.21 + cpe:/a:glftpd:glftpd:1.23 + + CVE-2001-0965 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.017-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3201 + + + BUGTRAQ + 20010817 [ASGUARD-LABS] glFTPD v1.23 DOS Attack + + + CONFIRM + http://www.glftpd.org/ + + + XF + glftpd-list-dos(7001) + + glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters. + + + + + + + + + cpe:/a:nudester.org:nudester:1.10 + + CVE-2001-0966 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.173-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3202 + + + BUGTRAQ + 20010818 [Real Security] Advisory for Nudester 1.10 + + Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command. + + + + + + + + + + cpe:/a:knox_software:arkeia:4.2 + cpe:/a:knox_software:arkeia:4.2.8.2 + + CVE-2001-0967 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3204 + + + BUGTRAQ + 20010817 Arkeia Possible remote root & information leakage + + Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing. + + + + + + + + + + cpe:/a:knox_software:arkeia:4.2 + cpe:/a:knox_software:arkeia:4.2.8.2 + + CVE-2001-0968 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.470-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3203 + + + BUGTRAQ + 20010817 Arkeia Possible remote root & information leakage + + Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges. + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + + CVE-2001-0969 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.610-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ipfw-me-unauthorized-access(7002) + + + BID + 3206 + + + FREEBSD + FreeBSD-SA-01:53 + + + OSVDB + 1937 + + ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts. + + + + + + + + + cpe:/a:tdavid:td_forum:1.2 + + CVE-2001-0970 + 2001-08-31T00:00:00.000-04:00 + 2014-12-02T21:59:13.903-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#782243 + + + BID + 3207 + + + BUGTRAQ + 20010820 tdforum 1.2 Messageboard + + + BUGTRAQ + 20010820 Re: tdforum 1.2 Messageboard + + Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script. + + + + + + + + + cpe:/a:aci:4d_webserver:6.5.7 + + CVE-2001-0971 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:21.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3209 + + + BUGTRAQ + 20010820 ACI 4D WebServer Directory traversal. + + + XF + 4d-webserver-directory-traversal(7010) + + Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request. + + + + + + + + + + cpe:/a:surf-net:asp_forum:2.20 + cpe:/a:surf-net:asp_forum:2.30 + + CVE-2001-0972 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:22.050-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3210 + + + BUGTRAQ + 20010820 security problem in surf-net ASP Discussion Forum < 2.30 + + + XF + surfnet-asp-cookie-seq-predictable(7011) + + Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888." + + + + + + + + + + + + + + cpe:/a:fraunhofer_fit:bscw:3.3 + cpe:/a:fraunhofer_fit:bscw:3.4.3 + cpe:/a:fraunhofer_fit:bscw:3.4.1 + cpe:/a:fraunhofer_fit:bscw:3.3.1 + cpe:/a:fraunhofer_fit:bscw:4.0.2_beta + cpe:/a:fraunhofer_fit:bscw:4.0.1_beta + + CVE-2001-0973 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:22.190-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#465971 + + + CONFIRM + http://bscw.gmd.de/Bulletins/BSCW-SB-2001-08.extract.txt + + + BUGTRAQ + 20010822 BSCW symlink vulnerability + + + BID + 3227 + + + XF + bscw-extracted-file-symlink(7029) + + BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space. + + + + + + + + + + cpe:/a:oracle:internet_directory:2.1.1 + cpe:/a:oracle:internet_directory:3.0.1 + + CVE-2001-0974 + 2001-07-17T00:00:00.000-04:00 + 2008-09-05T16:25:22.347-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#869184 + + + CERT + CA-2001-18 + + + XF + oracle-ldap-protos-format-string(6903) + + + BID + 3048 + + + CIAC + L-116 + + Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + cpe:/a:oracle:internet_directory:2.1.1 + cpe:/a:oracle:internet_directory:3.0.1 + + CVE-2001-0975 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:25:22.503-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#869184 + + + CERT + CA-2001-18 + + + XF + oracle-ldap-protos-bo(6902) + + + BID + 3047 + + + CIAC + L-116 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf + + Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:hp:process_resource_manager:c.01.08.2 + + CVE-2001-0976 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:22.643-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX0108-165 + + Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:openldap:openldap:1.2 + cpe:/a:openldap:openldap:1.2.12 + cpe:/a:openldap:openldap:1.1 + cpe:/a:openldap:openldap:1.2.9 + cpe:/a:openldap:openldap:1.0 + cpe:/a:openldap:openldap:1.2.8 + cpe:/a:openldap:openldap:1.2.7 + cpe:/a:openldap:openldap:1.2.10 + cpe:/a:openldap:openldap:1.2.11 + cpe:/a:openldap:openldap:2.0.4 + cpe:/a:openldap:openldap:2.0.5 + cpe:/a:openldap:openldap:2.0 + cpe:/a:openldap:openldap:2.0.6 + cpe:/a:openldap:openldap:2.0.7 + cpe:/a:openldap:openldap:2.0.1 + cpe:/a:openldap:openldap:2.0.2 + cpe:/a:openldap:openldap:2.0.3 + cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2 + cpe:/a:openldap:openldap:1.2.1 + cpe:/a:openldap:openldap:1.2.2 + cpe:/a:openldap:openldap:1.2.5 + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/a:openldap:openldap:1.2.6 + cpe:/a:openldap:openldap:1.2.3 + cpe:/a:openldap:openldap:1.2.4 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.0 + cpe:/a:openldap:openldap:1.1.1 + cpe:/a:openldap:openldap:1.1.3 + cpe:/a:openldap:openldap:1.1.2 + cpe:/a:openldap:openldap:1.1.4 + cpe:/o:debian:debian_linux:2.2 + cpe:/a:openldap:openldap:1.0.2 + cpe:/a:openldap:openldap:1.0.1 + cpe:/a:openldap:openldap:1.0.3 + + CVE-2001-0977 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:25:22.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#935800 + + + CERT + CA-2001-18 + + + XF + openldap-ldap-protos-dos(6904) + + + BID + 3049 + + + MANDRAKE + MDKSA-2001:069 + + + REDHAT + RHSA-2001:098 + + + OSVDB + 1905 + + + DEBIAN + DSA-068 + + + CONECTIVA + CLA-2001:417 + + slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field. + + + + + + + + + cpe:/o:hp:hp-ux:10.26 + + CVE-2001-0978 + 2001-09-03T00:00:00.000-04:00 + 2008-09-05T16:25:23.033-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3289 + + + HPBUG + PHCO_17719 + + + XF + hpux-login-btmp(8632) + + login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program. + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-0979 + 2001-09-03T00:00:00.000-04:00 + 2008-09-05T16:25:23.173-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hpux-swverify-bo(7078) + + + BID + 3279 + + + BUGTRAQ + 20010903 hpux warez + + Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument. + + + + + + + + + + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/a:caldera:openlinux_server:3.1 + + CVE-2001-0980 + 2001-07-17T00:00:00.000-04:00 + 2008-09-05T16:25:23.330-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + docview-httpd-command-execution(6854) + + + CALDERA + CSSA-2001-026.0 + + + BID + 3052 + + docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page. + + + + + + + + + cpe:/a:hp:cifs-9000_server:a.01.07 + + CVE-2001-0981 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:09:24.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + HP + HPSBUX0108-164 + + + XF + hp-cifs-change-passwords(7051) + + HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user. + + + + + + + + + + + + cpe:/a:ibm:tivoli_secureway_policy_director:3.7.1 + cpe:/a:ibm:tivoli_secureway_policy_director:3.6 + cpe:/a:ibm:tivoli_secureway_policy_director:3.0.1 + cpe:/a:ibm:tivoli_secureway_policy_director:3.7 + + CVE-2001-0982 + 2001-07-23T00:00:00.000-04:00 + 2008-09-05T16:25:23.610-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tivoli-secureway-dot-directory-traversal(6884) + + + BID + 3080 + + + BUGTRAQ + 20010723 iXsecurity.20010618.policy_director.a + + + CONFIRM + ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README + + + OSVDB + 1908 + + + AIXAPAR + IY18152 + + Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings. + + + + + + + + + cpe:/a:ultraedit:ultraedit-32 + + CVE-2001-0983 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T00:00:00.000-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.eve-software.com/security/ueditpw.html + + + BUGTRAQ + 20010823 Re: Respondus v1.1.2 stores passwords using weak encryption + + UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges. + + + + + + + + + cpe:/a:counterpane:password_safe:1.7.1 + + CVE-2001-0984 + 2001-09-13T00:00:00.000-04:00 + 2008-09-05T16:25:23.907-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + counterpane-password-access(7123) + + + BID + 3337 + + + BUGTRAQ + 20010913 leak of information in counterpane/Bruce Schneier's Password Safe program + + Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and promp on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords. + + + + + + + + + cpe:/a:hassan_consulting:shopping_cart:1.23 + + CVE-2001-0985 + 2001-09-08T00:00:00.000-04:00 + 2008-09-05T16:25:24.050-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.irata.com/shopver.html + + + XF + hassan-cart-command-execution(7106) + + + BID + 3308 + + + BUGTRAQ + 20010908 Shopping Cart Version 1.23 + + shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. + + + + + + + + + cpe:/a:microsoft:index_server:2.0 + + CVE-2001-0986 + 2001-09-14T00:00:00.000-04:00 + 2008-09-05T16:25:24.207-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010914 Security Vulnerability with Microsoft Index Server 2.0(Sample file reveals file info, physical path etc) + + + XF + winnt-indexserver-sqlqhit-asp(7125) + + + BID + 3339 + + SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo. + + + + + + + + + cpe:/a:nathan_neulinger:cgiwrap:3.7 + + CVE-2001-0987 + 2001-07-22T00:00:00.000-04:00 + 2008-09-05T16:25:24.347-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cgiwrap-cross-site-scripting(6886) + + + BID + 3084 + + + CONFIRM + http://cgiwrap.sourceforge.net/changes.html + + + BUGTRAQ + 20010722 Re: [cgiwrap-users] Re: Security hole in CGIWrap (cross-site scripting vulnerability) + + + OSVDB + 1909 + + Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap. + + + + + + + + + cpe:/a:knox_software:arkeia:4.2.8.2 + + CVE-2001-0988 + 2001-07-23T00:00:00.000-04:00 + 2008-09-05T16:25:24.487-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + arkeia-insecure-file-permissions(6885) + + + BID + 3085 + + + BUGTRAQ + 20010723 permission probs with Arkeia + + Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information. + + + + + + + + + cpe:/a:richard_everitt:pileup:1.1 + + CVE-2001-0989 + 2001-07-23T00:00:00.000-04:00 + 2008-09-05T16:25:24.627-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3086 + + + BUGTRAQ + 20010723 pileup 1.2 + + + CONFIRM + http://www.babbage.demon.co.uk/linux/pileup-1.2/pileup-1.2.tar.gz + + Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:inter7:vpopmail:3.4.10 + cpe:/a:inter7:vpopmail:3.4.11 + cpe:/a:inter7:vpopmail:3.4.9 + cpe:/a:inter7:vpopmail:3.4.8 + cpe:/a:inter7:vpopmail:3.4.6 + cpe:/a:inter7:vpopmail:3.4.7 + cpe:/a:inter7:vpopmail:3.4.4 + cpe:/a:inter7:vpopmail:3.4.5 + cpe:/a:inter7:vpopmail:3.4.2 + cpe:/a:inter7:vpopmail:3.4.3 + cpe:/a:inter7:vpopmail:3.4.1 + cpe:/a:inter7:vpopmail:4.5 + cpe:/a:inter7:vpopmail:3.4.11e + cpe:/a:inter7:vpopmail:4.6 + cpe:/a:inter7:vpopmail:4.7 + cpe:/a:inter7:vpopmail:4.9.10 + cpe:/a:inter7:vpopmail:4.8 + cpe:/a:inter7:vpopmail:4.9 + + CVE-2001-0990 + 2001-09-04T00:00:00.000-04:00 + 2008-09-05T16:25:24.783-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010904 BUZ.CH Security Advisory 200109041: Inter7 vpopmail DB pw problem + + + XF + vpopmail-insecure-auth-data(7076) + + + BID + 3284 + + + MISC + http://www.inter7.com/vpopmail/ChangeLog + + Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library. + + + + + + + + + + + + cpe:/a:scott_r._lemmon:proxomitron_naoko-4:beta2 + cpe:/a:scott_r._lemmon:proxomitron_naoko-4:beta3 + cpe:/a:scott_r._lemmon:proxomitron_naoko-4:beta1 + cpe:/a:scott_r._lemmon:proxomitron_naoko-4:beta4 + + CVE-2001-0991 + 2001-07-24T00:00:00.000-04:00 + 2008-09-05T16:25:24.957-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + proxomitron-cross-site-scripting(6887) + + + BID + 3087 + + + BUGTRAQ + 20010724 Proxomitron Cross-site Scripting Vulnerability + + Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message. + + + + + + + + + cpe:/a:kabotie_software_technologies:shopplus_cart + + CVE-2001-0992 + 2001-09-05T00:00:00.000-04:00 + 2008-09-05T16:25:25.110-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + shopplus-command-execution(7077) + + + BUGTRAQ + 20010905 ShopPlus Cart + + shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter. + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2001-0993 + 2001-07-24T00:00:00.000-04:00 + 2008-09-05T16:25:25.313-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-kernel-sendmsg-dos(6908) + + + BID + 3088 + + + NETBSD + NetBSD-SA2001-011 + + + OSVDB + 1910 + + sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length. + + + + + + + + + cpe:/a:marconi:forethought:7.1 + + CVE-2001-0994 + 2001-09-04T00:00:00.000-04:00 + 2008-09-05T16:25:25.470-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + forethought-telnet-dos(7082) + + + BID + 3286 + + + BUGTRAQ + 20010904 Telnet DoS Vulnerability in Marconi ATM Switch Software + + Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device. + + + + + + + + + + + + + + + cpe:/a:phpprojekt:phpprojekt:2.0.1 + cpe:/a:phpprojekt:phpprojekt:2.1 + cpe:/a:phpprojekt:phpprojekt:2.4a + cpe:/a:phpprojekt:phpprojekt:2.0 + cpe:/a:phpprojekt:phpprojekt:2.1a + cpe:/a:phpprojekt:phpprojekt:2.3 + cpe:/a:phpprojekt:phpprojekt:2.2 + + CVE-2001-0995 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:25.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phprojekt-id-modify(7035) + + + BID + 3239 + + + BUGTRAQ + 20010826 security hole in os groupware suite PHProjekt + + + MISC + http://www.phprojekt.com/ChangeLog + + PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs. + + + + + + + + + + cpe:/a:pop3lite:pop3lite:0.2.3b + cpe:/a:pop3lite:pop3lite:0.2.3 + + CVE-2001-0996 + 2001-09-02T00:00:00.000-04:00 + 2008-09-05T16:25:25.783-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pop3lite-dot-message-injection(7075) + + + BID + 3278 + + + BUGTRAQ + 20010902 POP3Lite 0.2.3b minor client side DoS and message injection + + POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise behave unexpectedly. + + + + + + + + + cpe:/a:textor_webmasters_ltd.:listrec.pl:1.0 + + CVE-2001-0997 + 2001-09-11T00:00:00.000-04:00 + 2008-09-05T16:25:25.923-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + listrecpl-remote-command-execution(7117) + + + BUGTRAQ + 20010911 Textor Webmasters Ltd (listrec.pl) + + Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter. + + + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/a:ibm:hacmp:4.4 + cpe:/o:ibm:aix:5.1 + cpe:/o:ibm:aix:4.3.3 + + CVE-2001-0998 + 2001-09-24T00:00:00.000-04:00 + 2008-09-05T16:25:26.063-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hacmp-portscan-dos(7165) + + + BID + 3358 + + + BUGTRAQ + 20011002 Vulnerability 3358, "IBM HACMP Port Scan Denial of Service Vulnerability" + + + BUGTRAQ + 20010924 HACMP and port scans + + + AIXAPAR + IY20943 + + + AIXAPAR + IY17630 + + IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd. + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + + CVE-2001-0999 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:26.220-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + outlook-express-text-script-execution(7118) + + + BID + 3334 + + + BUGTRAQ + 20010915 Proof-Of-Concept Perl Script for Bugtraq-ID: #3334 + + + BUGTRAQ + 20010912 FREAK SHOW: Outlook Express 6.00 + + Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script. + + + + + + + + + + cpe:/a:merit:aaa_radius_server:5.01 + cpe:/a:merit:aaa_radius_server:3.8m + + CVE-2001-1000 + 2001-09-07T00:00:00.000-04:00 + 2008-09-05T16:25:26.360-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + radius-rlmadmin-help-symlink(7096) + + + BID + 3302 + + + BUGTRAQ + 20010907 rlmadmin v3.8M view file symlink vulnerability + + rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file. + + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.0 + + CVE-2001-1002 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:26.517-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3241 + + + REDHAT + RHSA-2001:102 + + + BUGTRAQ + 20010827 LPRng/rhs-printfilters - remote execution of commands + + + XF + dvips-lpd-command-execution(16509) + + The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands. + + + + + + + + + cpe:/a:webct:respondus:1.1.2 + + CVE-2001-1003 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:09:30.680-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010823 Respondus v1.1.2 stores passwords using weak encryption + + Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges. + + + + + + + + + cpe:/a:gnutella:gnutella_client:0.4.27 + + CVE-2001-1004 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:26.813-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010830 gnut gnutella client html injection + + Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags. + + + + + + + + + cpe:/a:starfish:truesync_desktop:2.0b + + CVE-2001-1005 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:26.957-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities + + + BID + 3231 + + Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges. + + + + + + + + + cpe:/a:starfish:truesync_desktop:2.0b + + CVE-2001-1006 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:27.097-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities + + + BID + 3232 + + Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application. + + + + + + + + + cpe:/a:starfish:truesync_desktop:2.0b + + CVE-2001-1007 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:27.253-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities + + Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack. + + + + + + + + + + cpe:/a:sun:jre:1.3.0 + cpe:/a:sun:java_plug-in:1.4 + + CVE-2001-1008 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:27.393-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3245 + + + BUGTRAQ + 20010824 Java Plugin 1.4 with JRE 1.3 -> Ignores certificates. + + + XF + javaplugin-jre-expired-certificate(7048) + + Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.9.0 + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.8.13 + cpe:/a:fetchmail:fetchmail:5.8.11 + cpe:/a:fetchmail:fetchmail:5.8.14 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.6 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2001-1009 + 2001-08-31T00:00:00.000-04:00 + 2011-02-16T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 3166 + + + BID + 3164 + + + REDHAT + RHSA-2001:103 + + + ENGARDE + ESA-20010816-01 + + + BUGTRAQ + 20010809 Fetchmail security advisory + + + SUSE + SuSE-SA:2001:026 + + + MANDRAKE + MDKSA-2001:072 + + + XF + fetchmail-signed-integer-index(6965) + + + DEBIAN + DSA-071 + + + CONECTIVA + CLA-2001:419 + + Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request. + + + + + + + + + + + + + cpe:/a:sambar:sambar_server:4.4 + cpe:/a:sambar:sambar_server:5.0:beta1 + cpe:/a:sambar:sambar_server:5.0:beta2 + cpe:/a:sambar:sambar_server:5.0:beta3 + cpe:/a:sambar:sambar_server:5.0:beta4 + + CVE-2001-1010 + 2001-07-22T00:00:00.000-04:00 + 2008-09-05T16:25:27.707-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sambar-pagecount-overwrite-files(6916) + + + BID + 3092 + + + CONFIRM + http://www.sambar.com/security.htm + + + BUGTRAQ + 20010721 Sambar Web Server pagecount exploit code + + Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter. + + + + + + + + + + + + + + cpe:/a:mambo:mambo_site_server:3.0.5 + cpe:/a:mambo:mambo_site_server:3.0.3 + cpe:/a:mambo:mambo_site_server:3.0.4 + cpe:/a:mambo:mambo_site_server:3.0.1 + cpe:/a:mambo:mambo_site_server:3.0.2 + cpe:/a:mambo:mambo_site_server:3.0 + + CVE-2001-1011 + 2001-07-25T00:00:00.000-04:00 + 2008-09-05T16:25:27.860-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + mambo-phpsessid-gain-privileges(6910) + + + BID + 3093 + + + CONFIRM + http://prdownloads.sourceforge.net/mambo/mambov3.0.6.tar.gz + + + BUGTRAQ + 20010725 Serious security hole in Mambo Site Server version 3.0.X + + + OSVDB + 1911 + + index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters. + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2001-1012 + 2001-09-05T00:00:00.000-04:00 + 2008-09-10T15:09:31.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + screen-local-privilege-elevation(7134) + + + SUSE + SuSE-SA:2001:030 + + Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/. + + + + + + + + + cpe:/o:redhat:linux:7.0 + + CVE-2001-1013 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:28.173-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3335 + + + XF + linux-apache-username-exists(7129) + + + BUGTRAQ + 20010912 Is there user Anna at your host ? + + + VULN-DEV + 20000707 Re: your mail + + + VULN-DEV + 20000707 Re: apache and 404/404 status codes + + + VULN-DEV + 20000707 (no subject) + + Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server. + + + + + + + + + cpe:/a:michael_boehme:webdiscount_e_shop_online_shop_system:1.0 + + CVE-2001-1014 + 2001-09-15T00:00:00.000-04:00 + 2008-09-05T16:25:28.313-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eshop-script-execute-commands(7128) + + + BID + 3340 + + + BUGTRAQ + 20010915 advisory + + eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. + + + + + + + + + + cpe:/a:snes9x.com:snes9x:1.3.7 + cpe:/a:snes9x.com:snes9x:1.3.4 + + CVE-2001-1015 + 2001-10-16T00:00:00.000-04:00 + 2008-09-05T16:25:28.470-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3437 + + + BUGTRAQ + 20011016 [ ** Snes9x buffer overflow vulnerability ** ] + + Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument. + + + + + + + + + + + + + + + + cpe:/a:pgp:pgp:6.0.2 + cpe:/a:pgp:personal_security:7.0.3 + cpe:/a:pgp:corporate_desktop:7.1 + cpe:/a:pgp:e-business_server:7.1 + cpe:/a:pgp:pgp:5.0 + cpe:/a:pgp:freeware:7.0.3 + cpe:/a:pgp:e-business_server:7.0.4 + cpe:/a:pgp:e-business_server:6.5.8 + + CVE-2001-1016 + 2001-09-04T00:00:00.000-04:00 + 2008-09-05T16:25:28.610-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pgp-invalid-key-display(7081) + + + BID + 3280 + + + BUGTRAQ + 20010904 PGPsdk Key Validity Vulnerability + + + CONFIRM + http://www.pgp.com/support/product-advisories/pgpsdk.asp + + + OSVDB + 1946 + + PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability." + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + + CVE-2001-1017 + 2001-09-04T00:00:00.000-04:00 + 2008-09-05T16:25:28.783-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + rmuser-insecure-password-file(7086) + + + BID + 3282 + + + FREEBSD + FreeBSD-SA-01:59 + + + OSVDB + 1947 + + rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords. + + + + + + + + + cpe:/a:lotus:domino:5.0.8 + + CVE-2001-1018 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:25:28.923-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-ip-reveal(7180) + + + BID + 3350 + + + BUGTRAQ + 20010919 lotus domino server 5.08 is very gabby + + Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters. + + + + + + + + + cpe:/a:seaglass_technologies_inc.:sglmerchant:1.0 + + CVE-2001-1019 + 2001-09-08T00:00:00.000-04:00 + 2008-09-05T16:25:29.063-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sglmerchant-dot-directory-traversal(7100) + + + BID + 3309 + + + BUGTRAQ + 20010908 sglMerchant Version 1.0 + + Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter. + + + + + + + + + cpe:/a:vibechild:directory_manager:0.91 + + CVE-2001-1020 + 2001-09-05T00:00:00.000-04:00 + 2008-09-05T16:25:29.207-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + directory-manager-execute-commands(7079) + + + BID + 3288 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=51589 + + + BUGTRAQ + 20010905 directorymanager bug + + edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function. + + + + + + + + + cpe:/a:ipswitch:ws_ftp_server:2.0.2 + + CVE-2001-1021 + 2001-07-26T00:00:00.000-04:00 + 2008-09-05T16:25:29.360-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + wsftp-long-command-bo(6911) + + + MISC + http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html + + + BUGTRAQ + 20010726 def-2001-28 - WS_FTP server 2.0.2 Buffer Overflow and possible DOS + + Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD. + + + + + + + + + + + + + + + cpe:/a:gnu:groff:1.11a + cpe:/a:gnu:groff:1.10 + cpe:/a:gnu:groff:1.11 + cpe:/a:jgroff:jgroff + cpe:/a:gnu:groff:1.15 + cpe:/a:gnu:groff:1.14 + cpe:/a:gnu:groff:1.16.1 + + CVE-2001-1022 + 2001-07-26T00:00:00.000-04:00 + 2008-09-05T16:25:29.503-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-groff-format-string(6918) + + + BID + 3103 + + + BUGTRAQ + 20010727 ADV/EXP:pic/lpd remote exploit - RH 7.0 + + + DEBIAN + DSA-072 + + + REDHAT + RHSA-2002:004 + + + OSVDB + 1914 + + + DEBIAN + DSA-107 + + + CONECTIVA + CLA-2001:428 + + Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command. + + + + + + + + + + cpe:/a:xcache_technologies:xcache:2.1 + cpe:/a:xcache_technologies:xcache:2.0 + + CVE-2001-1023 + 2001-09-21T00:00:00.000-04:00 + 2008-09-05T16:25:29.657-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xcache-path-disclosure(7159) + + + BID + 3352 + + + BUGTRAQ + 20010921 IRM Security Advisory: Xcache Path Disclosure Vulnerability + + Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the Content-PageName header. + + + + + + + + + cpe:/a:entrust:getaccess + + CVE-2001-1024 + 2001-07-27T00:00:00.000-04:00 + 2008-09-05T16:25:29.813-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + entrust-getaccess-execute-commands(6915) + + + BUGTRAQ + 20010727 Entrust - getAccess + + login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument. + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.0 + cpe:/a:francisco_burzi:php-nuke:5.0.1 + + CVE-2001-1025 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:29.957-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3149 + + + VULNWATCH + 20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs) + + PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. + + + + + + + + + cpe:/a:trend_micro:interscan_applettrap:2.0 + + CVE-2001-1026 + 2001-07-09T00:00:00.000-04:00 + 2008-09-05T16:25:30.110-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + applettrap-zero-bypass-restrictions(6819) + + + XF + applettrap-bypass-ip-restrictions(6818) + + + XF + applettrap-unicode-bypass-filter(6817) + + + XF + content-slash-bypass-filter(6816) + + + BUGTRAQ + 20010709 Various problems in Ternd Micro AppletTrap URL filtering + + + BID + 3000 + + + BID + 2998 + + + BID + 2996 + + Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using a leading 0 in an octet of an IP address. + + + + + + + + + + + + + + + + cpe:/a:windowmaker:windowmaker:0.62.1 + cpe:/a:windowmaker:windowmaker:0.64 + cpe:/a:windowmaker:windowmaker:0.63.1 + cpe:/a:windowmaker:windowmaker:0.62 + cpe:/a:windowmaker:windowmaker:0.63 + cpe:/a:windowmaker:windowmaker:0.61.1 + cpe:/a:windowmaker:windowmaker:0.60 + cpe:/a:windowmaker:windowmaker:0.61 + + CVE-2001-1027 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:09:32.897-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3177 + + + DEBIAN + DSA-074 + + + CONFIRM + http://www.windowmaker.org/src/ChangeLog + + + XF + windowmaker-title-bo(6969) + + + SUSE + SuSE-SA:2001:032 + + + MANDRAKE + MDKSA-2001:074 + + + CONECTIVA + CLA-2001:411 + + Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title. + + + + + + + + + + + + + + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:5.2 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:5.1 + cpe:/o:redhat:linux:5.0 + + CVE-2001-1028 + 2001-05-28T00:00:00.000-04:00 + 2008-09-05T16:25:30.407-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2001:072 + + + XF + man-ultimate-source-bo(8622) + + Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.4 + cpe:/a:openbsd:openssh:4.5 + + CVE-2001-1029 + 2001-09-20T00:00:00.000-04:00 + 2008-09-05T16:25:30.563-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bsd-libutil-privilege-dropping(8697) + + + BUGTRAQ + 20010920 Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier) + + + OSVDB + 6073 + + libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:trustix:secure_linux:1.01 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.0 + cpe:/a:caldera:openlinux_server:3.1 + cpe:/a:immunix:immunix:7.0 + cpe:/a:squid:squid_web_proxy:2.3stable3 + cpe:/a:squid:squid_web_proxy:2.3stable4 + cpe:/a:immunix:immunix:7.0_beta + cpe:/a:immunix:immunix:6.2 + cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2 + cpe:/o:mandrakesoft:mandrake_linux:8.0 + + CVE-2001-1030 + 2001-07-18T00:00:00.000-04:00 + 2008-09-05T16:25:30.720-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + squid-http-accelerator-portscanning(6862) + + + BUGTRAQ + 20010718 Squid httpd acceleration acl bug enables portscanning + + + REDHAT + RHSA-2001:097 + + + IMMUNIX + IMNX-2001-70-031-01 + + + BUGTRAQ + 20010719 TSLSA-2001-0013 - Squid + + + MANDRAKE + MDKSA-2001:066 + + + CALDERA + CSSA-2001-029.0 + + Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. + + + + + + + + + cpe:/a:charles_clark:meteor_ftpd:1.0 + + CVE-2001-1031 + 2001-09-27T00:00:00.000-04:00 + 2008-09-10T15:09:33.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + meteor-ftpd-directory-traversal(7176) + + + BUGTRAQ + 20010927 CARTSA-2001-03 Meteor FTPD 1.0 Directory Traversal + + + BID + 3374 + + Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.2 + + CVE-2001-1032 + 2001-09-24T00:00:00.000-04:00 + 2008-09-05T16:25:31.033-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + php-nuke-admin-file-overwrite(7170) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=113892 + + + BUGTRAQ + 20010924 twlc advisory: all versions of php nuke are vulnerable... + + + BID + 3361 + + admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy. + + + + + + + + + + + + + + + cpe:/o:compaq:tru64:5.0 + cpe:/o:compaq:tru64:5.1 + cpe:/a:compaq:trucluster:1.5 + + CVE-2001-1033 + 2001-09-25T00:00:00.000-04:00 + 2008-09-05T16:25:31.190-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + trucluster-portscan-dos(7171) + + + BID + 3362 + + + BUGTRAQ + 20010925 Re: HACMP and port scans + + Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state. + + + + + + + + + cpe:/o:freebsd:freebsd:4.4 + + CVE-2001-1034 + 2001-09-23T00:00:00.000-04:00 + 2008-09-05T16:25:31.330-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hylafax-hostname-format-string(7164) + + + BID + 3357 + + + BUGTRAQ + 20010923 hylafax + + Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter. + + + + + + + + + cpe:/a:slrn_development_team:slrn:0.9 + + CVE-2001-1035 + 2001-09-24T00:00:00.000-04:00 + 2008-09-05T16:25:31.487-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + slrn-decode-script-execution(7166) + + + BID + 3364 + + + DEBIAN + DSA-078 + + Binary decoding feature of slrn 0.9 and earlier allows remote attackers to execute commands via shell scripts that are inserted into a news post. + + + + + + + + + + + + + + + + cpe:/a:gnu:findutils:4.1 + cpe:/a:gnu:findutils:4.0 + cpe:/o:slackware:slackware_linux:8.0 + cpe:/o:slackware:slackware_linux:7.1 + + CVE-2001-1036 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:31.627-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + locate-command-execution(6932) + + + BID + 3127 + + + BUGTRAQ + 20010801 Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate + + + OSVDB + 5477 + + GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory. + + + + + + + + + + cpe:/o:cisco:sn_5420_storage_router:1.1%282%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%283%29 + + CVE-2001-1037 + 2001-01-08T00:00:00.000-05:00 + 2008-09-05T16:25:31.783-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-sn-gain-access(6827) + + + CISCO + 20010711 Vulnerabilities in Cisco SN 5420 Storage Routers + + + BID + 3131 + + + OSVDB + 1917 + + Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. + + + + + + + + + + cpe:/o:cisco:sn_5420_storage_router:1.1%282%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%283%29 + + CVE-2001-1038 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:25:31.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-sn-dos(6826) + + + CISCO + 20010711 Vulnerabilities in Cisco SN 5420 Storage Routers + + + CIAC + L-112 + + + BID + 3014 + + + OSVDB + 1899 + + Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023. + + + + + + + + + + + + + + + + + cpe:/a:hp:jetadmin:4.1.2 + cpe:/a:hp:jetadmin:6.1 + cpe:/a:hp:jetadmin:6.0 + cpe:/a:hp:jetadmin:5.1 + cpe:/a:hp:jetadmin:4.0 + cpe:/a:hp:jetadmin:6.2 + cpe:/a:hp:jetadmin:5.6 + cpe:/a:hp:jetadmin:5.5.177 + cpe:/a:hp:jetadmin:5.5 + + CVE-2001-1039 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:32.080-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3132 + + + BUGTRAQ + 20010801 HP Jetdirect passwords don't sync + + The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer. + + + + + + + + + + + + + + + + + cpe:/a:hp:jetadmin:4.1.2 + cpe:/a:hp:jetadmin:6.1 + cpe:/a:hp:jetadmin:6.0 + cpe:/a:hp:jetadmin:5.1 + cpe:/a:hp:jetadmin:4.0 + cpe:/a:hp:jetadmin:6.2 + cpe:/a:hp:jetadmin:5.6 + cpe:/a:hp:jetadmin:5.5.177 + cpe:/a:hp:jetadmin:5.5 + + CVE-2001-1040 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:32.237-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3132 + + + BUGTRAQ + 20010802 Re: HP Jetdirect passwords don't sync + + HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. + + + + + + + + + + + cpe:/a:oracle:database_server:8.0 + cpe:/a:oracle:database_server:9.0.1 + cpe:/a:oracle:database_server:8.1 + + CVE-2001-1041 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:32.407-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3135 + + + BUGTRAQ + 20010802 vulnerability in oracle binary in Oracle 8.0.5 - 8.1.6 + + + BUGTRAQ + 20011024 Oracle File Overwrite Security Vulnerability + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf + + oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable. + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:5.9.5.0 + + CVE-2001-1042 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:25:32.563-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ftp-lnk-directory-traversal(6760) + + + BID + 2960 + + + BUGTRAQ + 20010701 Broker 5.9.5.0 Directory Traversal + + Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. + + + + + + + + + cpe:/a:argosoft:ftp_server:1.2.2.2 + + CVE-2001-1043 + 2001-07-01T00:00:00.000-04:00 + 2008-09-10T15:09:34.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2961 + + + BUGTRAQ + 20010701 ArGoSoft 1.2.2.2 *.lnk upload Directory Traversal + + + XF + ftp-lnk-directory-traversal(6760) + + + OSVDB + 1886 + + ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. + + + + + + + + + cpe:/a:basilix:basilix_webmail:0.9.7_beta + + CVE-2001-1044 + 2001-01-11T00:00:00.000-05:00 + 2008-09-05T16:25:32.860-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2198 + + + BUGTRAQ + 20010112 Basilix Webmail System *.class *.inc Permission Vulnerability + + + XF + basilix-webmail-retrieve-files(5934) + + Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file. + + + + + + + + + + cpe:/a:basilix:basilix_webmail:1.02_beta + cpe:/a:basilix:basilix_webmail:1.03_beta + + CVE-2001-1045 + 2001-07-06T00:00:00.000-04:00 + 2008-09-05T16:25:33.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + basilix-webmail-view-files(6873) + + + BID + 2995 + + + BUGTRAQ + 20010706 basilix bug + + Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter. + + + + + + + + + + + cpe:/a:qualcomm:qpopper:4.0 + cpe:/a:qualcomm:qpopper:4.0.1 + cpe:/a:qualcomm:qpopper:4.0.2 + + CVE-2001-1046 + 2001-06-02T00:00:00.000-04:00 + 2008-09-05T16:25:33.157-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + qpopper-username-bo(6647) + + + BID + 2811 + + + BUGTRAQ + 20010602 Qpopper 4.0.3 **** Fixes Buffer Overflow **** (fwd) + + + CALDERA + CSSA-2001-SCO.8 + + + VULN-DEV + 20010420 Qpopper 4.0 Buffer Overflow + + Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers gain privileges via a long username. + + + + + + + + + + + + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:openbsd:openbsd:2.9 + cpe:/o:openbsd:openbsd:2.8 + + CVE-2001-1047 + 2001-06-02T00:00:00.000-04:00 + 2009-08-21T00:07:41.437-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + openbsd-pipe-race-dos(6661) + + + XF + openbsd-dup2-race-dos(6660) + + + BID + 2818 + + + BID + 2817 + + + BUGTRAQ + 20010602 Locally exploitable races in OpenBSD VFS + + Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork. + + + + + + + + + + + + + + + cpe:/a:topher1kenobe:awol:1.0 + cpe:/a:topher1kenobe:awol:1.2 + cpe:/a:topher1kenobe:awol:1.0.1 + cpe:/a:topher1kenobe:awol:2.1 + cpe:/a:topher1kenobe:awol:2.0 + cpe:/a:topher1kenobe:awol:1.2.1 + cpe:/a:topher1kenobe:awol:2.01 + + CVE-2001-1048 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:25:33.457-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.gospelcom.net/mnn/topher/awol/changelog.php + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + BID + 3387 + + + MISC + http://www.geocrawler.com/archives/3/14414/2001/9/0/6668723/ + + + XF + php-includedir-code-execution(7215) + + AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + cpe:/a:paul_m._jones:phorecast:0.40 + + CVE-2001-1049 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:09:34.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + BID + 3388 + + + CONFIRM + http://phorecast.org/ + + + XF + php-includedir-code-execution(7215) + + Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + + + + + + + + + + cpe:/a:cccsoftware:ccc:0.94 + cpe:/a:cccsoftware:ccc:0.95 + cpe:/a:cccsoftware:ccc:0.92 + cpe:/a:cccsoftware:ccc:0.91 + cpe:/a:cccsoftware:ccc:1.0 + cpe:/a:cccsoftware:ccc:1.02 + cpe:/a:cccsoftware:ccc:1.03 + cpe:/a:cccsoftware:ccc:0.98 + cpe:/a:cccsoftware:ccc:0.99 + cpe:/a:cccsoftware:ccc:0.96 + cpe:/a:cccsoftware:ccc:0.97 + + CVE-2001-1050 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:25:33.767-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + php-includedir-code-execution(7215) + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + BID + 3389 + + CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + + cpe:/a:dark_hart_portal:darkportal-unix:0.1.18 + cpe:/a:dark_hart_portal:darkportal-unix:0.1.16 + cpe:/a:dark_hart_portal:darkportal-unix:0.1.17 + + CVE-2001-1051 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:25:33.940-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + XF + php-includedir-code-execution(7215) + + + BID + 3390 + + + MISC + http://sourceforge.net/tracker/index.php?func=detail&aid=440666&group_id=20971&atid=120971 + + Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + + cpe:/a:emergenices_personnel_information_system:empris:2001-09-08 + cpe:/a:emergenices_personnel_information_system:empris:0.4 + cpe:/a:emergenices_personnel_information_system:empris:2001-08-10 + + CVE-2001-1052 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:25:34.080-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + php-includedir-code-execution(7215) + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + BID + 3391 + + Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + + + + + + + cpe:/a:adcycle:adcycle:1.0 + cpe:/a:adcycle:adcycle:1.12 + cpe:/a:adcycle:adcycle:0.77b + cpe:/a:adcycle:adcycle:1.13 + cpe:/a:adcycle:adcycle:0.78b + cpe:/a:adcycle:adcycle:1.14 + cpe:/a:adcycle:adcycle:0.77 + cpe:/a:adcycle:adcycle:1.15 + + CVE-2001-1053 + 2001-07-13T00:00:00.000-04:00 + 2008-09-10T15:09:35.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + adcycle-insert-sql-command(6837) + + + BID + 3032 + + + BUGTRAQ + 20010713 AdCycle SQL Command Insertion Vulnerability - qDefense Advisory Number QDAV-2001-7-2 + + + CONFIRM + http://www.adcycle.com/cgi-bin/download.cgi?type=UNIX&version=1.17 + + AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument. + + + + + + + + + cpe:/a:phpadsnew:phpadsnew:2.0_beta5 + + CVE-2001-1054 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:09:35.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3392 + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=117952 + + + XF + php-includedir-code-execution(7215) + + + CONFIRM + http://sourceforge.net/forum/forum.php?thread_id=148900&forum_id=117952 + + PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + + CVE-2001-1055 + 2001-07-30T00:00:00.000-04:00 + 2008-09-05T16:25:34.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win-arp-packet-flooding-dos(6924) + + + BID + 3113 + + + BUGTRAQ + 20010730 ARPNuke - 80 kb/s kills a whole subnet + + The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke. + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.0.18 + + CVE-2001-1056 + 2001-07-30T00:00:00.000-04:00 + 2008-09-05T16:25:34.690-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3117 + + + BUGTRAQ + 20010730 Re: [RAZOR] Linux kernel IP masquerading vulnerability (_actual_ patch) + + + BUGTRAQ + 20010730 [RAZOR] Linux kernel IP masquerading vulnerability + + + OSVDB + 1916 + + + XF + linux-ipmasqirc-bypass-protection(6923) + + IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module to believe that the traffic is a valid request and allow the connection to the port specified in the DCC SEND request. + + + + + + + + + + cpe:/a:wolfram_research:mathematica:4.0 + cpe:/a:wolfram_research:mathematica:4.1 + + CVE-2001-1057 + 2001-07-30T00:00:00.000-04:00 + 2008-09-05T16:25:34.830-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010730 a couple minor issues with mathematica license manager + + + XF + mathematica-license-dos(6926) + + + BID + 3120 + + The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests. + + + + + + + + + + cpe:/a:wolfram_research:mathematica:4.0 + cpe:/a:wolfram_research:mathematica:4.1 + + CVE-2001-1058 + 2002-02-13T00:00:00.000-05:00 + 2008-09-05T16:25:34.987-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010730 a couple minor issues with mathematica license manager + + + XF + mathematica-license-retrieval(6927) + + + BID + 3118 + + The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license. + + + + + + + + + cpe:/a:vmware:workstation:2.0 + + CVE-2001-1059 + 2001-07-30T00:00:00.000-04:00 + 2008-09-05T16:25:35.127-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3119 + + + XF + vmware-obtain-license-info(6925) + + + BUGTRAQ + 20010730 vmware bug? + + + OSVDB + 5475 + + VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information. + + + + + + + + + + + + + + + + + + + + + cpe:/a:phpmyadmin:phpmyadmin:2.1 + cpe:/a:phpmyadmin:phpmyadmin:2.0 + cpe:/a:phpmyadmin:phpmyadmin:2.0.2 + cpe:/a:phpmyadmin:phpmyadmin:2.0.3 + cpe:/a:phpmyadmin:phpmyadmin:2.0.1 + cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3 + cpe:/a:phpmyadmin:phpmyadmin:2.1.1 + cpe:/a:phpmyadmin:phpmyadmin:2.1.2 + cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2 + cpe:/a:phpmyadmin:phpmyadmin:2.0.5 + cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1 + cpe:/a:phpmyadmin:phpmyadmin:2.0.4 + cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1 + + CVE-2001-1060 + 2001-07-31T00:00:00.000-04:00 + 2009-04-03T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3121 + + + BUGTRAQ + 20010731 New command execution vulnerability in myPhpAdmin + + + MISC + http://freshmeat.net/redir/phpmyadmin/8001/url_changelog/ + + phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2001-1061 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:35.500-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY22255 + + Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error. + + + + + + + + + cpe:/a:caldera:openserver:5.0.6a + + CVE-2001-1062 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:09:36.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-2001-SCO.12 + + + XF + openserver-mana-bo(7034) + + Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7 + cpe:/o:caldera:openunix:8.0 + + CVE-2001-1063 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:35.783-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + unixware-openunix-uidadmin-bo(7036) + + + BID + 3244 + + + CALDERA + CSSA-2001-SCO.14 + + Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:cbos:2.0.1 + cpe:/o:cisco:cbos:2.1.0a + cpe:/o:cisco:cbos:2.2.1 + cpe:/o:cisco:cbos:2.2.0 + cpe:/o:cisco:cbos:2.1.0 + cpe:/o:cisco:cbos:2.2.1a + cpe:/o:cisco:cbos:2.3 + cpe:/o:cisco:cbos:2.4.2ap + cpe:/o:cisco:cbos:2.3.2 + cpe:/o:cisco:cbos:2.4.2 + cpe:/o:cisco:cbos:2.3.7 + cpe:/o:cisco:cbos:2.3.8 + cpe:/o:cisco:cbos:2.3.5 + cpe:/o:cisco:cbos:2.4.1 + cpe:/o:cisco:cbos:2.3.9 + + CVE-2001-1064 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:35.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-http-dos(7026) + + + XF + cisco-cbos-telnet-dos(7025) + + + BID + 3236 + + + CISCO + 20010823 CBOS Web-based Configuration Utility Vulnerability + + Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets. + + + + + + + + + + cpe:/o:cisco:cbos:2.0.1 + cpe:/o:cisco:cbos:2.4.2ap + + CVE-2001-1065 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:36.110-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-cbos-web-config(7027) + + + CISCO + 20010823 CBOS Web-based Configuration Utility Vulnerability + + Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. + + + + + + + + + cpe:/o:sun:solaris + + CVE-2001-1066 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:36.267-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010827 Dangerous temp file creation during installation of Netscape 6. + + + XF + netscape-install-tmpfile-symlink(7042) + + + BID + 3243 + + + VULNWATCH + 20010827 Dangerous temp file creation during installation of Netscape 6. + + ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + cpe:/a:aol:aol_server:3.0 + cpe:/a:aol:aol_server:3.2 + + CVE-2001-1067 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:36.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3230 + + + XF + aolserver-long-password-dos(7030) + + + BUGTRAQ + 20010822 AOLserver 3.0 vulnerability + + + BUGTRAQ + 20010906 AOLserver exploit code + + Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header. + + + + + + + + + cpe:/a:qualcomm:qpopper:4.0.1 + + CVE-2001-1068 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:36.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + qpopper-pam-auth-error(7047) + + + BID + 3242 + + + BUGTRAQ + 20010825 qpopper and pam.d + + qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system. + + + + + + + + + cpe:/a:adobe:acrobat_reader:4.0.5 + + CVE-2001-1069 + 2001-08-31T00:00:00.000-04:00 + 2008-09-10T15:09:36.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3225 + + + BUGTRAQ + 20010822 Adobe Acrobat creates world writable ~/AdobeFnt.lst files + + + MISC + http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.html + + + XF + adobe-acrobat-insecure-permissions(7024) + + libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior. + + + + + + + + + cpe:/a:sage_software:mas_200 + + CVE-2001-1070 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:36.847-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mas-telnet-connect-dos(7020) + + + BID + 3221 + + + BUGTRAQ + 20010821 Bug in MAS90 Accounting Platform remote access? + + Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters. + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.0%285.1%29xp + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:catos:4.5%281%29 + cpe:/o:cisco:ios:11.3%2811%29b + cpe:/o:cisco:ios:11.2 + cpe:/o:cisco:ios:12.0%2819%29 + + CVE-2001-1071 + 2001-10-09T00:00:00.000-04:00 + 2008-09-05T16:25:36.987-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#139491 + + + XF + cisco-ios-cdp-dos(7242) + + + BID + 3412 + + + BUGTRAQ + 20011009 Cisco Systems - Vulnerability in CDP + + + BUGTRAQ + 20011009 Cisco CDP attacks + + + OSVDB + 1969 + + + + + Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements. + + + + + + + + + + + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.14 + + CVE-2001-1072 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:37.143-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3176 + + + BUGTRAQ + 20010812 Are your mod_rewrite rules doing what you expect? + + + XF + apache-rewrite-bypass-directives(8633) + + + CONFIRM + http://www.apacheweek.com/issues/02-02-01#security + + Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail. + + + + + + + + + cpe:/a:webridge:px_application_suite + + CVE-2001-1073 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:25:37.297-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + webridge-px-reveal-information(6993) + + + BID + 3182 + + + BUGTRAQ + 20010815 webridge application suite gives up too much error information on Internal Server Error + + Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname or internal IP address information in the variables (1) APPL_PHYSICAL_PATH, (2) PATH_TRANSLATED, and (3) LOCAL_ADDR. + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.7 + cpe:/a:webmin:webmin:0.6 + cpe:/a:webmin:webmin:0.80 + cpe:/a:webmin:webmin:0.83 + cpe:/a:webmin:webmin:0.5 + cpe:/a:webmin:webmin:0.84 + + CVE-2001-1074 + 2001-05-28T00:00:00.000-04:00 + 2008-09-05T16:25:37.440-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + webmin-gain-information(6627) + + + BID + 2795 + + + MANDRAKE + MDKSA-2001:059 + + + CALDERA + CSSA-2001-019.1 + + + BUGTRAQ + 20010526 Webmin Doesn't Clean Env (root exploit) + + Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges. + + + + + + + + + cpe:/h:sun:cobalt_raq_3i + + CVE-2001-1075 + 2001-07-04T00:00:00.000-04:00 + 2008-09-05T16:25:37.597-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010709 Re: poprelayd and sendmail relay authentication problem (Cobalt Raq3) + + + XF + cobalt-poprelayd-mail-relay(6806) + + + BID + 2986 + + + BUGTRAQ + 20010703 poprelayd and sendmail relay authentication problem (Cobalt Raq3) + + poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file. + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.8 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:sunos:5.7 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-1076 + 2001-07-05T00:00:00.000-04:00 + 2008-09-10T15:09:37.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BID + 2935 + + + BUGTRAQ + 20010705 Solaris whodo Vulnerability + + + XF + solaris-whodo-bo(6802) + + + + + + + + Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable. + + + + + + + + + cpe:/a:rxvt:rxvt:2.6.2 + + CVE-2001-1077 + 2001-06-15T00:00:00.000-04:00 + 2008-09-10T15:09:37.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + rxvt-ttprintf-bo(6701) + + + BUGTRAQ + 20010615 Rxvt vulnerability + + + DEBIAN + DSA-062 + + + IMMUNIX + IMNX-2001-70-028-01 + + + MANDRAKE + MDKSA-2001:060 + + + BID + 2878 + + Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:extremail:extremail:1.1.8 + cpe:/a:extremail:extremail:1.1.9 + cpe:/a:extremail:extremail:1.1.4 + cpe:/a:extremail:extremail:1.0.2 + cpe:/a:extremail:extremail:1.1.5 + cpe:/a:extremail:extremail:1.0.1 + cpe:/a:extremail:extremail:1.1.6 + cpe:/a:extremail:extremail:1.1.7 + cpe:/a:extremail:extremail:1.0.3 + cpe:/a:extremail:extremail:1.1.1 + cpe:/a:extremail:extremail:1.1 + cpe:/a:extremail:extremail:1.1.3 + cpe:/a:extremail:extremail:1.0 + cpe:/a:extremail:extremail:1.1.2 + + CVE-2001-1078 + 2001-06-21T00:00:00.000-04:00 + 2008-09-10T15:09:37.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + extremail-flog-format-string(6733) + + + BID + 2908 + + + CONFIRM + http://www.extremail.com/news.htm + + + CONFIRM + http://www.extremail.com/history.htm + + + BUGTRAQ + 20010622 eXtremail Remote Format String ('s) + + Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication. + + + + + + + + + cpe:/o:ibm:aix:3.2.0 + + CVE-2001-1079 + 2002-02-13T00:00:00.000-05:00 + 2008-09-05T16:25:38.237-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY19069 + + + XF + aix-keyfile-world-writable(8923) + + + OSVDB + 5473 + + create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service. + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:5.1 + + CVE-2001-1080 + 2001-06-19T00:00:00.000-04:00 + 2008-09-05T16:25:38.377-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + IBM + MSS-OAR-E01-2001:225.1 + + + XF + aix-diagrpt-root-shell(6734) + + + BID + 2916 + + diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program. + + + + + + + + + + cpe:/a:lucent:radius:2.1.2 + cpe:/a:simon_horms:radius:2.1_2 + + CVE-2001-1081 + 2001-07-06T00:00:00.000-04:00 + 2008-09-05T16:25:38.517-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2994 + + + CONFIRM + http://freshmeat.net/releases/52020/ + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + + MLIST + [fm-news] 20010713 Newsletter for Friday, July 13th 2001 + + Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages. + + + + + + + + + + cpe:/a:lucent:radius:2.1.2 + cpe:/a:simon_horms:radius:2.1_2 + + CVE-2001-1082 + 2001-07-13T00:00:00.000-04:00 + 2008-09-05T16:25:38.673-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://freshmeat.net/releases/52020/ + + Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. + + + + + + + + + + + cpe:/a:icecast:icecast:1.3.8_beta2 + cpe:/a:icecast:icecast:1.0.0 + cpe:/a:icecast:icecast:1.3.7 + + CVE-2001-1083 + 2001-06-26T00:00:00.000-04:00 + 2008-09-05T16:25:38.813-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + icecast-http-remote-dos(6751) + + + BID + 2933 + + + BUGTRAQ + 20010626 Advisory + + + CONFIRM + http://www.icecast.org/releases/icecast-1.3.11.tar.gz + + + MISC + http://www.icecast.org/index.html + + + REDHAT + RHSA-2002:063 + + + REDHAT + RHSA-2001:105 + + + DEBIAN + DSA-089 + + + CALDERA + CSSA-2002-020.0 + + Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash). + + + + + + + + + + cpe:/a:macromedia:jrun:2.3.3 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1084 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:09:38.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#654643 + + + BID + 2983 + + + XF + java-servlet-crosssite-scripting(6793) + + + OSVDB + 1891 + + + ALLAIRE + MPSB01-06 + + + BUGTRAQ + 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability + + Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message. + + + + + + + + + cpe:/a:jon_zeeff:lmail:2.7 + + CVE-2001-1085 + 2001-07-05T00:00:00.000-04:00 + 2008-09-05T16:25:39.110-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010705 lmail local root exploit + + + XF + lmail-tmpfile-symlink(6809) + + + BID + 2984 + + Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. + + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/a:xfree86_project:x11r6:3.3 + + CVE-2001-1086 + 2001-07-04T00:00:00.000-04:00 + 2008-09-05T16:25:39.250-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2985 + + + XF + xdm-cookie-brute-force(6808) + + + BUGTRAQ + 20010704 xdm cookies fast brute force + + + BUGTRAQ + 20010705 Re: xdm cookies fast brute force + + XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack. + + + + + + + + + + + + cpe:/h:network_appliance:netcache:c6100 + cpe:/h:network_appliance:netcache:c3100 + cpe:/h:network_appliance:netcache:c1100 + cpe:/h:network_appliance:netcache:c700 + + CVE-2001-1087 + 2001-07-05T00:00:00.000-04:00 + 2008-09-05T16:25:39.407-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + netcache-tunnel-default-configuration(6807) + + + BID + 2990 + + + BUGTRAQ + 20010705 RE: Tunnel ports allowed on NetApp NetCaches + + The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device. + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:4.72.3120.0 + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook:97 + cpe:/a:microsoft:outlook:98 + cpe:/a:microsoft:outlook_express:4.27.3110 + cpe:/a:microsoft:outlook_express:4.72.3612 + cpe:/a:microsoft:outlook_express:4.72.2106 + cpe:/a:microsoft:outlook_express:4.0 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:outlook_express:4.5 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2001-1088 + 2001-06-05T00:00:00.000-04:00 + 2008-09-05T16:25:39.547-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + outlook-address-book-spoofing(6655) + + + BID + 2823 + + + BUGTRAQ + 20010605 SECURITY.NNOV: Outlook Express address book spoofing + + + CONFIRM + http://support.microsoft.com/default.aspx?scid=kb;EN-US;q234241 + + Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user. + + + + + + + + + + cpe:/a:joerg_wendland:libnss-pgsql:0.9.0 + cpe:/a:alessandro_gardich:nss_postgresql:0.6.1 + + CVE-2001-1089 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:25:39.720-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + postgresql-nss-authentication-modules(7111) + + + BID + 3314 + + + BUGTRAQ + 20010910 RUS-CERT Advisory 2001-09:01 + + libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request. + + + + + + + + + cpe:/a:alessandro_gardich:nss_postgresql:0.6.1 + + CVE-2001-1090 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:25:39.860-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + postgresql-nss-authentication-modules(7111) + + + BUGTRAQ + 20010910 RUS-CERT Advisory 2001-09:01 + + + BID + 3315 + + nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request. + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2001-1091 + 2001-08-23T00:00:00.000-04:00 + 2008-09-05T16:25:40.017-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bsd-dump-tty-privileges(7037) + + + NETBSD + NetBSD-SA2001-014 + + The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable. + + + + + + + + + + + + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:compaq:tru64:4.0e + cpe:/o:compaq:tru64:4.0d + + CVE-2001-1092 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:25:40.157-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#440539 + + + XF + du-msgchk-symlink(7102) + + + BID + 3320 + + + BUGTRAQ + 20010910 Digital Unix 4.0x msgchk multiple vulnerabilities + + msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file. + + + + + + + + + + + + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:compaq:tru64:4.0e + cpe:/o:compaq:tru64:4.0d + + CVE-2001-1093 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:25:40.313-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + du-msgchk-bo(7101) + + + BID + 3311 + + + BUGTRAQ + 20010910 Digital Unix 4.0x msgchk multiple vulnerabilities + + Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument. + + + + + + + + + cpe:/a:crosstec_corporation:netop_school:1.5 + + CVE-2001-1094 + 2001-09-11T00:00:00.000-04:00 + 2008-09-05T16:25:40.470-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + netop-school-bypass-authentication(7120) + + + BID + 3321 + + + BUGTRAQ + 20010911 NetOP School Admin Vulnerability for Windows 2000 Terminal Services and NT4 + + NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version. + + + + + + + + + cpe:/o:ibm:aix:4.0 + + CVE-2001-1095 + 2001-10-09T00:00:00.000-04:00 + 2008-09-05T16:25:40.610-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + AIXAPAR + IY23401 + + + OSVDB + 5469 + + + AIXAPAR + IY24231 + + Buffer overflow in uuq in AIX 4 could alllow local users to execute arbitrary code via a long -r parameter. + + + + + + + + + cpe:/o:ibm:aix:4.0 + + CVE-2001-1096 + 2001-10-09T00:00:00.000-04:00 + 2013-07-25T10:18:38.743-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + OSVDB + 5470 + + + AIXAPAR + IY23402 + + Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code. + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0%283%29 + cpe:/o:cisco:ios:12.0%287%29t + cpe:/o:cisco:ios:12.0%284%29 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.0%282%29 + cpe:/o:cisco:ios:12.0%281%29 + cpe:/o:cisco:ios:12.0%286%29 + cpe:/o:cisco:ios:12.0%285%29 + + CVE-2001-1097 + 2001-07-24T00:00:00.000-04:00 + 2008-09-05T16:25:40.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-ios-udp-dos(6319) + + + BID + 3096 + + + BUGTRAQ + 20010724 UDP packet handling weird behaviour of various operating systems + + + BUGTRAQ + 20010811 Re: UDP packet handling weird behaviour of various operating systems + + Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. + + + + + + + + + cpe:/a:cisco:pix_firewall_manager:4.3%282%29g + + CVE-2001-1098 + 2001-10-10T00:00:00.000-04:00 + 2008-09-05T16:25:41.080-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#639507 + + + BUGTRAQ + 20011010 Vulnerability: Cisco PIX Firewall Manager + + + XF + cisco-pfm-plaintext-password(7265) + + + BID + 3419 + + Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file. + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:symantec:norton_antivirus:2.5 + + CVE-2001-1099 + 2001-09-07T00:00:00.000-04:00 + 2008-09-05T16:25:41.220-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nav-exchange-reveal-information(7093) + + + BID + 3305 + + + BUGTRAQ + 20010912 Re: Microsoft Exchange + Norton AntiVirus leak local information + + + BUGTRAQ + 20010907 Microsoft Exchange + Norton AntiVirus leak local information + + The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice. + + + + + + + + + cpe:/a:spencer_miles:w3mail:1.0.2 + + CVE-2001-1100 + 2001-10-07T00:00:00.000-04:00 + 2008-09-05T16:25:41.360-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011007 Bug found at W3Mail Webmail + + + XF + w3mail-metacharacters-command-execution(7230) + + + CONFIRM + http://www.w3mail.org/ChangeLog + + + BID + 3673 + + sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page. + + + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + cpe:/a:checkpoint:firewall-1:4.1:sp1 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2001-1101 + 2001-09-08T00:00:00.000-04:00 + 2008-09-05T16:25:41.517-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010908 Bug in remote GUI access in CheckPoint Firewall + + + XF + fw1-log-file-overwrite(7095) + + + BID + 3303 + + The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:4.1:sp1 + cpe:/a:checkpoint:firewall-1:3.0 + + CVE-2001-1102 + 2001-09-08T00:00:00.000-04:00 + 2008-09-05T16:25:41.673-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + fw1-tmp-file-symlink(7094) + + + BID + 3300 + + + BUGTRAQ + 20010908 Bug in compile portion for older versions of CheckPoint Firewalls + + Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable. + + + + + + + + + cpe:/a:rhinosoft:ftp_voyager:8.0 + + CVE-2001-1103 + 2001-03-03T00:00:00.000-05:00 + 2008-09-05T16:25:41.830-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#320944 + + + XF + ftp-voyager-embedded-script-execution(7119) + + FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands. + + + + + + + + + + + cpe:/h:sonicwall:soho:4.0.0 + cpe:/h:sonicwall:soho:5.1.5.0 + cpe:/h:sonicwall:soho:5.0.0 + + CVE-2001-1104 + 2001-07-25T00:00:00.000-04:00 + 2008-09-05T16:25:41.970-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3098 + + + BUGTRAQ + 20010725 Weak TCP Sequence Numbers in Sonicwall SOHO Firewall + + SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. + + + + + + + + + + + + cpe:/a:rsa:bsafe_ssl-j_sdk:3.0.1 + cpe:/a:rsa:bsafe_ssl-j_sdk:3.0 + cpe:/a:rsa:bsafe_ssl-j_sdk:3.1 + cpe:/a:cisco:icdn:2.0 + + CVE-2001-1105 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:42.127-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + bsafe-ssl-bypass-authentication(7112) + + + BID + 3329 + + + CIAC + L-141 + + + CONFIRM + http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL-J_3.x.SecurityBulletin.html + + + CISCO + 20010912 Vulnerable SSL Implementation in iCDN + + RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. + + + + + + + + + + + + + + + + + cpe:/a:sambar:sambar_server:4.4 + cpe:/a:sambar:sambar_server:4.1 + cpe:/a:sambar:sambar_server:5.0:beta1 + cpe:/a:sambar:sambar_server:4.3 + cpe:/a:sambar:sambar_server:5.0:beta2 + cpe:/a:sambar:sambar_server:5.0:beta5 + cpe:/a:sambar:sambar_server:4.2.1_production + cpe:/a:sambar:sambar_server:5.0:beta3 + cpe:/a:sambar:sambar_server:5.0:beta4 + + CVE-2001-1106 + 2001-07-25T00:00:00.000-04:00 + 2008-09-05T16:25:42.267-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3095 + + + XF + sambar-insecure-passwords(6909) + + + BUGTRAQ + 20010725 Sambar Server password decryption + + The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure. + + + + + + + + + cpe:/a:snapstream:pvs:1.2a + + CVE-2001-1107 + 2001-07-26T00:00:00.000-04:00 + 2008-09-05T16:25:42.437-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + snapstream-dot-directory-traversal(6917) + + + BID + 3101 + + + CONFIRM + http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html + + + BUGTRAQ + 20010726 Snapstream PVS vulnerability + + SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server. + + + + + + + + + cpe:/a:snapstream:pvs:1.2a + + CVE-2001-1108 + 2001-07-26T00:00:00.000-04:00 + 2008-09-05T16:25:42.580-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + snapstream-dot-directory-traversal(6917) + + + BID + 3100 + + + CONFIRM + http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html + + + BUGTRAQ + 20010726 Snapstream PVS vulnerability + + + OSVDB + 2080 + + Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.7.337 + + CVE-2001-1109 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:42.720-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eftp-quote-reveal-information(7114) + + + XF + eftp-list-directory-traversal(7113) + + + BID + 3333 + + + BID + 3331 + + + BUGTRAQ + 20010912 EFTP Version 2.0.7.337 vulnerabilities + + + MISC + http://www.eftp.org/releasehistory.html + + Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.7.337 + + CVE-2001-1110 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:42.860-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010912 EFTP Version 2.0.7.337 vulnerabilities + + EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.7.337 + + CVE-2001-1111 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:43.017-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eftp-plaintext-password(7116) + + + BID + 3332 + + + BUGTRAQ + 20010912 EFTP Version 2.0.7.337 vulnerabilities + + EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.7.337 + + CVE-2001-1112 + 2001-09-12T00:00:00.000-04:00 + 2008-09-05T16:25:43.157-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eftp-lnk-bo(7115) + + + BID + 3330 + + + BUGTRAQ + 20010912 EFTP Version 2.0.7.337 vulnerabilities + + Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters. + + + + + + + + + + + + + + + + + + cpe:/a:trolltech:trollftpd:1.24 + cpe:/a:trolltech:trollftpd:1.23 + cpe:/a:trolltech:trollftpd:1.26 + cpe:/a:trolltech:trollftpd:1.25 + cpe:/a:trolltech:trollftpd:1.19 + cpe:/a:trolltech:trollftpd:1.18 + cpe:/a:trolltech:trollftpd:1.17 + cpe:/a:trolltech:trollftpd:1.21 + cpe:/a:trolltech:trollftpd:1.22 + cpe:/a:trolltech:trollftpd:1.20 + + CVE-2001-1113 + 2001-08-13T00:00:00.000-04:00 + 2008-09-05T16:25:43.297-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + trollftpd-long-path-bo(6974) + + + BID + 3174 + + + BUGTRAQ + 20010813 Local exploit for TrollFTPD-1.26 + + + CONFIRM + ftp://ftp.trolltech.com/freebies/ftpd/troll-ftpd-1.27.tar.gz + + Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command. + + + + + + + + + cpe:/a:netcode:nc_book:0.2b + + CVE-2001-1114 + 2001-08-13T00:00:00.000-04:00 + 2008-09-05T16:25:43.453-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + netcode-book-pipes-command(6986) + + + BID + 3178 + + + BUGTRAQ + 20010813 NetCode NC Book 0.2b remote command execution vulnerability + + book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter. + + + + + + + + + cpe:/a:sixhead:six-webboard:2.01 + + CVE-2001-1115 + 2001-08-13T00:00:00.000-04:00 + 2008-09-05T16:25:43.610-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sixwebboard-dot-directory-traversal(6975) + + + BID + 3175 + + + BUGTRAQ + 20010813 SIX-webboard 2.01 "show files" vulnerability + + generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter. + + + + + + + + + + + + cpe:/a:identix:biologon:2.0 + cpe:/a:identix:biologon:2.0.2 + cpe:/a:identix:biologon:2.0.3 + cpe:/a:identix:biologon:2.0.1 + + CVE-2001-1116 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:25:43.750-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + identix-biologon-auth-bypass(6948) + + + BID + 3140 + + + NTBUGTRAQ + 20010802 Identix BioLogon Client security bug + + + OSVDB + 5453 + + + NTBUGTRAQ + 20010808 Response to Identix BioLogon Client security bug + + Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, which allows an attacker with physical access to the system to bypass authentication through a secondary display. + + + + + + + + + + + + cpe:/h:linksys:befsr41:1.38.5 + cpe:/h:linksys:befsr41:1.37 + cpe:/h:linksys:befsr41:1.35 + cpe:/h:linksys:befsr41:1.36 + + CVE-2001-1117 + 2001-08-10T00:00:00.000-04:00 + 2008-09-05T16:25:43.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linksys-etherfast-reveal-passwords(6949) + + + BID + 3141 + + + BUGTRAQ + 20010810 Linksys router security fix + + + CONFIRM + ftp://ftp.linksys.com/pub/befsr41/befsr-fw1402.zip + + + BUGTRAQ + 20010802 Advisory Update: Design Flaw in Linksys EtherFast 4-Port + + + OSVDB + 5467 + + + OSVDB + 1920 + + LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm. + + + + + + + + + + cpe:/a:roxen:roxen_webserver:2.1 + cpe:/a:roxen:roxen_webserver:2.0 + + CVE-2001-1118 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:25:44.047-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + roxen-urlrectifier-retrieve-files(6937) + + + BID + 3145 + + + BUGTRAQ + 20010802 Roxen security alert: URL decoding vulnerable + + + CONFIRM + http://download.roxen.com/2.0/patch/security-notice.html + + + BUGTRAQ + 20010802 FW: Security alert: Remote user can access any file + + A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL. + + + + + + + + + + + cpe:/a:ti_kan:xmcd:2.6.0 + cpe:/a:ti_kan:xmcd:3.0.1 + cpe:/a:ti_kan:xmcd:3.0.0 + + CVE-2001-1119 + 2001-08-03T00:00:00.000-04:00 + 2008-09-05T16:25:44.203-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#105347 + + + XF + xmcd-cda-symlink(6941) + + + BID + 3148 + + + SUSE + SuSE-SA:2001:025 + + cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.5.1 + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:3.1.1 + cpe:/a:allaire:coldfusion_server:4.0.1 + cpe:/a:allaire:coldfusion_server:2.0 + cpe:/a:allaire:coldfusion_server:4.5.1_sp2 + cpe:/a:allaire:coldfusion_server:4.5.1_sp1 + cpe:/a:allaire:coldfusion_server:3.0 + cpe:/a:allaire:coldfusion_server:4.5 + cpe:/a:allaire:coldfusion_server:3.0.1 + cpe:/a:allaire:coldfusion_server:3.1 + cpe:/a:allaire:coldfusion_server:3.1.2 + + CVE-2001-1120 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:25:44.347-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#135531 + + + XF + coldfusion-unauthorized-file-access(6839) + + + BID + 3018 + + + BUGTRAQ + 20010712 New Cold Fusion vulnerability + + + CONFIRM + http://www.allaire.com/handlers/index.cfm?id=21566 + + Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates. + + + + + + + + + + cpe:/a:macromedia:jrun:2.3.3 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1121 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:09:43.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-2001-1084. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp6a + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2001-1122 + 2001-08-03T00:00:00.000-04:00 + 2008-09-05T16:25:44.673-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010803 REPOST: A damaging local DoS in WinNT SP6a + + + XF + winnt-nt4all-dos(6943) + + + BID + 3144 + + Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode. + + + + + + + + + + + cpe:/a:hp:openview_network_node_manager:6.2 + cpe:/a:hp:openview_network_node_manager:6.1 + cpe:/a:hp:openview_network_node_manager:5.01 + + CVE-2001-1123 + 2001-10-01T00:00:00.000-04:00 + 2008-09-05T16:25:44.830-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#782155 + + + XF + openview-nmm-gain-privileges(7222) + + + BID + 3399 + + + HP + HPSBUX0110-170 + + + HP + HPSBUX0112-177 + + Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID. + + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-1124 + 2001-10-01T00:00:00.000-04:00 + 2009-03-04T00:09:36.547-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + hp-rpcbind-dos(7221) + + + BID + 3400 + + + HP + HPSBUX0110-169 + + + CIAC + M-003 + + + + + rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow. + + + + + + + + + + cpe:/a:symantec:liveupdate:1.4 + cpe:/a:symantec:liveupdate:1.5 + + CVE-2001-1125 + 2001-10-05T00:00:00.000-04:00 + 2008-09-05T16:25:45.127-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3403 + + + BUGTRAQ + 20011005 Symantec LiveUpdate attacks + + + XF + liveupdate-host-verification(7235) + + + CONFIRM + http://www.sarc.com/avcenter/security/Content/2001.10.05.html + + Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. + + + + + + + + + + + cpe:/a:symantec:liveupdate:1.6 + cpe:/a:symantec:liveupdate:1.4 + cpe:/a:symantec:liveupdate:1.5 + + CVE-2001-1126 + 2001-10-05T00:00:00.000-04:00 + 2008-09-05T16:25:45.267-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011005 Symantec LiveUpdate attacks + + + XF + liveupdate-host-verification(7235) + + + BID + 3413 + + + CONFIRM + http://www.sarc.com/avcenter/security/Content/2001.10.05.html + + Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. + + + + + + + + + + cpe:/a:progress:progress:9.1c + cpe:/a:progress:progress:8.3d + + CVE-2001-1127 + 2001-10-05T00:00:00.000-04:00 + 2008-09-05T16:25:45.423-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3404 + + + XF + progress-strcpy-bo(7236) + + + BUGTRAQ + 20011005 Progress Database vulnerabilities + + Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8) _sqldump. + + + + + + + + + + cpe:/a:progress:progress:9.1c + cpe:/a:progress:progress:8.3d + + CVE-2001-1128 + 2001-10-08T00:00:00.000-04:00 + 2008-09-05T16:25:45.627-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3414 + + + XF + progress-protermcap-bo(7264) + + + BUGTRAQ + 20011008 Progress TERM (protermcap) overflows and PROMSGS overflows + + Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables. + + + + + + + + + cpe:/a:progress:progress:9.1c + + CVE-2001-1129 + 2001-11-02T00:00:00.000-05:00 + 2008-09-05T16:25:45.767-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3502 + + + XF + progress-promsgs-format-string(7457) + + + BUGTRAQ + 20011102 Progres Databse PROMSGS Format strings issue. + + Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by the PROMSGS environment variable. + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:suse:suse_linux:6.4 + cpe:/o:suse:suse_linux:6.0 + + CVE-2001-1130 + 2001-08-02T00:00:00.000-04:00 + 2008-09-05T16:25:45.923-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sdbsearch-cgi-command-execution(7003) + + + BUGTRAQ + 20010802 suse: sdbsearch.cgi vulnerability + + + SUSE + SuSE-SA:2001:027 + + Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file. + + + + + + + + + cpe:/a:whitsoft_development:slimftpd:2.2 + + CVE-2001-1131 + 2001-08-21T00:00:00.000-04:00 + 2008-09-05T16:25:46.080-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/5RP0L0055O.html + + Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command. + + + + + + + + + cpe:/a:gnu:mailman:2.0.5 + + CVE-2001-1132 + 2001-09-05T00:00:00.000-04:00 + 2008-09-05T16:25:46.220-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + mailman-blank-passwords(7091) + + + OSVDB + 5455 + + + CONECTIVA + CLA-2001:420 + + Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. + + + + + + + + + + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:bsdi:bsd_os:3.1 + + CVE-2001-1133 + 2001-08-21T00:00:00.000-04:00 + 2008-09-05T16:25:46.377-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3220 + + + BUGTRAQ + 20010821 BSDi (3.0/3.1) reboot machine code as any user (non-specific) + + + XF + bsd-kernel-dos(7023) + + Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions. + + + + + + + + + cpe:/h:xerox:docuprint_n40 + + CVE-2001-1134 + 2001-08-09T00:00:00.000-04:00 + 2008-09-10T15:09:44.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xerox-docuprint-dos(6976) + + + BUGTRAQ + 20010809 Xerox N40 printers and Code Red worm + + + BUGTRAQ + 20010720 Re: Two birds with one worm + + + BID + 3170 + + Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm. + + + + + + + + + cpe:/h:zyxel:prestige:642r + + CVE-2001-1135 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:25:46.657-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + prestige-wan-bypass-filter(7146) + + + BID + 3346 + + + BUGTRAQ + 20010918 SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network + + + BUGTRAQ + 20010814 Fwd: ZyXEL Prestige 642 Router Administration Interface Vulnerability + + + BUGTRAQ + 20010810 Re: ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password + + + BUGTRAQ + 20010809 ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password + + ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known. + + + + + + + + + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-1136 + 2001-09-13T00:00:00.000-04:00 + 2008-09-10T15:09:44.570-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-virtualvault-libsecurity-dos(7124) + + + CIAC + L-143 + + + HP + HPSBUX0109-166 + + + BID + 3338 + + The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service. + + + + + + + + + cpe:/h:d-link:dl-704:v2.56b5 + + CVE-2001-1137 + 2001-09-06T00:00:00.000-04:00 + 2008-09-10T15:09:44.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dlink-fragmented-packet-dos(7090) + + + BUGTRAQ + 20010906 Malformed Fragmented Packets DoS Dlink Firewall/Routers + + + BID + 3306 + + D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments. + + + + + + + + + cpe:/a:randy_parker:power_up_html:0.8033_beta + + CVE-2001-1138 + 2001-09-07T00:00:00.000-04:00 + 2008-09-05T16:25:47.093-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + powerup-rcgi-directory-traversal(7092) + + + BID + 3304 + + + BUGTRAQ + 20010907 *** Security Advisory *** Power UP HTML + + Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter. + + + + + + + + + cpe:/a:ascii_nt:winwrapper_professional:2.0 + + CVE-2001-1139 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:25:47.250-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3219 + + + BUGTRAQ + 20010822 [SNS Advisory No.39] WinWrapper Professional 2.0 Remote Arbitrary File Disclosure Vulnerability + + + XF + winwrapper-dot-directory-traversal(7015) + + + MISC + http://www.tsc.ant.co.jp/products/download.htm + + Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.02_beta + + CVE-2001-1140 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:25:47.390-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + badblue-file-source-disclosure (7021) + + + BID + 3222 + + + BUGTRAQ + 20010822 -- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000 Advisory ] -- + + BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request. + + + + + + + + + + + + + + + + + + cpe:/a:openssl:openssl:0.9.2b + cpe:/a:ssleay:ssleay:0.8.1 + cpe:/a:ssleay:ssleay:0.9.1 + cpe:/a:openssl:openssl:0.9.1c + cpe:/a:openssl:openssl:0.9.3 + cpe:/a:ssleay:ssleay:0.9 + cpe:/a:openssl:openssl:0.9.4 + cpe:/a:openssl:openssl:0.9.5 + cpe:/a:openssl:openssl:0.9.6a + cpe:/a:openssl:openssl:0.9.6 + + CVE-2001-1141 + 2001-07-10T00:00:00.000-04:00 + 2008-09-05T16:25:47.533-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + openssl-prng-brute-force(6823) + + + BID + 3004 + + + BUGTRAQ + 20010710 OpenSSL Security Advisory: PRNG weakness in versions up to 0.9.6a + + + REDHAT + RHSA-2001:051 + + + FREEBSD + FreeBSD-SA-01:51 + + + OSVDB + 853 + + + ENGARDE + ESA-20010709-01 + + + MANDRAKE + MDKSA-2001:065 + + + CONECTIVA + CLA-2001:418 + + + NETBSD + NetBSD-SA2001-013 + + The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers. + + + + + + + + + cpe:/a:argosoft:ftp_server:1.2.2.2 + + CVE-2001-1142 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:25:47.703-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3029 + + + BUGTRAQ + 20010712 ArGoSoft FTP Server 1.2.2.2 Weak password encryption + + + XF + argosoft-ftp-weak-encryption(6848) + + ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges. + + + + + + + + + cpe:/a:ibm:db2_universal_database:7.0::linux + + CVE-2001-1143 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:25:47.843-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3010 + + + BUGTRAQ + 20010711 IBM Windows DB2 DoS + + + XF + ibm-db2-jds-dos(6833) + + + XF + ibm-db2-ccs-dos(6832) + + IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. + + + + + + + + + cpe:/a:mcafee:asap_virusscan:1.0 + + CVE-2001-1144 + 2001-07-11T00:00:00.000-04:00 + 2013-08-17T00:16:26.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#190267 + + + BID + 3020 + + + BUGTRAQ + 20010711 McAfee ASaP Virusscan - myCIO HTTP Server Directory Traversal Vulnerabilty + + + OSVDB + 584 + + + XF + mcafee-mycio-directory-traversal(6834) + + + NTBUGTRAQ + 20010716 McAfee ASaP Virusscan - MyCIO HTTP Server Directory Traversal Vul nerability + + Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:openbsd:openbsd:2.9 + + CVE-2001-1145 + 2001-08-17T00:00:00.000-04:00 + 2008-09-10T15:09:45.257-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + OPENBSD + 20010530 029: SECURITY FIX: May 30, 2001 + + + NETBSD + NetBSD-SA2001-016 + + + BID + 3205 + + + OSVDB + 5466 + + + XF + bsd-fts-race-condition(8715) + + + FREEBSD + FreeBSD-SA-01:40 + + fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories. + + + + + + + + + cpe:/a:lee_herron:allcommerce:1.2.3 + + CVE-2001-1146 + 2001-07-11T00:00:00.000-04:00 + 2008-09-10T15:09:45.320-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + allcommerce-temp-symlink(6830) + + + ENGARDE + ESA-20010711-01 + + + BID + 3016 + + AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack. + + + + + + + + + + + + + cpe:/a:andries_brouwer:util-linux:2.11f + cpe:/a:andries_brouwer:util-linux:2.10s + cpe:/a:andries_brouwer:util-linux:2.11i + cpe:/a:andries_brouwer:util-linux:2.11h + cpe:/a:andries_brouwer:util-linux:2.11k + + CVE-2001-1147 + 2001-10-08T00:00:00.000-04:00 + 2008-09-05T16:25:48.437-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3415 + + + XF + utillinux-pamlimits-gain-privileges(7266) + + + BUGTRAQ + 20011008 pam_limits.so Bug!! + + + REDHAT + RHSA-2001:132 + + + SUSE + SuSE-SA:2001:034 + + + MANDRAKE + MDKSA-2001:084 + + + CIAC + M-009 + + The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits. + + + + + + + + + cpe:/o:sco:openserver:5.0.6a + + CVE-2001-1148 + 2001-06-13T00:00:00.000-04:00 + 2008-09-05T16:25:48.593-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CALDERA + CSSA-2001-SCO.25 + + + VULN-DEV + 20010613 SCO atcronsh auditsh termsh overflows + + + XF + openserver-scoadmin-sysadm-bo(7281) + + Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh. + + + + + + + + + cpe:/a:panda:panda_antivirus_platinum:6.23.00 + + CVE-2001-1149 + 2001-08-21T00:00:00.000-04:00 + 2008-09-05T16:25:48.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULN-DEV + 20010821 RE: Bug report -- Incident number 240649 + + + OSVDB + 5456 + + Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file. + + + + + + + + + + + + + cpe:/a:trend_micro:officescan:corporate_3.54 + cpe:/a:trend_micro:virus_buster:corporate_3.52 + cpe:/a:trend_micro:virus_buster:corporate_3.54 + cpe:/a:trend_micro:virus_buster:corporate_3.53 + cpe:/a:trend_micro:officescan:corporate_3.5 + + CVE-2001-1150 + 2001-08-22T00:00:00.000-04:00 + 2008-09-05T16:25:48.877-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3216 + + + BUGTRAQ + 20010822 [SNS Advisory No.38] Trend Micro Virus Buster (Ver.3.5x) Remote + + + XF + officescan-iuser-read-files(7014) + + + BUGTRAQ + 20010824 [SNS Advisory No.40] TrendMicro OfficeScan Corp Edition ver.3.54 Remote read file of IUSER authority Vulnerability + + Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files. + + + + + + + + + + cpe:/a:trend_micro:officescan:corporate_3.53 + cpe:/a:trend_micro:virus_buster:corporate_3.53 + + CVE-2001-1151 + 2001-10-15T00:00:00.000-04:00 + 2008-09-05T16:25:49.033-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + officescan-config-file-access(7286) + + + BUGTRAQ + 20011015 [SNS Advisory No.44] Trend Micro OfficeScan Corporate Edition(Virus Buster Corporate Edition) + + + MISC + http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318 + + Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password. + + + + + + + + + cpe:/o:baltimore_technologies:websweeper:4.02 + + CVE-2001-1152 + 2001-09-05T00:00:00.000-04:00 + 2008-09-05T16:25:49.187-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3296 + + + BUGTRAQ + 20010905 Various problems in Baltimore WebSweeper URL filtering + + + MISC + http://www.mimesweeper.com/support/technotes/notes/1043.asp + + Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters. + + + + + + + + + cpe:/o:caldera:openunix:8.0 + + CVE-2001-1153 + 2001-08-28T00:00:00.000-04:00 + 2008-09-10T15:09:45.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + openunix-lpsystem-bo(7041) + + + CALDERA + CSSA-2001-SCO.15 + + + BID + 3248 + + lpsystem in OpenUnix 8.0.0 allows local users to cause a denial of service and possibly execute arbitrary code via a long command line argument. + + + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os:4.2 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.0.15 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.0.16 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:1.6.24 + + CVE-2001-1154 + 2001-08-30T00:00:00.000-04:00 + 2008-09-05T16:25:49.487-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cyrus-imap-php-dos(7053) + + + BID + 3260 + + + BUGTRAQ + 20010830 Possible Denial of Service with PHP and Cyrus IMAP on BSDi 4.2 + + Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients. + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1 + + CVE-2001-1155 + 2001-08-23T00:00:00.000-04:00 + 2008-09-05T16:25:49.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + FREEBSD + FreeBSD-SA-01:56 + + + OSVDB + 5454 + + TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing. + + + + + + + + + cpe:/a:typsoft:typsoft_ftp_server:0.95 + + CVE-2001-1156 + 2001-10-08T00:00:00.000-04:00 + 2008-09-05T16:25:49.783-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3409 + + + BUGTRAQ + 20011008 [ASGUARD-LABS] TYPSoft FTP Server v0.95 STOR/RETR Denial of Service Vulnerability + + + XF + typsoft-ftp-retr-stor-dos(7247) + + + CONFIRM + http://membres.lycos.fr/typsoft/eng/history.html + + TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR. + + + + + + + + + + cpe:/o:baltimore_technologies:websweeper:4.0 + cpe:/o:baltimore_technologies:websweeper:4.02 + + CVE-2001-1157 + 2001-08-12T00:00:00.000-04:00 + 2008-09-05T16:25:49.937-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3173 + + + BID + 3172 + + + BUGTRAQ + 20010812 Various problems in Baltimore's WEBSweeper Script filter ing + + Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode. + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.1_build_41439 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + + CVE-2001-1158 + 2001-07-09T00:00:00.000-04:00 + 2008-09-05T16:25:50.080-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#310295 + + + CERT + CA-2001-17 + + + XF + fw1-rdp-bypass(6815) + + + BID + 2952 + + + BUGTRAQ + 20010709 Check Point FireWall-1 RDP Bypass Vulnerability + + + OSVDB + 1884 + + + CHECKPOINT + 20010712 RDP Bypass workaround for VPN-1/FireWall 4.1 SPx + + + BUGTRAQ + 20010709 Check Point response to RDP Bypass + + + CIAC + L-109 + + Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts. + + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.0.5 + cpe:/a:squirrelmail:squirrelmail:1.0.4 + + CVE-2001-1159 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:25:50.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 2968 + + + XF + squirrelmail-loadprefs-execute-code(6775) + + + BUGTRAQ + 20010702 (SRADV00010) Remote command execution vulnerabilities in SquirrelMail + + + MISC + http://www.squirrelmail.org/changelog.php + + load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP. + + + + + + + + + cpe:/a:microburst:udirectory:2.0 + + CVE-2001-1160 + 2001-06-18T00:00:00.000-04:00 + 2008-09-05T16:25:50.377-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20010618 udirectory from Microburst Technologies remote command execution + + + XF + udirectory-remote-command-execution(6706) + + + BID + 2884 + + udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field. + + + + + + + + + cpe:/a:lotus:domino_r5_server:5.0.6 + + CVE-2001-1161 + 2001-07-02T00:00:00.000-04:00 + 2008-09-05T16:25:50.517-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#642239 + + + XF + lotus-domino-css(6789) + + + BID + 2962 + + + BUGTRAQ + 20010702 Lotus Domino Server Cross-Site Scripting Vulnerability + + + BUGTRAQ + 20010702 Re: Lotus Domino Server Cross-Site Scripting Vulnerability + + + OSVDB + 1887 + + Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script. + + + + + + + + + + + + + + + + + + + + cpe:/a:samba:samba:2.2.0 + cpe:/a:samba:samba:2.0.6 + cpe:/a:samba:samba:2.0.7 + cpe:/a:samba:samba:2.0.8 + cpe:/a:samba:samba:2.0.9 + cpe:/a:hp:cifs-9000_server:a.01.06 + cpe:/a:hp:cifs-9000_server:a.01.05 + cpe:/a:samba:samba:2.0.5 + + CVE-2001-1162 + 2001-06-23T00:00:00.000-04:00 + 2008-09-05T16:25:50.673-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + samba-netbios-file-creation(6731) + + + BID + 2928 + + + BUGTRAQ + 20010623 smbd remote file creation vulnerability + + + CONFIRM + http://us1.samba.org/samba/whatsnew/macroexploit.html + + + HP + HPSBUX0107-157 + + + REDHAT + RHSA-2001:086 + + + MANDRAKE + MDKSA-2001-062 + + + DEBIAN + DSA-065 + + + CALDERA + CSSA-2001-024.0 + + + IMMUNIX + IMNX-2001-70-027-01 + + + CONECTIVA + CLA-2001:405 + + + CIAC + L-105 + + + SGI + 20011002-01-P + + Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file. + + + + + + + + + cpe:/a:munica:netsql:1.0 + + CVE-2001-1163 + 2001-06-16T00:00:00.000-04:00 + 2008-09-05T16:25:50.843-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2885 + + Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500. + + + + + + + + + cpe:/a:caldera:unixware:7.0 + + CVE-2001-1164 + 2001-06-27T00:00:00.000-04:00 + 2008-09-05T16:25:50.987-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-2001-SCO.4 + + Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt. + + + + + + + + + + cpe:/a:intego:fileguard:4.0 + cpe:/a:intego:diskguard:2.0 + + CVE-2001-1165 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:25:51.127-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3213 + + + MISC + http://www.securemac.com/fileguard.php#disengage + + + XF + fileguard-weak-password-encryption(7018) + + Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + + CVE-2001-1166 + 2001-08-21T00:00:00.000-04:00 + 2008-09-05T16:25:51.250-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3217 + + + XF + linprocfs-process-memory-leak(7017) + + + OSVDB + 1938 + + + FREEBSD + FreeBSD-SA-01:55 + + linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process. + + + CVE-2001-1167 + 2001-08-28T00:00:00.000-04:00 + 2008-09-10T15:09:48.493-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.1.1 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.1.4 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.1.3 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.1.5 + cpe:/a:phpmyexplorer:phpmyexplorer_multiuser:1.0 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.0 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.1.0 + cpe:/a:phpmyexplorer:phpmyexplorer_classic:1.2 + + CVE-2001-1168 + 2001-08-29T00:00:00.000-04:00 + 2008-09-10T15:09:48.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010830 Re: eRisk Security Advisory: PhpMyExplorer vulnerable to directory traversal. + + + BUGTRAQ + 20010829 eRisk Security Advisory: PhpMyExplorer vulnerable to directory traversal. + + Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter. + + + + + + + + + cpe:/o:bell_communications_research:s_key:gold + + CVE-2001-1169 + 2001-09-02T00:00:00.000-04:00 + 2008-09-05T16:25:51.657-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010902 S/Key keyinit(1) authentication (lack thereof) + sudo(1) + + keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo. + + + + + + + + + cpe:/a:amtote_international:homebet + + CVE-2001-1170 + 2001-09-29T00:00:00.000-04:00 + 2008-09-10T15:09:48.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3370 + + + XF + homebet-view-logfile(7186) + + + BUGTRAQ + 20010929 Vulnerability in Amtote International homebet self service wagering system. + + AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers. + + + + + + + + + cpe:/a:checkpoint:firewall-1:3.0b + + CVE-2001-1171 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:25:51.937-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010907 Bug in compile portion for older versions of CheckPoint Firewalls + + Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy. + + + + + + + + + cpe:/a:omnisecure:httprotect:1.1.1 + + CVE-2001-1172 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:25:52.093-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + httprotect-protected-file-symlink(6880) + + + BUGTRAQ + 20010719 [SNS Advisory No.37] HTTProtect allows attackers to change the protected file using a symlink + + + CONFIRM + http://www.omnisecure.com/security-alert.html + + + OSVDB + 5452 + + OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:masqmail:masqmail:0.0.6 + cpe:/a:masqmail:masqmail:0.1.14 + cpe:/a:masqmail:masqmail:0.0.7 + cpe:/a:masqmail:masqmail:0.1.15 + cpe:/a:masqmail:masqmail:0.0.8 + cpe:/a:masqmail:masqmail:0.0.9 + cpe:/a:masqmail:masqmail:0.0.2 + cpe:/a:masqmail:masqmail:0.0.3 + cpe:/a:masqmail:masqmail:0.0.4 + cpe:/a:masqmail:masqmail:0.0.5 + cpe:/a:masqmail:masqmail:0.1.0 + cpe:/a:masqmail:masqmail:0.1.1 + cpe:/a:masqmail:masqmail:0.1.2 + cpe:/a:masqmail:masqmail:0.0.13 + cpe:/a:masqmail:masqmail:0.0.0 + cpe:/a:masqmail:masqmail:0.1.3 + cpe:/a:masqmail:masqmail:0.1.4 + cpe:/a:masqmail:masqmail:0.0.1 + cpe:/a:masqmail:masqmail:0.1.5 + cpe:/a:masqmail:masqmail:0.1.6 + cpe:/a:masqmail:masqmail:0.1.7 + cpe:/a:masqmail:masqmail:0.1.8 + cpe:/a:masqmail:masqmail:0.1.9 + cpe:/a:masqmail:masqmail:0.0.12 + cpe:/a:masqmail:masqmail:0.0.11 + cpe:/a:masqmail:masqmail:0.0.10 + cpe:/a:masqmail:masqmail:0.1.11 + cpe:/a:masqmail:masqmail:0.1.10 + cpe:/a:masqmail:masqmail:0.1.13 + cpe:/a:masqmail:masqmail:0.1.12 + + CVE-2001-1173 + 2001-07-26T00:00:00.000-04:00 + 2008-09-10T15:09:51.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + ftp://innominate.org/oku/masqmail/ChangeLog-stable + + Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases. + + + + + + + + + cpe:/a:elm_development_group:elm:2.5.5 + + CVE-2001-1174 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:25:52.437-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + elm-messageid-bo(6852) + + + REDHAT + RHSA-2001:091 + + + OSVDB + 5451 + + + MANDRAKE + MDKSA-2001:067 + + Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header. + + + + + + + + + + cpe:/a:andries_brouwer:util-linux:2.11d + cpe:/a:andries_brouwer:util-linux:2.10s + + CVE-2001-1175 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:25:52.577-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + vipw-world-readable-files(6851) + + + BID + 3036 + + + REDHAT + RHSA-2001:095 + + + REDHAT + RHSA-2001:132 + + vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing. + + + + + + + + + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:vpn-1:4.1 + cpe:/a:checkpoint:vpn-1:4.1:sp1 + cpe:/a:checkpoint:provider-1:4.1:sp3 + cpe:/a:checkpoint:vpn-1:4.1:sp3 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + cpe:/a:checkpoint:firewall-1:4.1:sp1 + cpe:/a:checkpoint:firewall-1:4.1:sp3 + cpe:/a:checkpoint:provider-1:4.1 + cpe:/a:checkpoint:provider-1:4.1:sp1 + cpe:/a:checkpoint:provider-1:4.1:sp2 + + CVE-2001-1176 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:25:52.737-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + fw1-management-format-string(6849) + + + BID + 3021 + + + BUGTRAQ + 20010712 VPN-1/FireWall-1 Format Strings Vulnerability + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/format_strings.html + + + OSVDB + 1901 + + Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection. + + + + + + + + + + cpe:/a:samsung:ml-85g_gdi_printer_driver + cpe:/a:samsung:ml-85p_printer_driver:1.0 + + CVE-2001-1177 + 2001-07-17T00:00:00.000-04:00 + 2008-09-05T16:25:52.890-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010717 Samsung ML-85G Printer Linux Helper/Driver Binary Exploit (Mandrake: ghostscript package) + + + XF + samsung-printer-temp-symlink(6845) + + + BID + 3008 + + ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.2 + + CVE-2001-1178 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:25:53.047-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xfree86-xman-manpath-bo(6853) + + + BID + 3030 + + + BUGTRAQ + 20010711 suid xman 3.1.6 overflows + + Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable. + + + + + + + + + cpe:/a:xfree86_project:x11r6:3.3.2 + + CVE-2001-1179 + 2001-07-17T00:00:00.000-04:00 + 2008-09-05T16:25:53.187-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010717 xman (suid) exploit, made easier. + + xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters. + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + + CVE-2001-1180 + 2001-07-10T00:00:00.000-04:00 + 2008-09-05T16:25:53.327-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#943633 + + + BID + 3007 + + + BUGTRAQ + 20010710 FreeBSD 4.3 local root, yet Linux and *BSD much better than Windows + + + XF + bsd-rfork-signal-handlers(6829) + + + OSVDB + 1897 + + + CIAC + L-111 + + + FREEBSD + FreeBSD-SA-01:42 + + FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child. + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + + CVE-2001-1181 + 2001-07-16T00:00:00.000-04:00 + 2009-03-04T00:09:59.280-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + hpux-dlkm-gain-privileges(6861) + + + CIAC + L-115 + + + HP + HPSBUX0107-159 + + + + + Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges. + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + + CVE-2001-1182 + 2001-07-17T00:00:00.000-04:00 + 2009-03-04T00:09:59.390-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + HP + HPSBUX0107-160 + + + + + Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges. + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1yd + cpe:/o:cisco:ios:12.1yc + cpe:/o:cisco:ios:12.1ya + cpe:/o:cisco:ios:12.2xa + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.2xd + cpe:/o:cisco:ios:12.2xe + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.2xq + cpe:/o:cisco:ios:12.1ez + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.2xh + + CVE-2001-1183 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:25:53.783-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#656315 + + + XF + cisco-ios-pptp-dos(6835) + + + BID + 3022 + + + CISCO + 20010712 Cisco IOS PPTP Vulnerability + + + OSVDB + 802 + + + + + PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet. + + + + + + + + + + cpe:/a:denicomp:winsock_rshd_nt:2.21 + cpe:/a:denicomp:winsock_rshd_nt:2.20 + + CVE-2001-1184 + 2001-12-08T00:00:00.000-05:00 + 2008-09-05T16:25:53.953-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3659 + + + BUGTRAQ + 20011208 Winsock RSHD/NT 2.20.00 CPU overusage when invalid data is send + + + XF + winsock-rshdnt-error-dos(7694) + + + CONFIRM + http://www.denicomp.com/rshdnt.htm + + + BUGTRAQ + 20011213 WRSHDNT 2.21.00 CPU overusage + + wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024. + + + + + + + + + cpe:/o:freebsd:freebsd:4.4 + + CVE-2001-1185 + 2001-12-10T00:00:00.000-05:00 + 2008-09-05T16:25:54.093-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3661 + + + BUGTRAQ + 20011210 AIO vulnerability + + + XF + bsd-aio-overwrite-memory(7693) + + + OSVDB + 2001 + + Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2001-1186 + 2001-12-11T00:00:00.000-05:00 + 2008-09-05T16:25:54.237-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3667 + + + BUGTRAQ + 20011211 Microsoft IIS/5 bogus Content-length bug. + + + XF + iis-false-content-length-dos(7691) + + + BUGTRAQ + 20011212 Microsoft IIS/5.0 Content-Length DoS (proved) + + + BUGTRAQ + 20011211 Microsoft IIS/5 bogus Content-length bug Memory attack + + Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection. + + + + + + + + + + cpe:/a:mutasem_abudahab:csvform:0.1 + cpe:/a:mutasem_abudahab:csvform_plus:1.0 + + CVE-2001-1187 + 2001-12-11T00:00:00.000-05:00 + 2008-09-10T15:09:52.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011211 CSVForm (Perl CGI) Remote Execution Vulnerability + + + XF + csvform-cgi-execute-commands(7692) + + + BID + 3668 + + csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter. + + + + + + + + + + + cpe:/a:brian_dorricott:mailto:1.0.7 + cpe:/a:brian_dorricott:mailto:1.0.8 + cpe:/a:brian_dorricott:mailto:1.0.9 + + CVE-2001-1188 + 2001-12-11T00:00:00.000-05:00 + 2008-09-05T16:25:54.530-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3669 + + + BUGTRAQ + 20011211 SPAMMERS DELIGHT: as feeble as feeble can be + + mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields. + + + + + + + + + + + + + + + + + + cpe:/a:ibm:websphere_application_server:3.5 + cpe:/a:ibm:websphere_application_server:3.0.2 + cpe:/a:ibm:websphere_application_server:3.5.1 + cpe:/a:ibm:websphere_application_server:3.5.3 + cpe:/a:ibm:websphere_application_server:3.5.2 + cpe:/a:ibm:websphere_application_server:3.0 + cpe:/a:ibm:websphere_application_server:3.0.2.2 + cpe:/a:ibm:websphere_application_server:3.0.2.1 + cpe:/a:ibm:websphere_application_server:3.0.2.4 + cpe:/a:ibm:websphere_application_server:3.0.2.3 + + CVE-2001-1189 + 2001-12-13T00:00:00.000-05:00 + 2008-09-05T16:25:54.673-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3682 + + + BUGTRAQ + 20011213 IBM WebSphere on UNIX security alert ! + + + XF + websphere-java-plaintext-passwords(7698) + + IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script. + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:8.1 + + CVE-2001-1190 + 2001-12-12T00:00:00.000-05:00 + 2008-09-05T16:25:54.843-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3683 + + + MANDRAKE + MDKSA-2001:091 + + + XF + linux-passwd-weak-encryption(7706) + + The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended. + + + + + + + + + cpe:/a:ibm:tivoli_secureway_policy_director:3.8 + + CVE-2001-1191 + 2001-12-11T00:00:00.000-05:00 + 2008-09-05T16:25:55.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3685 + + + BUGTRAQ + 20011211 Webseal 3.8 + + WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e. + + + + + + + + + cpe:/a:citrix:ica_client:6.1 + + CVE-2001-1192 + 2001-12-13T00:00:00.000-05:00 + 2008-09-05T16:25:55.140-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3688 + + + XF + citrix-ica-gain-root(7697) + + + BUGTRAQ + 20011213 Kikkert Security Advisory: Potentially serious security flaw in Citrix Client + + Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client. + + + + + + + + + cpe:/a:khamil_landross_and_zack_jones:eftp:2.0.8.346 + + CVE-2001-1193 + 2001-12-13T00:00:00.000-05:00 + 2008-09-05T16:25:55.280-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#413875 + + + BID + 3691 + + + BUGTRAQ + 20011213 EFTP 2.0.8.346 directory content disclosure + + + CONFIRM + http://www.eftp.org/releasehistory.html + + + XF + eftp-dot-directory-traversal(7699) + + + OSVDB + 2003 + + Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command. + + + + + + + + + + cpe:/h:zyxel:prestige_1600 + cpe:/h:zyxel:prestige_681 + + CVE-2001-1194 + 2001-12-14T00:00:00.000-05:00 + 2008-09-10T15:09:53.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3695 + + + XF + prestige-dsl-packet-length-dos(7704) + + + BUGTRAQ + 20011218 Re: Zyxel Prestige 681 and 1600 (possibly other?) remote DoS + + + BUGTRAQ + 20011214 Zyxel Prestige 681 and 1600 (possibly other?) remote DoS + + Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly. + + + + + + + + + + cpe:/a:novell:groupwise:6.0 + cpe:/a:novell:groupwise:5.5::enhancement_pack + + CVE-2001-1195 + 2001-12-15T00:00:00.000-05:00 + 2008-09-10T15:09:53.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011215 Novell Groupwise servlet gateway default username and password + + + XF + groupwise-servlet-manager-default(7701) + + + CONFIRM + http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm + + + BID + 3697 + + Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges. + + + + + + + + + cpe:/a:webmin:webmin:0.91 + + CVE-2001-1196 + 2001-12-17T00:00:00.000-05:00 + 2008-09-05T16:25:55.780-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3698 + + + BUGTRAQ + 20011217 webmin 0.91 ../.. problem + + + XF + webmin-dot-directory-traversal(7711) + + + BUGTRAQ + 20011218 Re: webmin 0.91 ../.. problem + + Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument. + + + + + + + + + + cpe:/a:kde:kdeutils:2.2.2 + cpe:/a:kde:kdeutils:2.2 + + CVE-2001-1197 + 2001-12-14T00:00:00.000-05:00 + 2008-09-05T16:25:55.937-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011214 klprfax_filter symlink vulnerability + + + XF + kdeutils-klprfax-symlink(7700) + + + BID + 3694 + + + BUGTRAQ + 20011214 Re: klprfax_filter symlink vulnerability + + klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2001-1198 + 2001-12-15T00:00:00.000-05:00 + 2009-03-04T00:10:00.953-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 3701 + + + BUGTRAQ + 20011215 HP-UX setuid rlpdaemon induced to make illicit file writes + + + XF + hp-rlpd-create-log(7729) + + + + + RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:steve_kneizys:agora.cgi:3.3i + cpe:/a:steve_kneizys:agora.cgi:3.3j + cpe:/a:steve_kneizys:agora.cgi:3.3d + cpe:/a:steve_kneizys:agora.cgi:4.0 + cpe:/a:steve_kneizys:agora.cgi:3.3e + cpe:/a:steve_kneizys:agora.cgi:3.3f + cpe:/a:steve_kneizys:agora.cgi:3.3a + cpe:/a:steve_kneizys:agora.cgi:3.3b + cpe:/a:steve_kneizys:agora.cgi:3.3c + cpe:/a:steve_kneizys:agora.cgi:3.2 + cpe:/a:steve_kneizys:agora.cgi:3.2r + cpe:/a:steve_kneizys:agora.cgi:3.2q + cpe:/a:steve_kneizys:agora.cgi:3.2p + cpe:/a:steve_kneizys:agora.cgi:3.2ja + cpe:/a:steve_kneizys:agora.cgi:4.0b + cpe:/a:steve_kneizys:agora.cgi:3.2i + cpe:/a:steve_kneizys:agora.cgi:4.0c + cpe:/a:steve_kneizys:agora.cgi:3.2j + cpe:/a:steve_kneizys:agora.cgi:4.0d + cpe:/a:steve_kneizys:agora.cgi:3.2g + cpe:/a:steve_kneizys:agora.cgi:3.2h + cpe:/a:steve_kneizys:agora.cgi:3.2m + cpe:/a:steve_kneizys:agora.cgi:3.2n + cpe:/a:steve_kneizys:agora.cgi:3.2k + cpe:/a:steve_kneizys:agora.cgi:4.0a + cpe:/a:steve_kneizys:agora.cgi:3.2l + cpe:/a:steve_kneizys:agora.cgi:3.2a + cpe:/a:steve_kneizys:agora.cgi:3.2b + cpe:/a:steve_kneizys:agora.cgi:3.2e + cpe:/a:steve_kneizys:agora.cgi:3.2f + cpe:/a:steve_kneizys:agora.cgi:3.2c + cpe:/a:steve_kneizys:agora.cgi:3.2d + + CVE-2001-1199 + 2001-12-17T00:00:00.000-05:00 + 2008-09-05T16:25:56.233-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3702 + + + BUGTRAQ + 20011217 Agoracgi v3.3e Cross Site Scripting Vulnerability + + + XF + agora-cgi-css(7708) + + + CONFIRM + http://www.agoracgi.com/security.html + + + OSVDB + 698 + + Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter. + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + + CVE-2001-1200 + 2001-12-17T00:00:00.000-05:00 + 2008-09-05T16:25:56.453-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3703 + + + BUGTRAQ + 20011217 Hot keys permissions bypass under XP + + + XF + winxp-hotkey-execute-programs(7713) + + Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys. + + + + + + + + + cpe:/a:timecop:wmcube_gdk:0.98 + + CVE-2001-1201 + 2001-12-17T00:00:00.000-05:00 + 2008-09-05T16:25:56.610-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3706 + + + CONFIRM + http://www.ne.jp/asahi/linux/timecop/software/wmcube-gdk-0.98p2.tar.gz + + + XF + wmcubegdk-object-file-bo(7720) + + + BUGTRAQ + 20011217 New Advisory + Exploit + + + BUGTRAQ + 20011218 wmcube-gdk is vulnerable to a local exploit + + Buffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description file. + + + + + + + + + + + + cpe:/a:delegate:delegate:7.7.1 + cpe:/a:delegate:delegate:7.7.0 + cpe:/a:delegate:delegate:7.8.1 + cpe:/a:delegate:delegate:7.8.0 + + CVE-2001-1202 + 2001-12-28T00:00:00.000-05:00 + 2008-09-10T15:09:53.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + delegate-proxy-css(7745) + + + BUGTRAQ + 20011228 DeleGate Cross Site Scripting Vulnerability + + + BID + 3749 + + Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error. + + + + + + + + + + cpe:/o:alessandro_rubini:gpm:1.17.18 + cpe:/o:alessandro_rubini:gpm:1.17.8 + + CVE-2001-1203 + 2001-12-27T00:00:00.000-05:00 + 2008-09-10T15:09:54.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-095 + + + XF + linux-gpm-format-string(7748) + + + BID + 3750 + + Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges. + + + + + + + + + cpe:/a:total_pc_solutions:php_rocket_add-in + + CVE-2001-1204 + 2001-12-28T00:00:00.000-05:00 + 2008-09-05T16:25:57.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3751 + + + BUGTRAQ + 20011228 PHP Rocket Add-in (file transversal vulnerability) + + + XF + phprocket-directory-traversal(7749) + + Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. + + + + + + + + + cpe:/a:matrixs_cgi_vault:last_lines:2.0 + + CVE-2001-1205 + 2001-12-30T00:00:00.000-05:00 + 2008-09-10T15:09:54.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 3754 + + + BUGTRAQ + 20011230 lastlines.cgi path traversal and command execution vulns + + Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable. + + + + + + + + + cpe:/a:matrixs_cgi_vault:last_lines:2.0 + + CVE-2001-1206 + 2001-12-30T00:00:00.000-05:00 + 2008-09-10T15:09:54.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3755 + + + BUGTRAQ + 20011230 lastlines.cgi path traversal and command execution vulns + + Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable. + + + + + + + + + + + + cpe:/a:daydream:daydream_bbs:2.12 + cpe:/a:daydream:daydream_bbs:2.10 + cpe:/a:daydream:daydream_bbs:2.9 + cpe:/a:daydream:daydream_bbs:2.13 + + CVE-2001-1207 + 2001-12-30T00:00:00.000-05:00 + 2008-09-05T16:25:57.483-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 3757 + + + XF + daydream-bbs-control-code-bo(7755) + + Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA. + + + + + + + + + + + + cpe:/a:daydream:daydream_bbs:2.12 + cpe:/a:daydream:daydream_bbs:2.10 + cpe:/a:daydream:daydream_bbs:2.9 + cpe:/a:daydream:daydream_bbs:2.13 + + CVE-2001-1208 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:25:57.640-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20011231 Daydream BBS Format strings issue. + + Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code. + + + + + + + + + cpe:/a:abe_timmerman:zml.cgi:0.0 + + CVE-2001-1209 + 2001-12-31T00:00:00.000-05:00 + 2009-04-30T00:08:52.797-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3759 + + + MISC + http://www.jero.cc/zml/zml.html + + + XF + zml-cgi-directory-traversal(7751) + + + BUGTRAQ + 20011231 blackshell2: zml.cgi remote exploit + + + VULNWATCH + 20011231 [VulnWatch] blackshell2: zml.cgi remote exploit + + Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. + + + + + + + + + + + cpe:/h:cisco:ubr920 + cpe:/h:cisco:ubr924 + cpe:/h:cisco:ubr925 + + CVE-2001-1210 + 2001-12-30T00:00:00.000-05:00 + 2008-09-10T15:09:55.557-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-docsis-default-strings(7806) + + + BID + 3758 + + + VULNWATCH + 20020103 Security Problem in Cisco ubr900 Series Routers + + + BUGTRAQ + 20011230 Possible security problem with Cisco ubr900 series routers + + Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings. + + + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:7.0.1 + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:6.4 + cpe:/a:ipswitch:imail:6.3 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:7.0.3 + cpe:/a:ipswitch:imail:7.0.2 + + CVE-2001-1211 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:25:58.093-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3766 + + + BUGTRAQ + 20011231 IMail Web Service User Aliases / Mailing Lists Admin Vulnerability + + + XF + imail-admin-domain-change(7752) + + + MISC + http://support.ipswitch.com/kb/IM-20020301-DM02.htm + + + MISC + http://support.ipswitch.com/kb/IM-20011219-DM01.htm + + Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain. + + + + + + + + + cpe:/a:aktivate:aktivate:1.03 + + CVE-2001-1212 + 2001-12-18T00:00:00.000-05:00 + 2008-09-10T15:09:55.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aktivate-shopping-css(7717) + + + BID + 3714 + + Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter. + + + + + + + + + + cpe:/a:datawizard:ftpxq:2.0 + cpe:/a:datawizard:ftpxq:2.1 + + CVE-2001-1213 + 2001-12-18T00:00:00.000-05:00 + 2008-09-10T15:09:56.367-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ftpxq-default-permissions(7715) + + + BUGTRAQ + 20011218 FTPXQ default install read/write capabilities + + + BID + 3716 + + The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder. + + + + + + + + + cpe:/a:marcus_s._xenakis:unix_manual:1.0 + + CVE-2001-1214 + 2001-12-15T00:00:00.000-05:00 + 2008-09-10T15:09:56.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#672419 + + + BUGTRAQ + 20011215 *ALERT* "Unix Manual" PHP-Script allows arbitrary code execution + + + XF + unixmanual-php-command-execution(7719) + + + BID + 3718 + + manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters. + + + + + + + + + + + cpe:/a:michael_baumer:pfinger:0.7.7 + cpe:/a:michael_baumer:pfinger:0.7.6 + cpe:/a:michael_baumer:pfinger:0.7.5 + + CVE-2001-1215 + 2001-12-20T00:00:00.000-05:00 + 2008-09-10T15:09:56.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + pfinger-plan-format-string(7742) + + + CONFIRM + http://www.xelia.ch/unix/pfinger/ChangeLog + + + BUGTRAQ + 20011220 [CERT-intexxia] pfinger Format String Vulnerability + + + BID + 3725 + + Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2001-1216 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:58.877-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#500203 + + + BID + 3726 + + + XF + oracle-appserver-modplsql-bo(7727) + + + BUGTRAQ + 20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/modplsql.pdf + + Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2001-1217 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:59.017-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#758483 + + + BID + 3727 + + + XF + oracle-appserver-modplsql-traversal(7728) + + + BUGTRAQ + 20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/modplsql.pdf + + Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences. + + + + + + + + + cpe:/a:microsoft:ie:5.0:sp1 + + CVE-2001-1218 + 2001-12-20T00:00:00.000-05:00 + 2008-09-10T15:09:57.273-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011220 E5 (SP1) crash the X server on Solaris2.6 chinese edition + + + BID + 3729 + + Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-1219 + 2001-12-20T00:00:00.000-05:00 + 2008-09-10T15:09:57.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20011220 MSIE DoS Using javascript + + + BID + 3730 + + Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. + + + + + + + + + cpe:/h:d-link:dwl-1000ap:3.2.28_483 + + CVE-2001-1220 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:59.470-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3735 + + + BUGTRAQ + 20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration + + + XF + dlink-ap-public-mib(7733) + + D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges. + + + + + + + + + cpe:/h:d-link:dwl-1000ap:3.2.28_483 + + CVE-2001-1221 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:25:59.610-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3736 + + + BUGTRAQ + 20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration + + D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information. + + + + + + + + + cpe:/a:plesk:plesk_server_administrator:1.0 + + CVE-2001-1222 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:25:59.767-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3737 + + + BUGTRAQ + 20011221 twlc advisory: plesk (psa) allows reading of .php files + + + XF + psa-php-reveal-source(7735) + + Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain. + + + + + + + + + cpe:/a:elsa:lancom_1100_office:0.0 + + CVE-2001-1223 + 2001-12-26T00:00:00.000-05:00 + 2008-09-05T16:25:59.907-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20011226 Phoenix Sistemi Security Advisory: ELSA Lancom 1100 Office Security Problems + + + BID + 3746 + + + XF + elsa-lancom-web-administration(7739) + + The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server. + + + + + + + + + cpe:/a:les_vanbrunt:adrotate_pro:2.0 + + CVE-2001-1224 + 2001-12-23T00:00:00.000-05:00 + 2008-09-05T16:26:00.063-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 3739 + + + BUGTRAQ + 20011223 GOBBLES CGI MARATHON #001 + + + XF + adrotate-sql-execute-commands(7736) + + get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack. + + + + + + + + + + + cpe:/a:hughes:msql:2.0.10 + cpe:/a:hughes:msql:2.0.11 + cpe:/a:hughes:msql:2.0.12 + + CVE-2001-1225 + 2001-12-26T00:00:00.000-05:00 + 2008-09-05T16:26:00.220-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3742 + + + BUGTRAQ + 20011226 msql DoS + + + XF + msql-char-array-dos(7746) + + Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried. + + + + + + + + + + + + + + cpe:/a:adcycle:adcycle:1.16 + cpe:/a:adcycle:adcycle:1.17 + cpe:/a:adcycle:adcycle:1.12 + cpe:/a:adcycle:adcycle:1.13 + cpe:/a:adcycle:adcycle:1.14 + cpe:/a:adcycle:adcycle:1.15 + + CVE-2001-1226 + 2001-12-25T00:00:00.000-05:00 + 2008-09-05T16:26:00.360-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3741 + + + BUGTRAQ + 20011225 GOBBLES CGI MARATHON #002 + + + XF + adcycle-modify-sql-query(7762) + + AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database. + + + + + + + + + + + + + + cpe:/a:zope:zope:2.2.4 + cpe:/a:zope:zope:2.2.5 + cpe:/a:zope:zope:2.2.1 + cpe:/a:zope:zope:2.2.0 + cpe:/a:zope:zope:2.2.3 + cpe:/a:zope:zope:2.2.2 + + CVE-2001-1227 + 2001-10-10T00:00:00.000-04:00 + 2008-09-10T15:09:58.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:115 + + + MANDRAKE + MDKSA-2001:080 + + + XF + zope-fmt-access-methods(7271) + + + BID + 3425 + + + REDHAT + RHSA-2001:072 + + Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. + + + + + + + + + + + cpe:/a:gnu:gzip:1.2.4 + cpe:/a:gnu:gzip:1.2.4a + cpe:/a:gnu:gzip:1.3 + + CVE-2001-1228 + 2001-11-18T00:00:00.000-05:00 + 2008-09-10T15:09:58.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011230 gzip bug w/ patch.. + + + XF + gzip-long-filename-bo(7882) + + + NETBSD + NetBSD-SA2002-002 + + + BID + 3712 + + Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server. + + + + + + + + + + cpe:/a:libshout:libshout:1.0.4 + cpe:/a:icecast:icecast:1.3.9 + + CVE-2001-1229 + 2001-03-12T00:00:00.000-05:00 + 2008-09-10T15:09:59.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2002:063 + + + CONECTIVA + CLA-2001:387 + + + BUGTRAQ + 20010312 Icecast / Libshout remote vulnerabilities + + Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. + + + + + + + + + cpe:/a:icecast:icecast:1.3.10 + + CVE-2001-1230 + 2001-03-13T00:00:00.000-05:00 + 2008-09-05T16:26:01.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-089 + + + REDHAT + RHSA-2002:063 + + + BUGTRAQ + 20010313 More Icecast remote vulnerabilities + + Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. + + + + + + + + + + cpe:/a:novell:groupwise:6.0 + cpe:/a:novell:groupwise:5.5 + + CVE-2001-1231 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:26:01.157-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010814 Fwd: Security Alert: Groupwise - Action Required + + + CONFIRM + http://support.novell.com/padlock/details.htm + + + XF + novell-groupwise-admin-privileges(6998) + + + BID + 3189 + + GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix. + + + + + + + + + cpe:/a:novell:groupwise:5.5 + + CVE-2001-1232 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:26:01.313-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010815 Groupwise Webaccess, NetWare web server, and Novell + + + XF + netware-get-directory-listing(6988) + + + BID + 3188 + + GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get". + + + + + + + + + + + + + + cpe:/a:novell:groupwise_webaccess:5.5 + cpe:/a:novell:netware:5.1 + + CVE-2001-1233 + 2001-08-14T00:00:00.000-04:00 + 2008-09-05T16:26:01.453-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010815 Groupwise Webaccess, NetWare web server, and Novell + + + XF + netware-nds-information-leak(6987) + + Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm. + + + + + + + + + + + cpe:/a:gallery_project:gallery:1.2 + cpe:/a:gallery_project:gallery:1.1 + cpe:/a:gallery_project:gallery:1.2.1 + + CVE-2001-1234 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:26:01.610-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + php-includedir-code-execution(7215) + + + BID + 3397 + + + CONFIRM + http://prdownloads.sourceforge.net/gallery/gallery-1.2.5.tar.gz + + + OSVDB + 1967 + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable. + + + + + + + + + cpe:/a:derek_leung:pslash:0.70 + + CVE-2001-1235 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:09:59.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#847803 + + + BID + 3395 + + + XF + php-includedir-code-execution(7215) + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable. + + + + + + + + + cpe:/a:sebastian_bunka:myphppagetool:0.4.3.1 + + CVE-2001-1236 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:09:59.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#847803 + + + BID + 3394 + + + XF + php-includedir-code-execution(7215) + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable. + + + + + + + + + cpe:/a:peaceworks_computer_consulting:phormation:0.9.1 + + CVE-2001-1237 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:10:00.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#847803 + + + BID + 3393 + + + CONFIRM + http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz + + + XF + php-includedir-code-execution(7215) + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2 + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp1 + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services + + CVE-2001-1238 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:02.203-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + win2k-taskmanager-unkillable-process(6919) + + + BID + 3033 + + + BUGTRAQ + 20010716 W2k: Unkillable Applications + + Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager. + + + + + + + + + cpe:/a:connect_inc.:powernet_ix:6.0 + + CVE-2001-1239 + 2001-06-29T00:00:00.000-04:00 + 2008-09-10T15:10:00.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2992 + + PowerNet IX allows remote attackers to cause a denial of service via a port scan. + + + + + + + + + cpe:/o:engardelinux:secure_linux:1.0.1 + + CVE-2001-1240 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:26:02.530-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ENGARDE + ESA-20010711-02 + + The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access. + + + + + + + + + + + + + + + + + + + + cpe:/a:steve_grimm:un-cgi:1.6.1 + cpe:/a:steve_grimm:un-cgi:1.1 + cpe:/a:steve_grimm:un-cgi:1.0 + cpe:/a:steve_grimm:un-cgi:1.5 + cpe:/a:steve_grimm:un-cgi:1.4 + cpe:/a:steve_grimm:un-cgi:1.6.2 + cpe:/a:steve_grimm:un-cgi:1.3 + cpe:/a:steve_grimm:un-cgi:1.2 + cpe:/a:steve_grimm:un-cgi:1.9 + cpe:/a:steve_grimm:un-cgi:1.8 + cpe:/a:steve_grimm:un-cgi:1.7 + cpe:/a:steve_grimm:un-cgi:1.6 + + CVE-2001-1241 + 2001-07-17T00:00:00.000-04:00 + 2008-09-10T15:10:01.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + uncgi-unexecutable-cgi(6847) + + + CONFIRM + http://www.midwinter.com/~koreth/uncgi.html + + + CONFIRM + http://www.midwinter.com/~koreth/uncgi-changes.html + + + BUGTRAQ + 20010717 multiple vulnerabilities in un-cgi + + + BID + 3057 + + + BUGTRAQ + 20010718 Re: [Khamba Staring <purrcat@edoropolis.org>] multiple + + Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name. + + + + + + + + + + + + + + + + + + + + cpe:/a:steve_grimm:un-cgi:1.6.1 + cpe:/a:steve_grimm:un-cgi:1.1 + cpe:/a:steve_grimm:un-cgi:1.0 + cpe:/a:steve_grimm:un-cgi:1.5 + cpe:/a:steve_grimm:un-cgi:1.4 + cpe:/a:steve_grimm:un-cgi:1.6.2 + cpe:/a:steve_grimm:un-cgi:1.3 + cpe:/a:steve_grimm:un-cgi:1.2 + cpe:/a:steve_grimm:un-cgi:1.9 + cpe:/a:steve_grimm:un-cgi:1.8 + cpe:/a:steve_grimm:un-cgi:1.7 + cpe:/a:steve_grimm:un-cgi:1.6 + + CVE-2001-1242 + 2001-07-17T00:00:00.000-04:00 + 2008-09-10T15:10:01.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + uncgi-dot-directory-traversal(6846) + + + CONFIRM + http://www.midwinter.com/~koreth/uncgi-changes.html + + + BUGTRAQ + 20010717 multiple vulnerabilities in un-cgi + + + BID + 3056 + + + BUGTRAQ + 20010718 Re: [Khamba Staring <purrcat@edoropolis.org>] multiple vulnerabilities in un-cgi + + Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2001-1243 + 2001-07-04T00:00:00.000-04:00 + 2008-09-05T16:26:03.063-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2973 + + + BUGTRAQ + 20010704 NERF Advisory #4: MS IIS local and remote DoS + + + XF + iis-device-asp-dos(6800) + + Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2 + cpe:/o:microsoft:windows_2000::sp1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp6a + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:openbsd:openbsd:2.9 + cpe:/o:openbsd:openbsd:2.8 + cpe:/o:microsoft:windows_nt:4.0 + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_2000:::workstation + cpe:/o:sun:solaris:8.0 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:sun:solaris:7.0 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:hp:vvos:11.04 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:hp:hp-ux:11.0.4 + + CVE-2001-1244 + 2001-07-07T00:00:00.000-04:00 + 2008-09-05T16:26:03.203-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tcp-mss-dos(6824) + + + BID + 2997 + + + BUGTRAQ + 20010708 Small TCP packets == very large overhead == DoS? + + Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:5.0::linux + + CVE-2001-1245 + 2001-07-09T00:00:00.000-04:00 + 2008-09-05T16:26:03.423-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3012 + + + XF + opera-browser-header-bo(6838) + + + BUGTRAQ + 20010712 Re: Opera Browser Heap Overflow (Session Replay Attack) + + Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name. + + + + + + + + + cpe:/a:php:php:4.0.5 + + CVE-2001-1246 + 2001-06-30T00:00:00.000-04:00 + 2008-09-10T15:10:02.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + php-safemode-elevate-privileges(6787) + + + CONFIRM + http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz + + + BID + 2954 + + + REDHAT + RHSA-2003:159 + + + REDHAT + RHSA-2002:129 + + + REDHAT + RHSA-2002:102 + + + BUGTRAQ + 20010630 php breaks safe mode + + PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters. + + + + + + + + + + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.4pl1 + + CVE-2001-1247 + 2001-12-06T00:00:00.000-05:00 + 2012-06-25T00:00:00.000-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + REDHAT + RHSA-2002:035 + + + BUGTRAQ + 20010630 php breaks safe mode + + + CONFIRM + http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz + + + OSVDB + 5440 + + PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files. + + + + + + + + + cpe:/a:vwebserver:vwebserver:1.2.0 + + CVE-2001-1248 + 2001-06-29T00:00:00.000-04:00 + 2008-09-10T15:10:02.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vwebserver-asp-reveal-source(6769) + + + BUGTRAQ + 20010629 4 New vulns. vWebServer and SmallHTTP + + + BID + 2975 + + vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20). + + + + + + + + + cpe:/a:vwebserver:vwebserver:1.2.0 + + CVE-2001-1249 + 2001-06-29T00:00:00.000-04:00 + 2008-09-10T15:10:02.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010629 4 New vulns. vWebServer and SmallHTTP + + + BID + 2978 + + vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names. + + + + + + + + + cpe:/a:vwebserver:vwebserver:1.2.0 + + CVE-2001-1250 + 2001-06-29T00:00:00.000-04:00 + 2008-09-10T15:10:02.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vwebserver-long-url-dos(6771) + + + BUGTRAQ + 20010629 4 New vulns. vWebServer and SmallHTTP + + + BID + 2979 + + vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow. + + + + + + + + + + + + + cpe:/a:max_feoktistov:small_http_server:3.0_beta + cpe:/a:max_feoktistov:small_http_server:1.212 + cpe:/a:max_feoktistov:small_http_server:2.03 + cpe:/a:vwebserver:vwebserver:1.2 + cpe:/a:max_feoktistov:small_http_server:2.01 + + CVE-2001-1251 + 2001-06-29T00:00:00.000-04:00 + 2008-09-10T15:10:02.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + vwebserver-long-url-dos(6771) + + + BID + 2980 + + + BUGTRAQ + 20010629 4 New vulns. vWebServer and SmallHTTP + + SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests. + + + + + + + + + + cpe:/a:pgp:keyserver:7.0.1 + cpe:/a:pgp:keyserver:7.0 + + CVE-2001-1252 + 2001-09-28T00:00:00.000-04:00 + 2008-09-10T15:10:02.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + pgp-keyserver-http-dos(7203) + + + CONFIRM + http://www.pgp.com/support/product-advisories/keyserver.asp + + + BID + 3375 + + + OSVDB + 4193 + + + OSVDB + 1955 + + + BUGTRAQ + 20010928 SNS-43: PGP Keyserver Permissions Misconfiguration + + Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory. + + + + + + + + + + cpe:/a:com2001:alexis_server:2.0 + cpe:/a:com2001:alexis_server:2.1 + + CVE-2001-1253 + 2001-09-27T00:00:00.000-04:00 + 2008-09-05T16:26:04.627-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + alexis-http-plaintext-information(7205) + + + BUGTRAQ + 20010927 Two problems with Alexis/InternetPBX from COM2001 + + Alexis 2.0 and 2.1 in COM2001 InternetPBX stores voicemail passwords in plain text in the com2001.ini file, which could allow local users to make long distance calls as other users. + + + + + + + + + + cpe:/a:com2001:alexis_server:2.0 + cpe:/a:com2001:alexis_server:2.1 + + CVE-2001-1254 + 2001-09-27T00:00:00.000-04:00 + 2008-09-10T15:10:03.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20010927 Two problems with Alexis/InternetPBX from COM2001 + + + BID + 3373 + + Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing. + + + + + + + + + + cpe:/a:mysql:winmysqladmin:1.1 + cpe:/a:mysql:mysql:3.23 + + CVE-2001-1255 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:10:03.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 3381 + + + XF + winmysqladmin-password-plaintext(7206) + + + BUGTRAQ + 20011002 WinMySQLadmin 1.1 Store MySQL password in clear text + + WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database. + + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-1256 + 2001-06-11T00:00:00.000-04:00 + 2009-03-04T00:10:08.280-05:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CONFIRM + http://www.kb.cert.org/vuls/id/TJSL-4Z5Q92 + + + CERT-VN + VU#127435 + + + CIAC + L-093 + + + XF + hpux-kmmodreg-symlink(6656) + + + BID + 2821 + + + BUGTRAQ + 20010604 yet another sym link followers + + + HP + HPSBUX0106-153 + + + + + kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files. + + + + + + + + + + + + + + + cpe:/a:horde:imp:2.2.1 + cpe:/a:horde:imp:2.0 + cpe:/a:horde:imp:2.2.3 + cpe:/a:horde:imp:2.2 + cpe:/a:horde:imp:2.2.2 + cpe:/a:horde:imp:2.2.5 + cpe:/a:horde:imp:2.2.4 + + CVE-2001-1257 + 2001-07-21T00:00:00.000-04:00 + 2011-03-07T21:07:03.987-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-073 + + + BID + 3082 + + + XF + imp-cross-site-scripting(6905) + + + CALDERA + CSSA-2001-027.0 + + + BUGTRAQ + 20010721 IMP 2.2.6 (SECURITY) released + + + CONECTIVA + CLA-2001:410 + + Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email. + + + + + + + + + + + + + + + cpe:/a:horde:imp:2.2.1 + cpe:/a:horde:imp:2.0 + cpe:/a:horde:imp:2.2.3 + cpe:/a:horde:imp:2.2 + cpe:/a:horde:imp:2.2.2 + cpe:/a:horde:imp:2.2.5 + cpe:/a:horde:imp:2.2.4 + + CVE-2001-1258 + 2001-07-21T00:00:00.000-04:00 + 2011-03-07T21:07:04.610-05:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-073 + + + BID + 3083 + + + XF + imp-prefslang-gain-privileges(6906) + + + CALDERA + CSSA-2001-027.0 + + + BUGTRAQ + 20010721 IMP 2.2.6 (SECURITY) released + + + CONECTIVA + CLA-2001:410 + + Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server. + + + + + + + + + cpe:/a:avaya:argent_office + + CVE-2001-1259 + 2001-08-07T00:00:00.000-04:00 + 2008-09-05T16:26:05.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + argent-office-udp-dos(6953) + + + BUGTRAQ + 20010807 Multiple vulnerabilities in Avaya Argent Office + + Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload. + + + + + + + + + cpe:/a:avaya:argent_office + + CVE-2001-1260 + 2001-08-07T00:00:00.000-04:00 + 2008-09-05T16:26:05.687-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + argent-office-weak-encryption(6954) + + + BUGTRAQ + 20010807 Multiple vulnerabilities in Avaya Argent Office + + Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot. + + + + + + + + + cpe:/a:avaya:argent_office:2.1 + + CVE-2001-1261 + 2001-08-07T00:00:00.000-04:00 + 2008-09-05T16:26:05.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + argent-office-change-music(6956) + + + BUGTRAQ + 20010807 Multiple vulnerabilities in Avaya Argent Office + + Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file. + + + + + + + + + cpe:/a:avaya:argent_office:2.1 + + CVE-2001-1262 + 2001-08-07T00:00:00.000-04:00 + 2008-09-05T16:26:06.047-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + argent-office-community-string(6955) + + + BUGTRAQ + 20010807 Multiple vulnerabilities in Avaya Argent Office + + Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string. + + + + + + + + + cpe:/a:pragma_systems:interaccess:4.0_build_5 + + CVE-2001-1263 + 2001-06-06T00:00:00.000-04:00 + 2008-09-10T15:10:08.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pragma-interaccess-dos(6658) + + + BUGTRAQ + 20010606 advisory for Pragma Interaccess + + + BID + 2834 + + telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow. + + + + + + + + + + + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:vvos:4.5 + cpe:/o:hp:vvos:4.0 + + CVE-2001-1264 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:06.343-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#420475 + + + HP + HPSBUX0107-161 + + + CIAC + L-119 + + + XF + hp-virtualvault-mkacct-privilege-elevation(6867) + + + BID + 3072 + + Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges. + + + + + + + + + cpe:/a:ibm:alphaworks_tftp_server:1.21 + + CVE-2001-1265 + 2001-07-20T00:00:00.000-04:00 + 2008-09-05T16:26:06.500-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + ibm-tftp-directory-traversal(6864) + + + BID + 3076 + + + BUGTRAQ + 20010720 IBM TFTP Server for Java vulnerability + + Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack. + + + + + + + + + cpe:/a:doug_neal:dnhttpd:0.4.1 + + CVE-2001-1266 + 2001-07-03T00:00:00.000-04:00 + 2008-09-05T16:26:06.640-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://dnhttpd.sourceforge.net/changelog.html + + + MISC + http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0002.html + + Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'. + + + + + + + + + cpe:/a:gnu:tar:1.13.19 + + CVE-2001-1267 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:26:06.797-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:096 + + + BUGTRAQ + 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers + + + BID + 3024 + + + REDHAT + RHSA-2003:218 + + + REDHAT + RHSA-2002:138 + + + MANDRAKE + MDKSA-2002:066 + + + XF + archive-extraction-directory-traversal(10224) + + + SUNALERT + 47800 + + + HP + HPSBTL0209-068 + + + CONECTIVA + CLA-2002:538 + + + CONFIRM + ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gz + + Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot). + + + + + + + + + cpe:/a:info-zip:unzip:5.42 + + CVE-2001-1268 + 2001-07-12T00:00:00.000-04:00 + 2010-05-25T00:10:12.967-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers + + + CONFIRM + http://www.info-zip.org/pub/infozip/UnZip.html + + + SUNALERT + 1000928 + + + SUNALERT + 47800 + + Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. + + + + + + + + + cpe:/a:info-zip:unzip:5.42 + + CVE-2001-1269 + 2001-07-12T00:00:00.000-04:00 + 2010-05-25T00:10:13.127-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers + + + CONFIRM + http://www.info-zip.org/pub/infozip/UnZip.html + + + SUNALERT + 1000928 + + + SUNALERT + 47800 + + Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character. + + + + + + + + + cpe:/a:pkware:pkzip:4.00 + + CVE-2001-1270 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:26:07.233-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers + + + MISC + http://www.security.nnov.ru/advisories/archdt.asp + + Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files. + + + + + + + + + cpe:/a:rarsoft:rar:2.02 + + CVE-2001-1271 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:26:07.390-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers + + + MISC + http://www.security.nnov.ru/advisories/archdt.asp + + Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames. + + + + + + + + + cpe:/a:wliang:wmtv:0.6.5 + + CVE-2001-1272 + 2001-12-06T00:00:00.000-05:00 + 2008-09-05T16:26:07.530-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + wmtv-execute-commands(7669) + + + BID + 3658 + + + DEBIAN + DSA-092 + + wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.17:pre14 + + CVE-2001-1273 + 2001-02-12T00:00:00.000-05:00 + 2008-09-05T16:26:07.687-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:013 + + + CIAC + L-045 + + The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt). + + + + + + + + + cpe:/a:mysql:mysql:3.23.31 + + CVE-2001-1274 + 2001-01-23T00:00:00.000-05:00 + 2008-09-05T16:26:07.827-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-013 + + + REDHAT + RHSA-2001:003 + + + CONFIRM + http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.3 + + + MANDRAKE + MDKSA-2001:014 + + + CALDERA + CSSA-2001-006.0 + + + FREEBSD + FreeBSD-SA-01:16 + + + CONECTIVA + CLA-2001:375 + + Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges. + + + + + + + + + cpe:/a:mysql:mysql:3.23.31 + + CVE-2001-1275 + 2001-01-19T00:00:00.000-05:00 + 2011-03-07T21:07:05.907-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2001:003 + + + MANDRAKE + MDKSA-2001:014 + + + CALDERA + CSSA-2001-006.0 + + + FREEBSD + FreeBSD-SA-01:16 + + MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. + + + + + + + + + cpe:/a:itcorp:ispell:3.1.20 + + CVE-2001-1276 + 2001-06-21T00:00:00.000-04:00 + 2008-09-05T16:26:08.123-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:074 + + + BUGTRAQ + 20010621 ispell update -- Immunix OS 6.2 + + + MANDRAKE + MDKSA-2001:058 + + + IMMUNIX + IMNX-2001-62-004-01 + + ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file. + + + + + + + + + cpe:/a:wolfram_schneider:makewhatis:1.5i2 + + CVE-2001-1277 + 2001-06-11T00:00:00.000-04:00 + 2008-09-05T16:26:08.280-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:072 + + + BUGTRAQ + 20010611 man 1.5h10 + man 1.5i-4 exploits + + + MISC + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=41805 + + makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters. + + + + + + + + + + + + + cpe:/a:zope:zope:2.2.4 + cpe:/a:zope:zope:2.2.1 + cpe:/a:zope:zope:2.2.0 + cpe:/a:zope:zope:2.2.3 + cpe:/a:zope:zope:2.2.2 + + CVE-2001-1278 + 2001-10-10T00:00:00.000-04:00 + 2008-09-10T15:10:10.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2001:115 + + + MANDRAKE + MDKSA-2001:080 + + + BID + 3425 + + Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. + + + + + + + + + cpe:/a:lbl:tcpdump:3.6.2 + + CVE-2001-1279 + 2001-07-17T00:00:00.000-04:00 + 2008-09-10T15:10:10.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#797201 + + + REDHAT + RHSA-2001:089 + + + BID + 3065 + + + MANDRAKE + MDKSA-2002:032 + + + XF + tcpdump-afs-rpc-bo(7006) + + + CONECTIVA + CLA-2002:480 + + + FREEBSD + FreeBSD-SA-01:48 + + + CALDERA + CSSA-2002-025.0 + + Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1280 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Vulnerabilities in Ipswitch IMail Server 7.04 + + + BID + 3424 + + POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1281 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Vulnerabilities in Ipswitch IMail Server 7.04 + + + BID + 3429 + + Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1282 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Ipswitch Imail 7.04 vulnerabilities + + + BID + 3426 + + Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1283 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Ipswitch Imail 7.04 vulnerabilities + + + BID + 3427 + + The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1284 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Ipswitch Imail 7.04 vulnerabilities + + + BID + 3428 + + Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1285 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Ipswitch Imail 7.04 vulnerabilities + + + BID + 3432 + + Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1286 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020310 IMail Account hijack through the Web Interface + + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011011 Ipswitch Imail 7.04 vulnerabilities + + + BID + 3432 + + Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control. + + + + + + + + + + + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2001-1287 + 2001-10-12T00:00:00.000-04:00 + 2008-09-10T15:10:10.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.ipswitch.com/Support/IMail/news.html + + + BUGTRAQ + 20011012 def-2001-29 + + + BID + 3431 + + Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2001-1288 + 2001-07-27T00:00:00.000-04:00 + 2008-09-10T15:10:10.883-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010731 NT TS / Win 2K and F7 - Enter bug + + + BUGTRAQ + 20010727 bug w2k + + + VULN-DEV + 20010730 RE: bug w2k + + + BUGTRAQ + 20010729 Re: w2k dos + + + BID + 3115 + + + BUGTRAQ + 20010801 F7-Enter bug details & workaround + + Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe. + + + + + + + + + + cpe:/a:id_software:quake_3_arena:1.29g + cpe:/a:id_software:quake_3_arena:1.29f + + CVE-2001-1289 + 2001-07-29T00:00:00.000-04:00 + 2008-09-10T15:10:10.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010730 ADV: Quake 3 Arena 1.29f/g Vulnerability + + + BID + 3123 + + Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters. + + + + + + + + + cpe:/a:active_web_suite_technologies:active_classifieds:1.0::free + + CVE-2001-1290 + 2001-06-28T00:00:00.000-04:00 + 2008-09-10T15:10:11.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + active-classifieds-admin-access(6754) + + + BUGTRAQ + 20010627 Active Web Classifieds failure to authenticate leads to arbitrary code execution + + + BID + 2942 + + + OSVDB + 12326 + + admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter. + + + + + + + + + cpe:/h:3com:superstack_ii_ps_hub:40 + + CVE-2001-1291 + 2001-07-12T00:00:00.000-04:00 + 2008-09-05T16:26:10.437-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + 3com-telnetd-brute-force(6855) + + + BID + 3034 + + + BUGTRAQ + 20010712 3Com TelnetD + + The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing. + + + + + + + + + + + + + + cpe:/a:sambar:sambar_server:5.1:site3 + cpe:/a:sambar:sambar_server:5.1:site2 + cpe:/a:sambar:sambar_server:5.1 + cpe:/a:sambar:sambar_server:5.0 + cpe:/a:sambar:sambar_server:5.2:beta3 + cpe:/a:sambar:sambar_server:5.2:beta2 + + CVE-2001-1292 + 2001-08-13T00:00:00.000-04:00 + 2008-09-05T16:26:10.593-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + sambar-telnet-bo(6973) + + + BUGTRAQ + 20010813 Sambar Telnet Proxy/Server multiple vulnerablietis + + Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password. + + + + + + + + + cpe:/h:3com:3cr29223 + + CVE-2001-1293 + 2001-09-26T00:00:00.000-04:00 + 2008-09-10T15:10:11.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#500027 + + + BUGTRAQ + 20010926 3Com(r) HomeConnect(r) Cable Modem Denial of Service + + + BID + 3366 + + Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of service (crash) via a long HTTP request. + + + + + + + + + + + cpe:/a:avtronics:inetserv:3.1.1 + cpe:/a:avtronics:inetserv:3.2.1 + cpe:/a:avtronics:inetserv:3.0 + + CVE-2001-1294 + 2001-08-22T00:00:00.000-04:00 + 2008-09-10T15:10:11.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + inetserv-webmail-bo(7022) + + + BID + 3224 + + + NTBUGTRAQ + 20000117 Remote Buffer Exploit - InetServ 3.0 + + Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password. + + + + + + + + + cpe:/a:grant_averett:cerberus_ftp_server:1.5 + + CVE-2001-1295 + 2001-08-21T00:00:00.000-04:00 + 2008-09-05T16:26:11.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/5SP0M0055W.html + + + XF + cerberus-ftp-directory-traversal(7004) + + + CONFIRM + http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes + + Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command. + + + + + + + + + cpe:/a:marc_logemann:more.groupware:0.5.1 + + CVE-2001-1296 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:10:12.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + php-includedir-code-execution(7215) + + + BID + 3383 + + + MISC + http://www.moregroupware.org/index.php?action=detail&news_id=24 + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + cpe:/a:actionpoll:actionpoll:1.1.1 + + CVE-2001-1297 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:10:12.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + php-includedir-code-execution(7215) + + + BID + 3384 + + + OSVDB + 1960 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=58331 + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter. + + + + + + + + + cpe:/a:grant_horwood:webodex:1.0 + + CVE-2001-1298 + 2001-10-02T00:00:00.000-04:00 + 2008-09-10T15:10:12.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + php-includedir-code-execution(7215) + + + BID + 3385 + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + cpe:/a:zorbat:zorbstats:0.8 + + CVE-2001-1299 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:26:11.640-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-53RJKV + + + CERT-VN + VU#847803 + + + XF + php-includedir-code-execution(7215) + + + BID + 3386 + + + CONFIRM + http://www.come.to/zorbat/ + + + BUGTRAQ + 20011002 results of semi-automatic source code audit + + Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. + + + + + + + + + + cpe:/a:dynu_systems_inc.:dynu_ftp_server:1.05 + cpe:/a:dynu_systems_inc.:dynu_ftp_server:1.04 + + CVE-2001-1300 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:26:11.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/5KP0N0A55M.html + + + XF + dynuftp-dot-directory-traversal(7045) + + Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command. + + + + + + + + + + cpe:/a:gnu:emacs:20.4 + cpe:/a:xemacs:xemacs:21.1.10 + + CVE-2001-1301 + 2001-08-07T00:00:00.000-04:00 + 2008-09-05T16:26:11.937-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://savannah.gnu.org/cgi-bin/viewcvs/emacs/emacs/lib-src/rcs2log?only_with_tag=EMACS_PRETEST_21_0_95 + + + BUGTRAQ + 20010807 rcs2log + + + XF + rcs2log-tmp-symlink(11210) + + rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2 + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1 + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2001-1302 + 2001-07-18T00:00:00.000-04:00 + 2008-09-05T16:26:12.093-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + win2k-change-network-passwords(6876) + + + BID + 3063 + + + NTBUGTRAQ + 20010718 Changing NT/2000 accounts password from the command line + + The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function. + + + + + + + + + + + + + + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + cpe:/a:checkpoint:firewall-1:4.1:sp1 + cpe:/a:checkpoint:firewall-1:4.1:sp4 + cpe:/a:checkpoint:firewall-1:4.1:sp3 + + CVE-2001-1303 + 2001-07-18T00:00:00.000-04:00 + 2008-09-10T15:10:13.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fw1-securemote-gain-information(6857) + + + BID + 3058 + + + BUGTRAQ + 20010718 Firewall-1 Information leak + + + OSVDB + 588 + + The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication. + + + + + + + + + cpe:/a:nullsoft:shoutcast_server:1.8.2 + + CVE-2001-1304 + 2001-08-03T00:00:00.000-04:00 + 2008-09-05T16:26:12.407-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + shoutcast-http-field-bo(6938) + + + BUGTRAQ + 20010803 Denial of Service in SHOUTcast Server 1.8.2 Linux/w32/? + + Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header. + + + + + + + + + + + cpe:/a:mirabilis:icq:2000.0b_build3278 + cpe:/a:mirabilis:icq:2000.0a + cpe:/a:mirabilis:icq:2001a + + CVE-2001-1305 + 2001-08-17T00:00:00.000-04:00 + 2008-09-10T15:10:13.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + icq-auto-add-user(7028) + + + BID + 3226 + + + BUGTRAQ + 20010822 Hexyn / Securax Advisory #22 - ICQ Forced Auto-Add Users + + ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer. + + + + + + + + + cpe:/a:sun:iplanet_directory_server:4.1.4 + + CVE-2001-1306 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:12.717-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2001-18 + + + MISC + http://www.kb.cert.org/vuls/id/JPLA-4WESMM + + + CERT-VN + VU#276944 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + SGI + 20011102-01-I + + iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:sun:iplanet_directory_server:4.1.4 + + CVE-2001-1307 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:12.860-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2001-18 + + + MISC + http://www.kb.cert.org/vuls/id/JPLA-4WESMM + + + CERT-VN + VU#276944 + + + XF + iplanet-ldap-protos-bo(6893) + + + BID + 3038 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + SGI + 20011102-01-I + + Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:sun:iplanet_directory_server:4.1.4 + + CVE-2001-1308 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:13.017-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.kb.cert.org/vuls/id/JPLA-4WESMM + + + CERT-VN + VU#276944 + + + CERT + CA-2001-18 + + + SGI + 20011102-01-I + + + XF + iplanet-ldap-protos-format-string(6898) + + + BID + 3039 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + CIAC + L-116 + + Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:ibm:secureway_directory:3.2.1 + + CVE-2001-1309 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:13.157-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y + + + CERT-VN + VU#505564 + + + CERT + CA-2001-18 + + + XF + secureway-ldap-protos-dos(6894) + + + BID + 3040 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + CIAC + L-116 + + Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:ibm:secureway_directory:3.2.1 + + CVE-2001-1310 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:13.297-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y + + + CERT-VN + VU#505564 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + secureway-ldap-protos-dos(6894) + + + BID + 3040 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:ibm:lotus_domino_r5:5.0.7a + + CVE-2001-1311 + 2001-07-16T00:00:00.000-04:00 + 2008-09-10T15:10:13.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#583184 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + domino-ldap-protos-bo(6895) + + + BID + 3041 + + + CONFIRM + http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + BUGTRAQ + 20030313 R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression + + Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:ibm:lotus_domino_r5:5.0.7a + + CVE-2001-1312 + 2001-07-16T00:00:00.000-04:00 + 2008-09-10T15:10:14.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#583184 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + domino-ldap-protos-format-string(6896) + + + BID + 3042 + + + CONFIRM + http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:ibm:lotus_domino_r5:5.0.7a + + CVE-2001-1313 + 2001-07-16T00:00:00.000-04:00 + 2008-09-10T15:10:14.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#583184 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + CONFIRM + http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + + + + + cpe:/a:critical_path:injoin_directory_server:2.0 + cpe:/a:critical_path:injoin_directory_server:2.1 + cpe:/a:critical_path:injoin_directory_server:3.0 + cpe:/a:critical_path:injoin_directory_server:4.0 + cpe:/a:critical_path:injoin_directory_server:3.1 + cpe:/a:critical_path:livecontent_directory:8a3 + + CVE-2001-1314 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:13.890-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM + + + CERT-VN + VU#657547 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + BID + 3124 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + BUGTRAQ + 20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable + + Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + + + + + cpe:/a:critical_path:injoin_directory_server:2.0 + cpe:/a:critical_path:injoin_directory_server:2.1 + cpe:/a:critical_path:injoin_directory_server:3.0 + cpe:/a:critical_path:injoin_directory_server:4.0 + cpe:/a:critical_path:injoin_directory_server:3.1 + cpe:/a:critical_path:livecontent_directory:8a3 + + CVE-2001-1315 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.063-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM + + + CERT-VN + VU#657547 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + + BUGTRAQ + 20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable + + Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + + + + cpe:/a:teamware:teamware_office:5.3 + cpe:/a:teamware:teamware_office:5.2 + cpe:/a:teamware:teamware_office:5.4 + cpe:/a:teamware:teamware_office:5.1 + cpe:/a:teamware:teamware_office:5.0 + + CVE-2001-1316 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.217-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4WESNA + + + CERT-VN + VU#688960 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + teamware-ldap-protos-bo(6897) + + + BID + 3044 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Buffer overflows in Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + + + + cpe:/a:teamware:teamware_office:5.3 + cpe:/a:teamware:teamware_office:5.2 + cpe:/a:teamware:teamware_office:5.4 + cpe:/a:teamware:teamware_office:5.1 + cpe:/a:teamware:teamware_office:5.0 + + CVE-2001-1317 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.373-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4WESNA + + + CERT-VN + VU#688960 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for certain BER object types, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:qualcomm:eudora_worldmail_server:2.0 + + CVE-2001-1318 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.547-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4WESNA + + + CERT-VN + VU#717380 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + BID + 3043 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Vulnerabilities in Qualcomm Eudora WorldMail Server may allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:5.5 + + CVE-2001-1319 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.687-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/CFCN-4YAQC7 + + + CERT-VN + VU#763400 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + exchange-ldap-protos-dos(6899) + + + BID + 3045 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + cpe:/a:pgp:keyserver:7.0 + + CVE-2001-1320 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.843-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4WESNK + + + CERT-VN + VU#765256 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + XF + pgp-keyserver-ldap-bo(6900) + + + BID + 3046 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + cpe:/a:oracle:internet_directory:2.1.1 + cpe:/a:oracle:internet_directory:3.0.1 + + CVE-2001-1321 + 2001-07-16T00:00:00.000-04:00 + 2008-09-05T16:26:14.983-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JPLA-4WESNV + + + CERT-VN + VU#869184 + + + CERT + CA-2001-18 + + + CIAC + L-116 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/ + + Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:xinetd:xinetd:2.1.8.9_pre13 + cpe:/a:xinetd:xinetd:2.1.8.9_pre14 + cpe:/a:xinetd:xinetd:2.1.8.9_pre15 + cpe:/a:xinetd:xinetd:2.1.8.9_pre2 + cpe:/a:xinetd:xinetd:2.1.8.9_pre3 + cpe:/a:xinetd:xinetd:2.1.8.8_pre3 + cpe:/a:xinetd:xinetd:2.1.8.9_pre4 + cpe:/a:xinetd:xinetd:2.1.8.9_pre5 + cpe:/a:xinetd:xinetd:2.1.8.9_pre1 + cpe:/a:xinetd:xinetd:2.1.8.9_pre12 + cpe:/a:xinetd:xinetd:2.1.8.9_pre7 + cpe:/a:xinetd:xinetd:2.1.8.9_pre11 + cpe:/a:xinetd:xinetd:2.1.8.9_pre8 + cpe:/a:xinetd:xinetd:2.1.8.9_pre10 + cpe:/a:xinetd:xinetd:2.1.8.9_pre9 + cpe:/a:xinetd:xinetd:2.1.8.8 + + CVE-2001-1322 + 2001-07-10T00:00:00.000-04:00 + 2008-09-10T15:10:15.603-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ENGARDE + ESA-20010621-01 + + + XF + xinetd-insecure-permissions(6657) + + + BID + 2826 + + + REDHAT + RHSA-2001:075 + + + MANDRAKE + MDKSA-2001:055 + + + DEBIAN + DSA-063 + + + IMMUNIX + IMNX-2001-70-024-01 + + + CONECTIVA + CLA-2001:404 + + xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask. + + + + + + + + + cpe:/a:mit:kerberos:5-1.2.2 + + CVE-2001-1323 + 2001-05-16T00:00:00.000-04:00 + 2008-09-05T16:26:15.327-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2001:060 + + + BUGTRAQ + 20010426 Security advisory: krb5 ftpd buffer overflows + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/ftpbuf.txt + + + IMMUNIX + IMNX-2001-70-022-01 + + Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function. + + + + + + + + + + cpe:/a:paul_jarc:idtools:2001-05-31 + cpe:/a:paul_jarc:idtools:2001-06-08 + + CVE-2001-1324 + 2001-06-26T00:00:00.000-04:00 + 2008-09-10T15:10:15.897-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2934 + + + SECTRACK + 1001839 + + + CONFIRM + http://multivac.cwru.edu/idtools/admin_idtools.tar.bz2 + + cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2001-1325 + 2001-04-20T00:00:00.000-04:00 + 2008-09-05T16:26:15.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + ie-xml-stylesheets-scripting(6448) + + + BID + 2633 + + + BUGTRAQ + 20010420 XML scripting in IE, Outlook Express + + Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH). + + + + + + + + + cpe:/a:qualcomm:eudora:5.1 + + CVE-2001-1326 + 2001-05-29T00:00:00.000-04:00 + 2008-09-05T16:26:15.780-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2796 + + + BUGTRAQ + 20010528 feeble.hey!dora.exploit part.II + + Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments. + + + + + + + + + cpe:/a:berkeley_softworks:pmake:2.1.35 + + CVE-2001-1327 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:26:15.937-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + TURBO + TLSA2001024 + + + XF + pmake-binary-gain-privileges(9988) + + pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local users to gain privileges by exploiting vulnerabilities in pmake or programs that are used by pmake. + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.8 + cpe:/o:sun:sunos:5.7 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.4::x86 + cpe:/o:sun:sunos:5.8::x86 + cpe:/o:sun:sunos:5.4 + cpe:/o:sun:sunos:5.7::x86 + cpe:/o:sun:sunos:5.5 + cpe:/o:sun:sunos:5.6::x86 + cpe:/o:sun:sunos:5.6 + + CVE-2001-1328 + 2001-06-22T00:00:00.000-04:00 + 2008-09-05T16:26:16.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + AUSCERT + AA-2001.03 + + + XF + solaris-ypbind-bo(6828) + + + CIAC + L-103 + + + SUN + 00203 + + + + + Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code. + + + + + + + + + cpe:/o:ibm:aix:4.2.0 + + CVE-2001-1329 + 2001-06-11T00:00:00.000-04:00 + 2008-09-05T16:26:16.310-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010611 rsh bufferoverflow on AIX 4.2 + + Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument. + + + + + + + + + cpe:/o:ibm:aix:4.2.0 + + CVE-2001-1330 + 2001-06-11T00:00:00.000-04:00 + 2008-09-05T16:26:16.467-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010611 rsh bufferoverflow on AIX 4.2 + + Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument. + + + + + + + + + + cpe:/o:progeny:debian:1.0 + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-1331 + 2001-05-03T00:00:00.000-04:00 + 2008-09-10T15:10:16.383-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-056 + + + CONFIRM + http://online.securityfocus.com/advisories/3307 + + + BID + 2720 + + mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks. + + + + + + + + + cpe:/a:easy_software_products:cups:1.1.5 + + CVE-2001-1332 + 2001-05-10T00:00:00.000-04:00 + 2008-09-05T16:26:16.767-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MANDRAKE + MDKSA-2001:048 + + + SUSE + SuSE-SA:2002:005 + + + CONECTIVA + CLA-2001:386 + + + CONECTIVA + CLA-2001:384 + + Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code. + + + + + + + + + cpe:/a:easy_software_products:cups:1.1.5 + + CVE-2001-1333 + 2001-05-10T00:00:00.000-04:00 + 2008-09-05T16:26:16.907-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2001:048 + + + SUSE + SuSE-SA:2002:005 + + + CONECTIVA + CLA-2001:386 + + + CONECTIVA + CLA-2001:384 + + Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files. + + + + + + + + + + cpe:/a:phpslash:phpslash:0.6.1 + cpe:/a:phpslash:phpslash:0.5.3.2 + + CVE-2001-1334 + 2002-05-19T00:00:00.000-04:00 + 2008-09-10T15:10:18.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://marc.theaimsgroup.com/?l=phpslash&m=99029398904419&w=2 + + + BID + 2724 + + + XF + phpslash-block-read-files(9990) + + + BUGTRAQ + 20010515 PHPSlash : potential vulnerability in URL blocks + + Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL. + + + + + + + + + cpe:/a:aclogic:cesarftp:0.98b + + CVE-2001-1335 + 2001-05-27T00:00:00.000-04:00 + 2008-09-10T15:10:19.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cesarftp-directory-traversal(6606) + + + BUGTRAQ + 20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption + + + BID + 2786 + + Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot). + + + + + + + + + cpe:/a:aclogic:cesarftp:0.98b + + CVE-2001-1336 + 2001-05-28T00:00:00.000-04:00 + 2008-09-10T15:10:19.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cesarftp-settings-plaintext-password(6608) + + + BUGTRAQ + 20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption + + + BID + 2785 + + CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_embedded-webserver + + CVE-2001-1337 + 2001-05-21T00:00:00.000-04:00 + 2008-09-05T16:26:17.517-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2774 + + + BUGTRAQ + 20010524 IPC@Chip Security + + + XF + ipcchip-http-dos(6594) + + Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_telnetd_server + + CVE-2001-1338 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:26:17.657-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#198979 + + + BUGTRAQ + 20010524 IPC@Chip Security + + + BID + 2773 + + + XF + ipcchip-telnet-verify-account(6595) + + + BUGTRAQ + 20010602 IPC@Chip - Fixes + + Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_embedded-webserver + + CVE-2001-1339 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:26:17.810-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#198979 + + + BID + 2771 + + + BUGTRAQ + 20010524 IPC@Chip Security + + + XF + ipcchip-telnet-bruteforce-passwords(6605) + + + BUGTRAQ + 20010602 IPC@Chip - Fixes + + Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_telnetd_server + + CVE-2001-1340 + 2002-05-21T00:00:00.000-04:00 + 2008-09-10T15:10:19.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#756019 + + + BID + 2772 + + + BUGTRAQ + 20010524 IPC@Chip Security + + + XF + ipcchip-telnet-admin-lockout(6596) + + + BUGTRAQ + 20010602 IPC@Chip - Fixes + + Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_embedded-webserver + + CVE-2001-1341 + 2001-05-24T00:00:00.000-04:00 + 2008-09-10T15:10:19.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#574739 + + + BID + 2767 + + + BUGTRAQ + 20010524 IPC@Chip Security + + + XF + ipcchip-chipcfg-gain-information(6600) + + + BUGTRAQ + 20010602 IPC@Chip - Fixes + + The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program. + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.12::win32 + cpe:/a:apache:http_server:1.3.14::win32 + cpe:/a:apache:http_server:1.3.15::win32 + cpe:/a:apache:http_server:1.3.16::win32 + cpe:/a:apache:http_server:1.3.17::win32 + cpe:/a:apache:http_server:1.3.18::win32 + cpe:/a:apache:http_server:1.3.19::win32 + + CVE-2001-1342 + 2001-05-12T00:00:00.000-04:00 + 2008-09-10T15:10:19.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + apache-server-dos(6527) + + + CONFIRM + http://www.apacheweek.com/issues/01-05-25 + + + CONFIRM + http://bugs.apache.org/index.cgi/full/7522 + + + BID + 2740 + + + BUGTRAQ + 20010412 Apache Win32 8192 chars string bug + + + BUGTRAQ + 20010522 [Announce] Apache 1.3.20 Released + + Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer. + + + + + + + + + + cpe:/a:cgicentral:webstore_400cs:4.14 + cpe:/a:cgicentral:webstore_400:4.14 + + CVE-2001-1343 + 2001-06-12T00:00:00.000-04:00 + 2008-09-05T16:26:18.420-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2861 + + + XF + webstore-cgi-command-execution(6685) + + + BUGTRAQ + 20010612 bug + + ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter. + + + + + + + + + + cpe:/a:cgicentral:webstore_400cs:4.14 + cpe:/a:cgicentral:webstore_400:4.14 + + CVE-2001-1344 + 2001-06-12T00:00:00.000-04:00 + 2008-09-05T16:26:18.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + webstore-cgi-command-execution(6685) + + + BID + 2860 + + + BUGTRAQ + 20010612 bug + + WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot). + + + + + + + + + cpe:/a:jetico:bestcrypt:0.7 + + CVE-2001-1345 + 2001-06-05T00:00:00.000-04:00 + 2008-09-05T16:26:18.717-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + bestcrypt-bctool-gain-privileges(6648) + + + BID + 2820 + + + CONFIRM + http://www.jetico.com/index.htm#/linux.htm + + + BUGTRAQ + 20010604 Fatal flaw in BestCrypt <= v0.7 (Linux) + + bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program. + + + + + + + + + + cpe:/a:ca:arcserve_backup:6.63 + cpe:/a:ca:arcserve_backup:6.61 + + CVE-2001-1346 + 2001-05-18T00:00:00.000-04:00 + 2008-09-10T15:10:20.180-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20010518 tmp-races in ARCservIT Unix Client + + + BID + 2748 + + + BID + 2741 + + Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2001-1347 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:26:19.013-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2764 + + + XF + win2k-debug-elevate-privileges(6590) + + + BUGTRAQ + 20010524 Elevation of privileges with debug registers on Win2K + + Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:twig_development_team:twig:2.0_beta1 + cpe:/a:twig_development_team:twig:2.0_beta2 + cpe:/a:twig_development_team:twig:2.2.3 + cpe:/a:twig_development_team:twig:2.2.2 + cpe:/a:twig_development_team:twig:2.2.1 + cpe:/a:twig_development_team:twig:2.1.1 + cpe:/a:twig_development_team:twig:2.6 + cpe:/a:twig_development_team:twig:2.4 + cpe:/a:twig_development_team:twig:2.0.3 + cpe:/a:twig_development_team:twig:2.5 + cpe:/a:twig_development_team:twig:2.0.2 + cpe:/a:twig_development_team:twig:2.3.1 + cpe:/a:twig_development_team:twig:2.6.1 + cpe:/a:twig_development_team:twig:2.3.2 + cpe:/a:twig_development_team:twig:2.3 + cpe:/a:twig_development_team:twig:2.0.1 + cpe:/a:twig_development_team:twig:2.2 + cpe:/a:twig_development_team:twig:2.1 + cpe:/a:twig_development_team:twig:2.0 + cpe:/a:twig_development_team:twig:2.5.1 + cpe:/a:twig_development_team:twig:2.0_beta3 + + CVE-2001-1348 + 2001-05-28T00:00:00.000-04:00 + 2008-09-05T16:26:19.170-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2791 + + + XF + twig-webmail-query-modification(6619) + + + MISC + http://twig.screwdriver.net/index.php3 + + + BUGTRAQ + 20010528 TWIG SQL query bugs + + TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter. + + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.10 + cpe:/a:sendmail:sendmail:8.11.2 + cpe:/a:sendmail:sendmail:8.12:beta7 + cpe:/a:sendmail:sendmail:8.11.3 + cpe:/a:sendmail:sendmail:8.11.0 + cpe:/a:sendmail:sendmail:8.11.1 + cpe:/a:sendmail:sendmail:8.10.2 + cpe:/a:sendmail:sendmail:8.10.1 + + CVE-2001-1349 + 2001-05-28T00:00:00.000-04:00 + 2008-09-05T16:26:19.373-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 2794 + + + BINDVIEW + 20010528 Unsafe Signal Handling in Sendmail + + + BUGTRAQ + 20010529 sendmail 8.11.4 and 8.12.0.Beta10 available (fwd) + + + CONFIRM + http://archives.neohapsis.com/archives/sendmail/2001-q2/0001.html + + + XF + sendmail-signal-handling(6633) + + + REDHAT + RHSA-2001:106 + + Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers. + + + + + + + + + cpe:/a:namazu:namazu:2.0.7 + + CVE-2001-1350 + 2001-11-25T00:00:00.000-05:00 + 2008-09-05T16:26:19.547-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://search.namazu.org/ml/namazu-devel-ja/msg02114.html + + + REDHAT + RHSA-2001:162 + + Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter. + + + + + + + + + cpe:/a:namazu:namazu:2.0.8 + + CVE-2001-1351 + 2001-12-25T00:00:00.000-05:00 + 2008-09-05T16:26:19.703-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:162 + + + XF + linux-namazu-css(7875) + + + OSVDB + 5690 + + Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers. + + + + + + + + + cpe:/a:namazu:namazu:2.0.9 + + CVE-2001-1352 + 2001-12-27T00:00:00.000-05:00 + 2008-09-05T16:26:19.843-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020109 Details on the updated namazu packages that are available + + + REDHAT + RHSA-2001:179 + + + XF + linux-namazu-css(7875) + + + OSVDB + 5691 + + + BUGTRAQ + 20011227 Re: [RHSA-2001:162-04] Updated namazu packages are available + + Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter. + + + + + + + + + cpe:/a:aladdin_enterprises:ghostscript:6.51 + + CVE-2001-1353 + 2001-09-18T00:00:00.000-04:00 + 2008-09-05T16:26:20.000-04:00 + + + 2.6 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:138 + + + MISC + http://marc.theaimsgroup.com/?l=lprng&m=100083210910857&w=2 + + + REDHAT + RHSA-2001:112 + + + HP + HPSBUX0112-009 + + ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled. + + + + + + + + + + + + + + + + + + + + cpe:/a:netwin:dmail:2.8f + cpe:/a:netwin:surgeftp:1.0b + cpe:/a:netwin:dmail:2.8g + cpe:/a:netwin:dmail:2.8h + cpe:/a:netwin:dmail:2.7 + cpe:/a:netwin:dmail:2.8i + cpe:/a:netwin:dmail:2.7r + cpe:/a:netwin:dmail:2.7q + cpe:/a:netwin:surgeftp:2.0b + cpe:/a:netwin:surgeftp:2.0a + cpe:/a:netwin:dmail:2.8e + cpe:/a:netwin:dmail:2.5d + + CVE-2001-1354 + 2001-07-20T00:00:00.000-04:00 + 2008-09-05T16:26:20.140-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + netwin-nwauth-weak-encryption(6866) + + + BID + 3075 + + + BUGTRAQ + 20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows + + NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password. + + + + + + + + + + + + + + + + + + + + cpe:/a:netwin:dmail:2.8f + cpe:/a:netwin:surgeftp:1.0b + cpe:/a:netwin:dmail:2.8g + cpe:/a:netwin:dmail:2.8h + cpe:/a:netwin:dmail:2.7 + cpe:/a:netwin:dmail:2.8i + cpe:/a:netwin:dmail:2.7r + cpe:/a:netwin:dmail:2.7q + cpe:/a:netwin:surgeftp:2.0b + cpe:/a:netwin:surgeftp:2.0a + cpe:/a:netwin:dmail:2.8e + cpe:/a:netwin:dmail:2.5d + + CVE-2001-1355 + 2001-07-20T00:00:00.000-04:00 + 2008-09-05T16:26:20.327-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + netwin-nwauth-bo(6865) + + + BID + 3077 + + + BUGTRAQ + 20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows + + Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command. + + + + + + + + + + + + + + cpe:/a:netwin:surgeftp:2.0f + cpe:/a:netwin:surgeftp:2.0e + cpe:/a:netwin:surgeftp:2.0d + cpe:/a:netwin:surgeftp:2.0c + cpe:/a:netwin:surgeftp:2.0b + cpe:/a:netwin:surgeftp:2.0a + + CVE-2001-1356 + 2001-08-04T00:00:00.000-04:00 + 2008-09-05T16:26:20.500-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3157 + + + XF + surgeftp-weak-password-encryption(6961) + + + BUGTRAQ + 20010804 SurgeFTP admin account bruteforcable + + NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021. + + + + + + + + + cpe:/a:phpheaven:phpmychat:0.14.5 + + CVE-2001-1357 + 2001-02-07T00:00:00.000-05:00 + 2008-09-05T16:26:20.657-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.phpheaven.net/projects/phpMyChat/changes.php3 + + Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables. + + + + + + + + + cpe:/a:phpheaven:phpmychat:0.14.4 + + CVE-2001-1358 + 2001-02-07T00:00:00.000-05:00 + 2008-09-05T16:26:20.810-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.phpheaven.net/projects/phpMyChat/changes.php3 + + Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter. + + + + + + + + + + + cpe:/a:caldera:volution:1.0.7 + cpe:/a:caldera:volution:1.0 + cpe:/a:caldera:volution:1.0.6 + + CVE-2001-1359 + 2001-06-08T00:00:00.000-04:00 + 2008-09-05T16:26:20.953-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + volution-authentication-failure-access(6672) + + + BID + 2850 + + + CALDERA + CSSA-2001-021.0 + + Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server. + + + + + + + + + cpe:/a:mostang:sane:1.0.5 + + CVE-2001-1360 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.107-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + + CONFIRM + ftp://ftp.mostang.com/pub/sane/sane-1.0.8/sane-backends-1.0.8.tar.gz + + Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned. + + + + + + + + + cpe:/a:twig_development_team:twig:2.7.1 + + CVE-2001-1361 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.263-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://twig.screwdriver.net/file.php3?file=CHANGELOG + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links. + + + + + + + + + cpe:/a:horsburgh:npulse:0.53p4 + + CVE-2001-1362 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.407-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://freshmeat.net/releases/51981/ + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + Vulnerability in the server for nPULSE before 0.53p4. + + + + + + + + + cpe:/a:phpwebsite_development_team:phpwebsite:0.7.9 + + CVE-2001-1363 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.560-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://phpwebsite.appstate.edu/downloads/0.7.9/phpWebSite-en-0.7.9.tar.gz + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges. + + + + + + + + + cpe:/a:project_purple:autodns:0.0.4 + + CVE-2001-1364 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.703-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + + CONFIRM + ftp://ftp.earth.li/pub/projectpurple/autodns-0.0.4.tar.gz + + Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified. + + + + + + + + + cpe:/a:osi_codes_inc.:intragnat:1.4 + + CVE-2001-1365 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:21.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + + CONFIRM + http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0011.html + + Vulnerability in IntraGnat before 1.4. + + + + + + + + + cpe:/a:netscript_project:netscript:1.6.3 + + CVE-2001-1366 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:22.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://netscript.sourceforge.net/netscript-1.6.2.tgz + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information. + + + + + + + + + cpe:/a:phpslice:phpslice:0.1.6 + + CVE-2001-1367 + 2001-07-19T00:00:00.000-04:00 + 2011-03-07T21:07:15.220-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + phpslice-checkaccess-function-privileges(9649) + + + CONFIRM + http://phpslice.org/comments.php?aid=1031& + + + VULNWATCH + 20010719 [VulnWatch] Changelog maddness (14 various broken apps) + + The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges. + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.0 + + CVE-2001-1368 + 2001-06-11T00:00:00.000-04:00 + 2008-09-05T16:26:22.297-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hp-virtualvault-iws-corrupt-data(6697) + + + HP + HPSBUX0106-152 + + Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data. + + + + + + + + + + cpe:/a:leon_j_breedt:pam-pgsql:0.5.1 + cpe:/a:leon_j_breedt:pam-pgsql:0.5.2 + + CVE-2001-1369 + 2001-09-10T00:00:00.000-04:00 + 2008-09-10T15:10:23.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + postgresql-pam-authentication-module(7110) + + + BID + 3319 + + + FREEBSD + FreeBSD-SA-02:14 + + Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields. + + + + + + + + + + + + cpe:/a:phplib_team:phplib:7.2 + cpe:/a:phplib_team:phplib:7.2c + cpe:/a:phplib_team:phplib:7.2b + cpe:/a:phplib_team:phplib:7.2.1 + + CVE-2001-1370 + 2001-07-21T00:00:00.000-04:00 + 2008-09-05T16:26:22.607-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3079 + + + DEBIAN + DSA-073 + + + BUGTRAQ + 20010726 TSLSA-2001-0014 - PHPLib + + + BUGTRAQ + 20010722 [SEC] Hole in PHPLib 7.2 prepend.php3 + + + XF + phplib-script-execution(6892) + + + BUGTRAQ + 20010721 IMP 2.2.6 (SECURITY) released + + + CONECTIVA + CLA-2001:410 + + + CALDERA + CSSA-2001-027.0 + + prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2001-1371 + 2002-02-06T00:00:00.000-05:00 + 2008-09-05T16:26:22.763-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT + CA-2002-08 + + + CERT-VN + VU#736923 + + + BID + 4289 + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + XF + oracle-appserver-soap-components(8449) + + + CONFIRM + http://technet.oracle.com/deploy/security/pdf/ias_soap_alert.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2001-1372 + 2002-02-06T00:00:00.000-05:00 + 2008-09-05T16:26:22.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-08 + + + CERT-VN + VU#278971 + + + BID + 3341 + + + BUGTRAQ + 20010921 Response to "Path disclosure vulnerability in Oracle 9i and 8i + + + MISC + http://www.nii.co.in/research.html + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/jspexecute_alert.pdf + + + XF + oracle-jsp-reveal-path(7135) + + + BUGTRAQ + 20010917 Yet another path disclosure vulnerability + + Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message. + + + + + + + + + + + + + + + + cpe:/a:zonelabs:zonealarm:2.6 + cpe:/a:zonelabs:zonealarm:2.5 + cpe:/a:zonelabs:zonealarm:2.2 + cpe:/a:zonelabs:zonealarm:2.4::pro + cpe:/a:zonelabs:zonealarm:2.1 + cpe:/a:zonelabs:zonealarm:2.4 + cpe:/a:zonelabs:zonealarm:2.6::pro + cpe:/a:zonelabs:zonealarm:2.3 + + CVE-2001-1373 + 2001-07-18T00:00:00.000-04:00 + 2008-09-05T16:26:23.060-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + zonealarm-bypass-mailsafe(6877) + + + CONFIRM + http://www.zonelabs.com/products/zap/rel_history.html#2.6.362 + + + BID + 3055 + + + BUGTRAQ + 20010718 ZoneAlarm Pro + + MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send potentially dangerous attachments. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:don_libes:expect:5.29 + cpe:/o:conectiva:linux:6.0 + cpe:/a:don_libes:expect:5.21 + cpe:/a:don_libes:expect:5.0 + cpe:/a:don_libes:expect:5.22 + cpe:/a:don_libes:expect:5.23 + cpe:/a:don_libes:expect:5.24 + cpe:/a:don_libes:expect:5.25 + cpe:/a:don_libes:expect:5.26 + cpe:/a:don_libes:expect:5.27 + cpe:/a:don_libes:expect:5.28 + cpe:/a:don_libes:expect:5.8 + cpe:/a:don_libes:expect:3 + cpe:/a:don_libes:expect:5.7 + cpe:/a:don_libes:expect:2 + cpe:/a:don_libes:expect:5.6 + cpe:/a:don_libes:expect:1 + cpe:/a:don_libes:expect:5.5 + cpe:/a:don_libes:expect:0 + cpe:/a:don_libes:expect:5.4 + cpe:/a:don_libes:expect:5.3 + cpe:/a:don_libes:expect:5.2 + cpe:/a:don_libes:expect:5.20 + cpe:/o:conectiva:linux:7.0 + cpe:/a:don_libes:expect:5.1 + cpe:/a:don_libes:expect:4 + cpe:/a:don_libes:expect:5.9 + cpe:/a:don_libes:expect:5.18 + cpe:/a:don_libes:expect:5.19 + cpe:/a:don_libes:expect:5.16 + cpe:/a:don_libes:expect:5.17 + cpe:/a:don_libes:expect:5.14 + cpe:/a:don_libes:expect:5.15 + cpe:/a:don_libes:expect:5.12 + cpe:/a:don_libes:expect:5.13 + cpe:/a:don_libes:expect:5.10 + cpe:/o:redhat:linux:7.0 + cpe:/a:don_libes:expect:5.11 + cpe:/a:don_libes:expect:5.31 + cpe:/a:don_libes:expect:5.30 + + CVE-2001-1374 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:23.217-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + expect-insecure-library-search(6870) + + + BID + 3074 + + + CONFIRM + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224 + + + CONFIRM + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187 + + + REDHAT + RHSA-2002:148 + + + MANDRAKE + MDKSA-2002:060 + + + CONECTIVA + CLA-2001:409 + + expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd. + + + + + + + + + + + + + + + cpe:/o:conectiva:linux:6.0 + cpe:/o:conectiva:linux:7.0 + cpe:/o:redhat:linux:7.0 + + CVE-2001-1375 + 2001-07-19T00:00:00.000-04:00 + 2008-09-05T16:26:23.467-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3073 + + + XF + tcltk-insecure-library-search(6869) + + + CONFIRM + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28226 + + + REDHAT + RHSA-2002:148 + + + MANDRAKE + MDKSA-2002:060 + + + CONECTIVA + CLA-2001:409 + + tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:icradius:icradius:0.18.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.2 + cpe:/a:radiusclient:radiusclient:0.3.1 + cpe:/a:xtradius:xtradius:1.1_pre1 + cpe:/a:openradius:openradius:0.9.3 + cpe:/a:ascend:radius:1.16 + cpe:/a:gnu:radius:0.92.1 + cpe:/a:livingston:radius:2.0.1 + cpe:/a:openradius:openradius:0.8 + cpe:/a:openradius:openradius:0.9 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6_.0 + cpe:/a:openradius:openradius:0.9.2 + cpe:/a:openradius:openradius:0.9.1 + cpe:/a:gnu:radius:0.93 + cpe:/a:gnu:radius:0.94 + cpe:/a:gnu:radius:0.95 + cpe:/a:freeradius:freeradius:0.2 + cpe:/a:lucent:radius:2.1 + cpe:/a:freeradius:freeradius:0.3 + cpe:/a:lucent:radius:2.0 + cpe:/a:livingston:radius:2.1 + cpe:/a:yard_radius:yard_radius:1.0.16 + cpe:/a:yard_radius:yard_radius:1.0.17 + cpe:/a:yard_radius:yard_radius:1.0.19 + cpe:/a:yard_radius:yard_radius:1.0.18 + cpe:/a:yard_radius:yard_radius:1.0_pre13 + cpe:/a:icradius:icradius:0.18 + cpe:/a:icradius:icradius:0.17b + cpe:/a:icradius:icradius:0.17 + cpe:/a:livingston:radius:2.0 + cpe:/a:icradius:icradius:0.16 + cpe:/a:icradius:icradius:0.15 + cpe:/a:icradius:icradius:0.14 + cpe:/a:yard_radius:yard_radius:1.0_pre15 + cpe:/a:yard_radius:yard_radius:1.0_pre14 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.5 + cpe:/a:lucent:radius:2.0.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.4 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.3 + + CVE-2001-1376 + 2002-03-04T00:00:00.000-05:00 + 2008-09-05T16:26:23.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-06 + + + CERT-VN + VU#589523 + + + BID + 3530 + + + REDHAT + RHSA-2002:030 + + + BUGTRAQ + 20011113 More problems with RADIUS (protocol and implementations) + + + SUSE + SuSE-SA:2002:013 + + + BUGTRAQ + 20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations + + + CONECTIVA + CLA-2002:466 + + Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:icradius:icradius:0.18.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.2 + cpe:/a:radiusclient:radiusclient:0.3.1 + cpe:/a:xtradius:xtradius:1.1_pre1 + cpe:/a:xtradius:xtradius:1.1_pre2 + cpe:/a:openradius:openradius:0.9.3 + cpe:/a:gnu:radius:0.92.1 + cpe:/a:livingston:radius:2.0.1 + cpe:/a:openradius:openradius:0.8 + cpe:/a:openradius:openradius:0.9 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6_.0 + cpe:/a:openradius:openradius:0.9.2 + cpe:/a:openradius:openradius:0.9.1 + cpe:/a:gnu:radius:0.93 + cpe:/a:gnu:radius:0.94 + cpe:/a:gnu:radius:0.95 + cpe:/a:freeradius:freeradius:0.2 + cpe:/a:lucent:radius:2.1 + cpe:/a:freeradius:freeradius:0.3 + cpe:/a:lucent:radius:2.0 + cpe:/a:livingston:radius:2.1 + cpe:/a:yard_radius:yard_radius:1.0.16 + cpe:/a:yard_radius:yard_radius:1.0.17 + cpe:/a:yard_radius:yard_radius:1.0.19 + cpe:/a:yard_radius:yard_radius:1.0.18 + cpe:/a:yard_radius:yard_radius:1.0_pre13 + cpe:/a:icradius:icradius:0.18 + cpe:/a:icradius:icradius:0.17b + cpe:/a:icradius:icradius:0.17 + cpe:/a:livingston:radius:2.0 + cpe:/a:icradius:icradius:0.16 + cpe:/a:icradius:icradius:0.15 + cpe:/a:icradius:icradius:0.14 + cpe:/a:yard_radius:yard_radius:1.0_pre15 + cpe:/a:yard_radius:yard_radius:1.0_pre14 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.5 + cpe:/a:lucent:radius:2.0.1 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.4 + cpe:/a:miquel_van_smoorenburg_cistron:radius:1.6.3 + + CVE-2001-1377 + 2002-03-04T00:00:00.000-05:00 + 2008-09-05T16:26:23.873-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#936683 + + + CERT + CA-2002-06 + + + BID + 4230 + + + XF + radius-vendor-attribute-dos(8354) + + + REDHAT + RHSA-2002:030 + + + SUSE + SuSE-SA:2002:013 + + + FREEBSD + FreeBSD-SN-02:02 + + + BUGTRAQ + 20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations + + + CONECTIVA + CLA-2002:466 + + Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + + CVE-2001-1378 + 2001-09-06T00:00:00.000-04:00 + 2011-02-16T00:00:00.000-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + REDHAT + RHSA-2001:103 + + + MISC + http://lists.ccil.org/pipermail/fetchmail-announce/2001-March/000015.html + + fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files. + + + + + + + + + + cpe:/a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:0.9.6 + cpe:/a:guiseppe_tanzilli_and_matthias_eckermann:mod_auth_pgsql:0.9.5 + + CVE-2001-1379 + 2001-08-29T00:00:00.000-04:00 + 2008-09-10T15:10:24.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + apache-postgresql-authentication-module(7054) + + + BUGTRAQ + 20010829 RUS-CERT Advisory 2001-08:01 + + + REDHAT + RHSA-2001:124 + + + VULNWATCH + 20010829 [VulnWatch] RUS-CERT Advisory 2001-08:01 + + + FREEBSD + FreeBSD-SA-02:03 + + + BID + 3251 + + + CONECTIVA + CLA-2001:427 + + The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name. + + + + + + + + + cpe:/a:openbsd:openssh:2.9.9 + + CVE-2001-1380 + 2001-10-18T00:00:00.000-04:00 + 2008-09-05T16:26:24.420-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#905795 + + + REDHAT + RHSA-2001:114 + + + BUGTRAQ + 20010926 OpenSSH Security Advisory (adv.option) + + + XF + openssh-access-control-bypass(7179) + + + BID + 3369 + + + OSVDB + 642 + + + MANDRAKE + MDKSA-2001:081 + + + CIAC + M-010 + + + IMMUNIX + IMNX-2001-70-034-01 + + + CONECTIVA + CLSA-2001:431 + + OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses. + + + + + + + + + cpe:/a:openbsd:openssh:2.9.9p2 + + CVE-2001-1382 + 2001-09-27T00:00:00.000-04:00 + 2008-09-05T16:26:24.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.openwall.com/Owl/CHANGES-stable.shtml + + + OSVDB + 5408 + + The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used. + + + + + + + + + cpe:/o:redhat:linux:7.1 + + CVE-2001-1383 + 2001-09-26T00:00:00.000-04:00 + 2008-09-10T15:10:24.820-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-setserial-initscript-symlink(7177) + + + REDHAT + RHSA-2001:110 + + + BID + 3367 + + initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.2.9 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.8 + cpe:/o:linux:linux_kernel:2.2.11 + cpe:/o:linux:linux_kernel:2.2.7 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.2.6 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.2.2 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.4 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.2.5 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.1 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.7 + + CVE-2001-1384 + 2001-10-18T00:00:00.000-04:00 + 2008-09-10T15:10:24.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ENGARDE + ESA-20011019-02 + + + XF + linux-ptrace-race-condition(7311) + + + REDHAT + RHSA-2001:130 + + + REDHAT + RHSA-2001:129 + + + SUSE + SuSE-SA:2001:036 + + + MANDRAKE + MDKSA-2001:082 + + + MANDRAKE + MDKSA-2001:079 + + + HP + HPSBTL0112-003 + + + IMMUNIX + IMNX-2001-70-035-01 + + + CALDERA + CSSA-2001-036.0 + + + BID + 3447 + + + BUGTRAQ + 20011019 TSLSA-2001-0028 + + + BUGTRAQ + 20011018 Flaws in recent Linux kernels + + ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + + CVE-2001-1385 + 2001-01-12T00:00:00.000-05:00 + 2008-09-10T15:10:24.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2000:136 + + + XF + php-view-source-code(5939) + + + BID + 2205 + + + MANDRAKE + MDKSA-2001:013 + + + DEBIAN + DSA-020 + + + BUGTRAQ + 20010112 PHP Security Advisory - Apache Module bugs + + + CONECTIVA + CLA-2001:373 + + The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts. + + + + + + + + + + + + + + + + + + + + + cpe:/a:texas_imperial_software:wftpd:3.0_0r4 + cpe:/a:texas_imperial_software:wftpd:3.0_0r5 + cpe:/a:texas_imperial_software:wftpd:2.41_rc14::pro + cpe:/a:texas_imperial_software:wftpd:3.0_0r3 + cpe:/a:texas_imperial_software:wftpd:2.40 + cpe:/a:texas_imperial_software:wftpd:3.0 + cpe:/a:texas_imperial_software:wftpd:2.41_rc14 + cpe:/a:texas_imperial_software:wftpd:3.0::pro + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc11 + cpe:/a:texas_imperial_software:wftpd:2.4.1 + cpe:/a:texas_imperial_software:wftpd:2.4.1_rc12 + cpe:/a:texas_imperial_software:wftpd:3.0_0r5::pro + cpe:/a:texas_imperial_software:wftpd:3.0_0r4::pro + + CVE-2001-1386 + 2001-07-01T00:00:00.000-04:00 + 2008-09-10T15:10:25.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2957 + + + XF + ftp-lnk-directory-traversal(6760) + + + BUGTRAQ + 20010701 WFTPD v3.00 R5 Directory Traversal + + WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension. + + + + + + + + + + + + + cpe:/a:netfilter_core_team:iptables:1.1.2 + cpe:/a:netfilter_core_team:iptables:1.2.1a + cpe:/a:netfilter_core_team:iptables:1.2.2 + cpe:/a:netfilter_core_team:iptables:1.2.3 + cpe:/a:netfilter_core_team:iptables:1.2 + + CVE-2001-1387 + 2001-11-05T00:00:00.000-05:00 + 2008-09-05T16:26:25.420-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:144 + + + CONFIRM + http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=50500 + + iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak. + + + + + + + + + + + + + cpe:/a:netfilter_core_team:iptables:1.1.2 + cpe:/a:netfilter_core_team:iptables:1.2.1a + cpe:/a:netfilter_core_team:iptables:1.2.2 + cpe:/a:netfilter_core_team:iptables:1.2.3 + cpe:/a:netfilter_core_team:iptables:1.2 + + CVE-2001-1388 + 2001-11-05T00:00:00.000-05:00 + 2008-09-05T16:26:25.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:144 + + + CONFIRM + http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=53325 + + iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:xinetd:xinetd:2.1.8.9_pre13 + cpe:/a:xinetd:xinetd:2.1.8.9_pre14 + cpe:/a:xinetd:xinetd:2.1.8.9_pre15 + cpe:/a:xinetd:xinetd:2.1.8.9_pre2 + cpe:/a:xinetd:xinetd:2.1.8.9_pre3 + cpe:/a:xinetd:xinetd:2.1.8.8_pre3 + cpe:/a:xinetd:xinetd:2.3.0 + cpe:/a:xinetd:xinetd:2.1.8.9_pre5 + cpe:/a:xinetd:xinetd:2.1.8.9_pre1 + cpe:/a:xinetd:xinetd:2.1.8.9_pre12 + cpe:/a:xinetd:xinetd:2.1.8.9_pre7 + cpe:/a:xinetd:xinetd:2.1.8.9_pre11 + cpe:/a:xinetd:xinetd:2.1.8.9_pre8 + cpe:/a:xinetd:xinetd:2.1.8.9_pre10 + cpe:/a:xinetd:xinetd:2.1.8.9_pre9 + cpe:/a:xinetd:xinetd:2.1.8.8 + + CVE-2001-1389 + 2001-08-29T00:00:00.000-04:00 + 2008-09-10T15:10:25.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:109 + + + MANDRAKE + MDKSA-2001:076 + + + IMMUNIX + IMNX-2001-70-033-01 + + + BID + 3257 + + + BUGTRAQ + 20010830 xinetd 2.3.0 audit status + + Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1390 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:25.920-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + SUSE + SuSE-SA:2001:18 + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + CALDERA + CSSA-2001-012.0 + + + IMMUNIX + IMNX-2001-70-010-01 + + Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1391 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.077-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-cpia-memory-overwrite(11162) + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + + IMMUNIX + IMNX-2001-70-010-01 + + Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1392 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.217-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1393 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.437-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang). + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1394 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.577-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1395 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.733-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1396 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:26.873-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1397 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:27.013-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1398 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:27.170-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1399 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:27.310-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86." + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1400 + 2001-04-17T00:00:00.000-04:00 + 2008-09-05T16:26:27.467-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:047 + + + CONFIRM + http://www.linux.org.uk/VERSION/relnotes.2219.html + + + BUGTRAQ + 20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels + + + BUGTRAQ + 20010405 Trustix Security Advisory #2001-0003 - kernel + + + IMMUNIX + IMNX-2001-70-010-01 + + + SUSE + SuSE-SA:2001:018 + + + CONECTIVA + CLA-2001:394 + + + MANDRAKE + MDKSA-2001:037 + + + DEBIAN + DSA-047 + + + CALDERA + CSSA-2001-012.0 + + Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock). + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1401 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:27.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=82781 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=70189 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39533 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39531 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39527 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39526 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39524 + + Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1402 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:27.763-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=95235 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=87701 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=39536 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=38859 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=38855 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=38854 + + Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1403 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:27.920-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=15980 + + Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1404 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:28.077-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=74032 + + Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1405 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:28.247-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=54556 + + Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1406 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:28.390-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=66235 + + + XF + bugzilla-processbug-old-restrictions(10478) + + process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.6 + cpe:/a:mozilla:bugzilla:2.8 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.4 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2001-1407 + 2001-09-10T00:00:00.000-04:00 + 2008-09-05T16:26:28.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2001:107 + + + BUGTRAQ + 20010829 Security Advisory for Bugzilla v2.13 and older + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=96085 + + + XF + bugzilla-duplicate-view-restricted(10479) + + Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug. + + + + + + + + + + cpe:/a:cobalt:webmail:2.0.1 + cpe:/a:cobalt:qube:3.0 + + CVE-2001-1408 + 2001-07-05T00:00:00.000-04:00 + 2008-09-05T16:26:28.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cobalt-qube-directory-traversal(6805) + + + BUGTRAQ + 20010818 Cobalt update for my Webmail issue. + + + BUGTRAQ + 20010705 Cobalt Cube Webmail directory traversal + + Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter. + + + + + + + + + cpe:/a:xfree86_project:xfree86_x_server:4.1.0.2 + + CVE-2001-1409 + 2003-07-24T00:00:00.000-04:00 + 2010-05-25T00:10:35.063-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:067 + + + CONFIRM + http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au + + + SUNALERT + 1017429 + + + SUNALERT + 228529 + + dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2001-1410 + 2003-08-18T00:00:00.000-04:00 + 2008-09-05T16:26:29.013-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#490708 + + + XF + ie-javascript-spoof-dialog(7313) + + + MISC + http://www.systemintegra.com/ie-fullscreen/ + + + BID + 3469 + + + BUGTRAQ + 20011021 Javascript in IE may spoof the whole screen + + + MISC + http://www.guninski.com/popspoof.html + + + MISC + http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/ + + + BUGTRAQ + 20030715 Internet Explorer Full-Screen mode threats + + + BUGTRAQ + 20030713 IE chromeless window vulnerabilities + + Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering. + + + + + + + + + cpe:/o:apple:mac_os_x:10.4.9 + + CVE-2001-1411 + 2003-11-17T00:00:00.000-05:00 + 2008-09-05T16:26:29.170-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#147587 + + + XF + macos-gm4-utility-bo(10174) + + + BUGTRAQ + 20011020 gm4 format strings on OSX + + + CONFIRM + http://lists.apple.com/mhonarc/security-announce/msg00038.html + + Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs. + + + + + + + + + cpe:/o:apple:mac_os_x:10.4.9 + + CVE-2001-1412 + 2003-11-17T00:00:00.000-05:00 + 2008-09-10T15:10:28.227-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.securemac.com/macosxnidump.php + + + MISC + http://www.securiteam.com/securityreviews/5QP032A4UU.html + + + SECTRACK + 1001946 + + + BUGTRAQ + 20020915 nidump on OS X + + + CONFIRM + http://lists.apple.com/mhonarc/security-announce/msg00038.html + + + BUGTRAQ + 20010903 Re: Possible Issue with Netinfo and Mac OS X + + nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument. + + + + + + + + + cpe:/a:ncompress:ncompress:4.2.4 + + CVE-2001-1413 + 2004-12-23T00:00:00.000-05:00 + 2008-09-05T16:26:29.467-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#176363 + + + REDHAT + RHSA-2004:536 + + + GENTOO + GLSA-200410-08 + + + XF + ncompress-filename-bo(10619) + + + VULN-DEV + 20010621 New bugs, old bugs + + Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2001-1414 + 2001-10-09T00:00:00.000-04:00 + 2008-09-10T15:10:28.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + solaris-bsm-no-audit(11841) + + + SUNALERT + 40521 + + + BID + 7396 + + The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root. + + + + + + + + + + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:openbsd:openbsd:2.9 + + CVE-2001-1415 + 2001-11-13T00:00:00.000-05:00 + 2008-09-05T16:26:29.763-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#191675 + + + XF + bsd-virecover-delete-files(10149) + + + CONFIRM + ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/016_recover.patch + + vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes. + + + + + + + + + cpe:/a:aol:instant_messenger:4.4a + + CVE-2001-1416 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:29.920-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-56TPBQ + + + CERT-VN + VU#541384 + + + MISC + http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&DisplayTab=Article + + Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags. + + + + + + + + + cpe:/a:aol:instant_messenger:4.7 + + CVE-2001-1417 + 2001-10-06T00:00:00.000-04:00 + 2008-09-05T16:26:30.060-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-56TQEN + + + CERT-VN + VU#710347 + + + XF + aim-large-buddyicon-dos(7255) + + + BID + 3408 + + + BUGTRAQ + 20011230 Windows AIM Client Exploits + + + BUGTRAQ + 20011006 AIM Exploits + + AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data. + + + + + + + + + cpe:/a:aol:instant_messenger:4.7 + + CVE-2001-1418 + 2001-10-06T00:00:00.000-04:00 + 2008-09-05T16:26:30.200-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-569M8X + + + CERT-VN + VU#990451 + + + XF + aim-wav-file-dos(10686) + + + BUGTRAQ + 20011006 AIM Exploits + + AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file. + + + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.3 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:cerulean_studios:trillian:0.6351 + cpe:/a:aol:instant_messenger:4.2 + cpe:/a:aol:instant_messenger:4.1 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:4.7.2480 + cpe:/a:aol:instant_messenger:4.3.2229 + + CVE-2001-1419 + 2001-10-02T00:00:00.000-04:00 + 2008-09-05T16:26:30.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-56TPTN + + + CERT-VN + VU#507771 + + + XF + aim-html-comments-dos(7233) + + + BID + 3398 + + + BUGTRAQ + 20011230 Windows AIM Client Exploits + + + BUGTRAQ + 20011002 AIM 0day DoS + + AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments. + + + + + + + + + cpe:/a:aol:instant_messenger:4.7 + + CVE-2001-1420 + 2005-05-02T00:00:00.000-04:00 + 2008-09-05T16:26:30.513-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-569MEK + + + CERT-VN + VU#972499 + + + XF + aim-long-filename-dos(7254) + + + BID + 3407 + + + BUGTRAQ + 20011006 AIM Exploits + + AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow. + + + + + + + + + cpe:/a:aol:instant_messenger:4.7 + + CVE-2001-1421 + 2001-10-06T00:00:00.000-04:00 + 2008-09-05T16:26:30.670-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-569MD7 + + + CERT-VN + VU#530299 + + + XF + aim-multiple-fonts-dos(7757) + + + BID + 3756 + + + BUGTRAQ + 20011230 Windows AIM Client Exploits + + + BUGTRAQ + 20011006 AIM Exploits + + AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag. + + + + + + + + + cpe:/a:att:winvnc:3.3.3 + + CVE-2001-1422 + 2001-01-23T00:00:00.000-05:00 + 2008-09-05T16:26:30.810-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#303080 + + + XF + vnc-weak-authentication(5992) + + + MISC + http://www1.corest.com/common/showdoc.php?idxseccion=10&idx=117 + + + BID + 2275 + + WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users. + + + + + + + + + cpe:/a:advanced_poll:advanced_poll:1.6 + + CVE-2001-1423 + 2001-10-10T00:00:00.000-04:00 + 2008-09-05T16:26:30.967-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#140723 + + + XF + advancedpoll-php-admin-access(7861) + + + SECTRACK + 1002516 + + Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter. + + + + + + + + + + + + cpe:/h:alcatel:speed_touch_home:khdsaa.108 + cpe:/h:alcatel:speed_touch_home:khdsaa.133 + cpe:/h:alcatel:speed_touch_home:khdsaa.132 + cpe:/h:alcatel:speed_touch_home:khdsaa.134 + + CVE-2001-1424 + 2001-04-10T00:00:00.000-04:00 + 2008-09-05T16:26:31.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#212088 + + + CERT + CA-2001-08 + + + XF + alcatel-blank-password(6335) + + + BID + 2568 + + + BUGTRAQ + 20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems + + + MISC + http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html + + Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access. + + + + + + + + + + + + cpe:/h:alcatel:speed_touch_home:khdsaa.108 + cpe:/h:alcatel:speed_touch_home:khdsaa.133 + cpe:/h:alcatel:speed_touch_home:khdsaa.132 + cpe:/h:alcatel:speed_touch_home:khdsaa.134 + + CVE-2001-1425 + 2001-04-10T00:00:00.000-04:00 + 2008-09-05T16:26:31.263-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#243592 + + + CERT + CA-2001-08 + + + XF + alcatel-expert-account(6354) + + + BID + 2568 + + + BUGTRAQ + 20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems + + + MISC + http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html + + The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. + + + + + + + + + + + + cpe:/h:alcatel:speed_touch_home:khdsaa.108 + cpe:/h:alcatel:speed_touch_home:khdsaa.133 + cpe:/h:alcatel:speed_touch_home:khdsaa.132 + cpe:/h:alcatel:speed_touch_home:khdsaa.134 + + CVE-2001-1426 + 2001-04-10T00:00:00.000-04:00 + 2008-09-05T16:26:31.420-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#490344 + + + CERT + CA-2001-08 + + + BID + 2566 + + + XF + alcatel-tftp-lan-access(6336) + + + BUGTRAQ + 20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems + + Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations. + + + + + + + + + + + + + + + + + + + + cpe:/a:macromedia:coldfusion:3.0.1 + cpe:/a:macromedia:coldfusion:4.0 + cpe:/a:macromedia:coldfusion:4.5.1 + cpe:/a:macromedia:coldfusion:4.5.1:sp1 + cpe:/a:macromedia:coldfusion:4.5.1:sp2 + cpe:/a:macromedia:coldfusion:4.5 + cpe:/a:macromedia:coldfusion:3.1 + cpe:/a:macromedia:coldfusion:3.0 + cpe:/a:macromedia:coldfusion:4.0.1 + cpe:/a:macromedia:coldfusion:3.1.2 + cpe:/a:macromedia:coldfusion:3.1.1 + cpe:/a:macromedia:coldfusion:2.0 + + CVE-2001-1427 + 2001-07-11T00:00:00.000-04:00 + 2008-09-05T16:26:31.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#321475 + + + BID + 3023 + + + CONFIRM + http://www.macromedia.com/devnet/security/security_zone/mpsb01-07.html + + + XF + coldfusion-overwrite-template(6840) + + Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors. + + + + + + + + + cpe:/a:beck_ipc_gmbh:ipc_at_chip_embedded-webserver + + CVE-2001-1428 + 2001-05-24T00:00:00.000-04:00 + 2008-09-05T16:26:31.733-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#461219 + + + CERT-VN + VU#426459 + + + XF + ipcchip-telnet-default-password(6598) + + + XF + ipcchip-ftp-default-passwords(6597) + + + BID + 2770 + + + BID + 2769 + + + BUGTRAQ + 20010524 IPC@Chip Security + + The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access. + + + + + + + + + cpe:/a:midnight_commander:midnight_commander:4.5.1 + + CVE-2001-1429 + 2001-11-12T00:00:00.000-05:00 + 2008-09-05T16:26:31.890-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#203203 + + + XF + midnight-commander-mcedit-bo(10630) + + Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file. + + + + + + + + + cpe:/h:cayman:3220-h_dsl_router:1.0 + + CVE-2001-1430 + 2001-06-11T00:00:00.000-04:00 + 2008-09-05T16:26:32.030-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/JARL-4ZTKY9 + + + CERT-VN + VU#557136 + + + XF + cayman-dsl-insecure-permissions(6841) + + + BID + 3017 + + + BUGTRAQ + 20010711 cayman strikes again + + Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access. + + + + + + + + + + + + + + + + + + + + cpe:/a:checkpoint:vpn-1:4.1:sp4 + cpe:/h:nokia:firewall_appliance:ipso_3.41 + cpe:/a:checkpoint:vpn-1:4.1:sp3 + cpe:/a:checkpoint:firewall-1:4.1:sp4 + cpe:/a:checkpoint:firewall-1:4.1:sp3 + cpe:/a:checkpoint:firewall-1:4.1:sp5 + cpe:/h:nokia:firewall_appliance:ipso_3.4 + cpe:/h:nokia:firewall_appliance:ipso_3.3 + + CVE-2001-1431 + 2001-10-08T00:00:00.000-04:00 + 2008-09-05T16:26:32.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#258731 + + + XF + nokia-cp-packet-retransmission(8293) + + Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information. + + + + + + + + + + + + + + + cpe:/a:cherokee:cherokee_httpd:0.2 + cpe:/a:cherokee:cherokee_httpd:0.1 + cpe:/a:cherokee:cherokee_httpd:0.1.5 + cpe:/a:cherokee:cherokee_httpd:0.1.6 + cpe:/a:cherokee:cherokee_httpd:0.2.7 + cpe:/a:cherokee:cherokee_httpd:0.2.6 + cpe:/a:cherokee:cherokee_httpd:0.2.5 + + CVE-2001-1432 + 2001-12-29T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.8 + NETWORK + LOW + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#464827 + + + XF + cherokee-http-directory-traversal(7799) + + + BID + 3772 + + + VULNWATCH + 20011229 Remote Root Hole in Cherokee Webserver + + Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. + + + + + + + + + + + + + + cpe:/a:cherokee:cherokee_httpd:0.2 + cpe:/a:cherokee:cherokee_httpd:0.1 + cpe:/a:cherokee:cherokee_httpd:0.1.5 + cpe:/a:cherokee:cherokee_httpd:0.1.6 + cpe:/a:cherokee:cherokee_httpd:0.2.6 + cpe:/a:cherokee:cherokee_httpd:0.2.5 + + CVE-2001-1433 + 2001-12-29T00:00:00.000-05:00 + 2008-09-05T16:26:32.497-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#245795 + + + BID + 3771 + + + XF + cherokee-http-insecure-privileges(7797) + + + VULNWATCH + 20011229 Remote Root Hole in Cherokee Webserver + + Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.0%289%29s8 + cpe:/o:cisco:ios:12.0%2812%29s3 + cpe:/o:cisco:ios:12.0%285.3%29wc1 + cpe:/o:cisco:ios:12.1eo + cpe:/o:cisco:ios:12.0%287%29t + cpe:/o:cisco:ios:12.1ey + cpe:/o:cisco:ios:12.1ex + cpe:/o:cisco:ios:12.1ew + cpe:/o:cisco:ios:12.1ev + cpe:/o:cisco:ios:12.1eu + cpe:/o:cisco:ios:12.0%287.4%29s + cpe:/o:cisco:ios:12.0%287%29xe2 + cpe:/o:cisco:ios:12.0%285.2%29xu + cpe:/o:cisco:ios:12.0%284%29xm1 + cpe:/o:cisco:ios:12.0%282%29xe + cpe:/o:cisco:ios:12.0%282%29xd + cpe:/o:cisco:ios:12.0%281%29xb + cpe:/o:cisco:ios:12.0%282%29xg + cpe:/o:cisco:ios:12.0%282%29xf + cpe:/o:cisco:ios:12.0%2814%29w5%2820%29 + cpe:/o:cisco:ios:12.0%281%29xe + cpe:/o:cisco:ios:12.0%282%29xc + cpe:/o:cisco:ios:12.0%285.4%29wc1 + cpe:/o:cisco:ios:12.1%2820%29ew + cpe:/o:cisco:ios:12.0%286b%29 + cpe:/o:cisco:ios:12.0%288a%29 + cpe:/o:cisco:ios:12.1eb + cpe:/o:cisco:ios:12.1ea + cpe:/o:cisco:ios:12.1%2820%29ec + cpe:/o:cisco:ios:12.1ec + cpe:/o:cisco:ios:12.0%2817%29st5 + cpe:/o:cisco:ios:12.0%284%29xm + cpe:/o:cisco:ios:12.0%2813%29w5%2819c%29 + cpe:/o:cisco:ios:12.0%284%29xe + cpe:/o:cisco:ios:12.0%2811%29s6 + cpe:/o:cisco:ios:12.0%2817a%29 + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.0dc + cpe:/o:cisco:ios:12.0db + cpe:/o:cisco:ios:12.0da + cpe:/o:cisco:ios:12.0%2815a%29 + cpe:/o:cisco:ios:12.0%2817%29s4 + cpe:/o:cisco:ios:12.0%2817%29st1 + cpe:/o:cisco:ios:12.0%2816%29st1 + cpe:/o:cisco:ios:12.0%289%29 + cpe:/o:cisco:ios:12.0%287%29wx5%2815a%29 + cpe:/o:cisco:ios:12.1%2820%29e2 + cpe:/o:cisco:ios:12.1%2820%29e1 + cpe:/o:cisco:ios:12.0%2818%29s + cpe:/o:cisco:ios:12.0%2813%29s6 + cpe:/o:cisco:ios:12.0%2816.06%29s + cpe:/o:cisco:ios:12.0w5 + cpe:/o:cisco:ios:12.0%288.0.2%29s + cpe:/o:cisco:ios:12.1aa + cpe:/o:cisco:ios:12.1ay + cpe:/o:cisco:ios:12.0%287%29dc1 + cpe:/o:cisco:ios:12.1ax + cpe:/o:cisco:ios:12.0%2811%29st4 + cpe:/o:cisco:ios:12.0%2810%29w5 + cpe:/o:cisco:ios:12.0%289a%29 + cpe:/o:cisco:ios:12.0%287%29s1 + cpe:/o:cisco:ios:12.0%287a%29 + cpe:/o:cisco:ios:12.0%2816%29w5%2821%29 + cpe:/o:cisco:ios:12.0%2813a%29 + cpe:/o:cisco:ios:12.0sl + cpe:/o:cisco:ios:12.1%2820%29ea1 + cpe:/o:cisco:ios:12.0%281%29xa3 + cpe:/o:cisco:ios:12.0%288%29s1 + cpe:/o:cisco:ios:12.0sp + cpe:/o:cisco:ios:12.0%287%29t2 + cpe:/o:cisco:ios:12.0%2816a%29 + cpe:/o:cisco:ios:12.0%285%29wc2 + cpe:/o:cisco:ios:12.1db + cpe:/o:cisco:ios:12.1dc + cpe:/o:cisco:ios:12.0%285%29wc3 + cpe:/o:cisco:ios:12.0sc + cpe:/o:cisco:ios:12.1da + cpe:/o:cisco:ios:12.0%2816%29sc3 + cpe:/o:cisco:ios:12.1xm + cpe:/o:cisco:ios:12.1xl + cpe:/o:cisco:ios:12.0%2811a%29 + cpe:/o:cisco:ios:12.1xk + cpe:/o:cisco:ios:12.1xj + cpe:/o:cisco:ios:12.1xi + cpe:/o:cisco:ios:12.1xh + cpe:/o:cisco:ios:12.1xw + cpe:/o:cisco:ios:12.1xv + cpe:/o:cisco:ios:12.0%284%29xe1 + cpe:/o:cisco:ios:12.1xu + cpe:/o:cisco:ios:12.1xt + cpe:/o:cisco:ios:12.1xs + cpe:/o:cisco:ios:12.1%2820%29e + cpe:/o:cisco:ios:12.1xr + cpe:/o:cisco:ios:12.1xq + cpe:/o:cisco:ios:12.1xp + cpe:/o:cisco:ios:12.0%287%29xf1 + cpe:/o:cisco:ios:12.1xf + cpe:/o:cisco:ios:12.1xg + cpe:/o:cisco:ios:12.0%287%29sc + cpe:/o:cisco:ios:12.0st + cpe:/o:cisco:ios:12.1xd + cpe:/o:cisco:ios:12.1xe + cpe:/o:cisco:ios:12.1xb + cpe:/o:cisco:ios:12.1xc + cpe:/o:cisco:ios:12.0sx + cpe:/o:cisco:ios:12.1xa + cpe:/o:cisco:ios:12.1yd + cpe:/o:cisco:ios:12.1yc + cpe:/o:cisco:ios:12.1yb + cpe:/o:cisco:ios:12.0%2810%29w5%2818f%29 + cpe:/o:cisco:ios:12.1yh + cpe:/o:cisco:ios:12.1yf + cpe:/o:cisco:ios:12.1ye + cpe:/o:cisco:ios:12.1xz + cpe:/o:cisco:ios:12.1xy + cpe:/o:cisco:ios:12.1xx + cpe:/o:cisco:ios:12.0%285%29t + cpe:/o:cisco:ios:12.1yi + cpe:/o:cisco:ios:12.1yj + cpe:/o:cisco:ios:12.0%281%29 + cpe:/o:cisco:ios:12.1%2820%29ec1 + cpe:/o:cisco:ios:12.1%2820%29ew1 + cpe:/o:cisco:ios:12.0%285%29wc2b + cpe:/o:cisco:ios:12.0%2810%29w5%2818g%29 + cpe:/o:cisco:ios:12.0%281%29w + cpe:/o:cisco:ios:12.0%2814%29s7 + cpe:/o:cisco:ios:12.0%282%29 + cpe:/o:cisco:ios:12.0%283%29t2 + cpe:/o:cisco:ios:12.0%289%29s + cpe:/o:cisco:ios:12.0%288.3%29sc + cpe:/o:cisco:ios:12.0%287%29xk3 + cpe:/o:cisco:ios:12.0wc + cpe:/o:cisco:ios:12.0%2812a%29 + cpe:/o:cisco:ios:12.0%2814%29st + cpe:/o:cisco:ios:12.0%283%29 + cpe:/o:cisco:ios:12.0%2816%29s8 + cpe:/o:cisco:ios:12.0%2810a%29 + cpe:/o:cisco:ios:12.0%2815%29s3 + cpe:/o:cisco:ios:12.0%2815%29s6 + cpe:/o:cisco:ios:12.0wt + cpe:/o:cisco:ios:12.0wx + cpe:/o:cisco:ios:12.0%282b%29 + cpe:/o:cisco:ios:12.0xb + cpe:/o:cisco:ios:12.0xa + cpe:/o:cisco:ios:12.0%287%29db2 + cpe:/o:cisco:ios:12.0xd + cpe:/o:cisco:ios:12.0xc + cpe:/o:cisco:ios:12.0xf + cpe:/o:cisco:ios:12.0xe + cpe:/o:cisco:ios:12.0xh + cpe:/o:cisco:ios:12.0xg + cpe:/o:cisco:ios:12.0xi + cpe:/o:cisco:ios:12.0xj + cpe:/o:cisco:ios:12.0%2817%29sl2 + cpe:/o:cisco:ios:12.0xk + cpe:/o:cisco:ios:12.0xl + cpe:/o:cisco:ios:12.0xm + cpe:/o:cisco:ios:12.0xn + cpe:/o:cisco:ios:12.0xp + cpe:/o:cisco:ios:12.0%2817%29 + cpe:/o:cisco:ios:12.0xq + cpe:/o:cisco:ios:12.0xr + cpe:/o:cisco:ios:12.0xs + cpe:/o:cisco:ios:12.0xu + cpe:/o:cisco:ios:12.0%2817%29sl6 + cpe:/o:cisco:ios:12.0%285%29wx + cpe:/o:cisco:ios:12.0%287%29xk + cpe:/o:cisco:ios:12.0%287%29xf + cpe:/o:cisco:ios:12.0%284%29t + cpe:/o:cisco:ios:12.0%287%29xe + cpe:/o:cisco:ios:12.0%284%29s + cpe:/o:cisco:ios:12.0%285.1%29xp + cpe:/o:cisco:ios:12.0%285%29wc3b + cpe:/o:cisco:ios:12.0%287%29xv + cpe:/o:cisco:ios:12.0%285%29wc + cpe:/o:cisco:ios:12.0%2818%29s5 + cpe:/o:cisco:ios:12.0%283d%29 + cpe:/o:cisco:ios:12.0%2810%29s7 + cpe:/o:cisco:ios:12.0%2818%29w5%2822b%29 + cpe:/o:cisco:ios:12.0%285%29xk2 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.0%2814a%29 + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.0%2813%29wt6%281%29 + cpe:/o:cisco:ios:12.0%2817%29s + cpe:/o:cisco:ios:12.0%2818b%29 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.0%285%29xs + cpe:/o:cisco:ios:12.0%285%29t1 + cpe:/o:cisco:ios:12.0%285%29xu + cpe:/o:cisco:ios:12.0%2818%29st1 + cpe:/o:cisco:ios:12.0%285%29xk + cpe:/o:cisco:ios:12.0%285%29xn + cpe:/o:cisco:ios:12.0%285%29xn1 + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.0%2814%29st3 + cpe:/o:cisco:ios:12.0%285%29yb4 + cpe:/o:cisco:ios:12.0%285%29xe + cpe:/o:cisco:ios:12.0%288%29 + cpe:/o:cisco:ios:12.1m + + CVE-2001-1434 + 2001-02-28T00:00:00.000-05:00 + 2008-09-05T16:26:32.670-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#848944 + + + XF + cisco-ios-snmp-server-community(6178) + + + CISCO + 20010228 Cisco IOS Software Multiple SNMP Community String Vulnerabilities + + Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created. + + + + + + + + + cpe:/o:compaq:tru64:5.1 + + CVE-2001-1435 + 2001-02-23T00:00:00.000-05:00 + 2011-03-07T21:07:20.563-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#880624 + + + XF + tru64-inetd-dos(6157) + + + COMPAQ + SSRT0708U + + inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services. + + + + + + + + + cpe:/h:dallas_semiconductor:ibutton:ds1991 + + CVE-2001-1436 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:33.420-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#178560 + + + XF + ibutton-ds1991-dictionary(10625) + + + ATSTAKE + A011801-1 + + Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password. + + + + + + + + + cpe:/a:easyscripts:easynews:1.5 + + CVE-2001-1437 + 2001-12-01T00:00:00.000-05:00 + 2008-09-05T16:26:33.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#597795 + + + XF + easynews-php-reveal-path(7660) + + + BID + 3649 + + + BUGTRAQ + 20011201 easynews 1.5 let's remote users modify database + + easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out. + + + + + + + + + + + + + + + cpe:/h:handspring:visor:1.0 + cpe:/o:palm:palm_os + cpe:/h:handspring:visor:1.0.1 + + CVE-2001-1438 + 2001-10-22T00:00:00.000-04:00 + 2008-09-05T16:26:33.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#222739 + + + XF + handspring-visor-sms-dos(10637) + + + VULN-DEV + 20011022 PalmOS crashes receiving SMS images using Handspring VisorPhone + + Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image. + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-1439 + 2001-02-16T00:00:00.000-05:00 + 2008-09-05T16:26:33.873-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#268848 + + + XF + hp-text-editor-bo(6111) + + + HP + HPSBUX0011-132 + + + AUSCERT + ESB-2001.066 + + Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit. + + + + + + + + + cpe:/o:ibm:aix:5.1l + + CVE-2001-1440 + 2001-12-21T00:00:00.000-05:00 + 2008-09-05T16:26:34.030-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#249491 + + + XF + aix-login-unauth-access(8269) + + + BID + 6839 + + + AIXAPAR + IY26302 + + + SECTRACK + 1003038 + + Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system. + + + + + + + + + cpe:/a:ibm:visualage_for_java:3.5::pro + + CVE-2001-1441 + 2001-07-02T00:00:00.000-04:00 + 2008-09-10T15:10:31.147-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#270083 + + + XF + java-servlet-crosssite-scripting(6793) + + + BUGTRAQ + 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message. + + + + + + + + + + + + + + cpe:/a:isc:inn:2.2.1 + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:2.2.2 + cpe:/a:isc:inn:2.2.3 + cpe:/a:isc:inn:2.0 + cpe:/a:isc:inn:2.1 + + CVE-2001-1442 + 2001-04-21T00:00:00.000-04:00 + 2008-09-05T16:26:34.310-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#943536 + + + BID + 2620 + + + BUGTRAQ + 20010418 Re: Innfeed Buffer Overflow + + + XF + innfeed-c-bo(6398) + + + SECTRACK + 1001353 + + + BUGTRAQ + 20010418 Innfeed Buffer Overflow + + Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument. + + + + + + + + + + cpe:/a:kth:kth_kerberos:5 + cpe:/a:kth:kth_kerberos:4 + + CVE-2001-1443 + 2001-08-27T00:00:00.000-04:00 + 2008-09-05T16:26:34.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#390280 + + + XF + kth-kerberos-unencrypted-connection(10640) + + + MISC + http://josefsson.org/ktelnet/kerberos-telnet.html + + KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack. + + + + + + + + + + cpe:/a:kth:kth_kerberos:5 + cpe:/a:kth:kth_kerberos:4 + + CVE-2001-1444 + 2001-08-27T00:00:00.000-04:00 + 2008-09-05T16:26:34.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#774587 + + + XF + kth-kerberos-unencrypted-connection(10640) + + + MISC + http://josefsson.org/ktelnet/kerberos-telnet.html + + The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack. + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino_mail_server:5.0.1 + cpe:/a:lotus:domino_mail_server:5.0.0 + cpe:/a:lotus:domino_mail_server:5.0.3 + cpe:/a:lotus:domino_mail_server:5.0.2 + cpe:/a:lotus:domino_mail_server:5.0.4 + cpe:/a:lotus:domino_mail_server:5.0.5 + cpe:/a:lotus:domino_mail_server:5.0.6 + cpe:/a:lotus:domino_mail_server:5.0.7 + cpe:/a:lotus:domino_mail_server:5.0.2b + + CVE-2001-1445 + 2001-03-01T00:00:00.000-05:00 + 2008-09-05T16:26:34.763-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#176972 + + + CONFIRM + http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21085603 + + + XF + lotus-domino-smtp-mail-relay(6591) + + Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands. + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/o:apple:mac_os_x:10.0.2 + + CVE-2001-1446 + 2001-09-11T00:00:00.000-04:00 + 2008-09-10T15:10:31.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#177243 + + + XF + macos-apache-directory-disclosure(7103) + + + BUGTRAQ + 20010910 Re: More security problems in Apache on Mac OS X + + + BID + 3325 + + Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories. + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.1 + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/o:apple:mac_os_x:10.0.2 + + CVE-2001-1447 + 2001-10-17T00:00:00.000-04:00 + 2008-09-05T16:26:35.093-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#945747 + + + XF + macos-netinfo-root-privileges(7303) + + + BID + 3439 + + + CIAC + M-007 + + + BUGTRAQ + 20011017 Re: Mac OS X setuid root security hole + + + BUGTRAQ + 20011017 Mac OS X setuid root security hole + + NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges. + + + + + + + + + cpe:/a:magic:edeveloper:8.30.5::enterprise + + CVE-2001-1448 + 2001-12-17T00:00:00.000-05:00 + 2008-09-05T16:26:35.247-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#157795 + + + XF + magic-edeveloper-tmp-symlink(10616) + + + BUGTRAQ + 20011217 MAGIC Enterprise Multiple Vulnerabilities + + Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.6 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.4 + cpe:/o:mandrakesoft:mandrake_linux:7.3 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3 + cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2 + cpe:/o:mandrakesoft:mandrake_linux:8.0 + + CVE-2001-1449 + 2001-11-28T00:00:00.000-05:00 + 2008-09-10T15:10:31.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#913704 + + + XF + mandrake-apache-browse-directories(8029) + + + MANDRAKE + MDKSA-2001:077 + + The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2001-1450 + 2001-05-11T00:00:00.000-04:00 + 2008-09-05T16:26:35.560-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#199408 + + + XF + ie-ftp-url-dos(10117) + + + BUGTRAQ + 20010505 [bug]: Cause IE 5.X to crash + + Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./". + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2001-1451 + 2002-10-22T00:00:00.000-04:00 + 2008-09-10T15:10:32.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#887393 + + + BID + 6030 + + + XF + win2k-snmp-lanman-dos(10431) + + + MSKB + Q296815 + + Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + + CVE-2001-1452 + 2001-08-31T00:00:00.000-04:00 + 2008-09-05T16:26:35.903-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#109475 + + + XF + nt-ms-dns-cachepollution(3675) + + + BID + 6791 + + + MSKB + Q241352 + + By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses. + + + + + + + + + cpe:/a:mysql:mysql:3.23.32 + + CVE-2001-1453 + 2001-02-09T00:00:00.000-05:00 + 2008-09-05T16:26:36.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#123384 + + + XF + mysql-libmysqlclient-bo(6418) + + + BUGTRAQ + 20010209 Some more MySql security issues + + + CONFIRM + http://dev.mysql.com/doc/mysql/en/news-3-23-33.html + + Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter. + + + + + + + + + cpe:/a:mysql:mysql:3.23.32 + + CVE-2001-1454 + 2001-02-09T00:00:00.000-05:00 + 2008-09-05T16:26:36.247-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#367320 + + + XF + mysql-drop-database-bo(6419) + + + BUGTRAQ + 20010209 Some more MySql security issues + + + CONFIRM + http://dev.mysql.com/doc/mysql/en/news-3-23-33.html + + Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request. + + + + + + + + + + + + cpe:/a:netegrity:siteminder:4.5.1 + cpe:/a:netegrity:siteminder:4.0 + cpe:/a:netegrity:siteminder:3.6 + cpe:/a:netegrity:siteminder:4.5 + + CVE-2001-1455 + 2001-08-24T00:00:00.000-04:00 + 2008-09-05T16:26:36.387-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#837419 + + + XF + siteminder-unicode-bypass(10497) + + + BID + 6060 + + Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mcafee:webshield_smtp:4.1 + cpe:/o:sgi:irix:6.5 + cpe:/a:mcafee:webshield_smtp:4.0 + cpe:/h:pgp:e-ppliance_300:1.5 + cpe:/h:network_associates:mcafee_e-ppliance:120_series + cpe:/a:network_associates:gauntlet_firewall:4.2 + cpe:/h:network_associates:mcafee_e-ppliance:100_series + cpe:/a:network_associates:gauntlet_firewall:unix_5.5 + cpe:/a:network_associates:gauntlet_firewall:unix_5.0 + cpe:/h:pgp:e-ppliance_300:1.0 + cpe:/h:pgp:e-ppliance_300:2.0 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/a:network_associates:gauntlet_firewall:unix_6.0 + cpe:/o:sgi:irix:6.2 + + CVE-2001-1456 + 2001-09-04T00:00:00.000-04:00 + 2008-09-10T15:10:32.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#206723 + + + CERT + CA-2001-25 + + + SGI + 20011104-01-I + + + XF + gauntlet-csmap-bo(7088) + + + BID + 3290 + + Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. + + + + + + + + + + cpe:/a:nobreak_technologies:crazywwwboard:2000lep5 + cpe:/a:nobreak_technologies:crazywwwboard:2000p4 + + CVE-2001-1457 + 2002-01-30T00:00:00.000-05:00 + 2008-09-05T16:26:36.780-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#229955 + + + XF + crazywwwboard-httpuseragent-bo(10110) + + + BUGTRAQ + 20010331 Remote buffer overflow in CrazyWWWBoard. + + Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable. + + + + + + + + + + + cpe:/a:novell:groupwise:6.0 + cpe:/a:novell:groupwise:5.5::enhancement_pack + cpe:/a:novell:groupwise:5.5 + + CVE-2001-1458 + 2001-10-15T00:00:00.000-04:00 + 2008-09-05T16:26:36.920-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#341539 + + + XF + novell-groupwise-directory-traversal(7287) + + + BID + 3436 + + + CONFIRM + http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html + + + MISC + http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/advisories_template.htm%3Findexid%3D12 + + + BUGTRAQ + 20011015 Novell Groupwise arbitrary file retrieval vulnerability + + Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character. + + + + + + + + + + + + + + + + cpe:/a:openbsd:openssh:2.5 + cpe:/a:openbsd:openssh:2.9 + cpe:/a:openbsd:openssh:2.5.2 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/a:openbsd:openssh:2.3 + cpe:/a:openbsd:openssh:2.5.1 + + CVE-2001-1459 + 2001-06-19T00:00:00.000-04:00 + 2011-03-07T21:07:22.657-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#797027 + + + XF + openssh-rsh-bypass-pam(6757) + + + BID + 2917 + + + BUGTRAQ + 20010619 pam session + + OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d. + + + + + + + + + + + cpe:/a:postnuke_software_foundation:postnuke:0.64 + cpe:/a:postnuke_software_foundation:postnuke:0.63 + cpe:/a:postnuke_software_foundation:postnuke:0.62 + + CVE-2001-1460 + 2001-10-13T00:00:00.000-04:00 + 2008-09-05T16:26:37.233-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#921547 + + + XF + postnuke-getusrinfo-bypass-authentication(7280) + + + BID + 3435 + + + BUGTRAQ + 20011012 Bug in PostNuke 0.62, 0.63 and 0.64 (and possibly PHPnuke) + + + BUGTRAQ + 20011013 Bug in PostNuke 0.62, 0.63 and 0.64 (and possibly PHPnuke) + + SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. + + + + + + + + + cpe:/h:rsa:securid:5.0 + + CVE-2001-1461 + 2001-10-22T00:00:00.000-04:00 + 2008-09-05T16:26:37.387-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#348040 + + + XF + securid-webid-unicode-traversal(7397) + + + BID + 3461 + + Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences. + + + + + + + + + cpe:/h:rsa:securid:5.0 + + CVE-2001-1462 + 2001-10-24T00:00:00.000-04:00 + 2008-09-05T16:26:37.530-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#609840 + + + XF + securid-webid-debug-mode(7399) + + + BID + 3462 + + WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information. + + + + + + + + + + cpe:/a:serv-u:serv-u:3.0.0.17 + cpe:/a:serv-u:serv-u:3.0.0.16 + + CVE-2001-1463 + 2001-11-19T00:00:00.000-05:00 + 2010-04-28T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#279763 + + + XF + servu-ftp-plaintext-password(7925) + + + SECTRACK + 1002882 + + The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords. + + + + + + + + + cpe:/a:businessobjects:crystal_reports + + CVE-2001-1464 + 2001-01-10T00:00:00.000-05:00 + 2008-09-05T16:26:37.827-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-06T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#403307 + + + XF + crystalreports-plaintext-auth-info(7928) + + Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords. + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter + + CVE-2001-1465 + 2002-02-26T00:00:00.000-05:00 + 2008-09-05T16:26:37.967-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#139315 + + + SECTRACK + 1001801 + + SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements. + + + + + + + + + cpe:/a:van_dyke_technologies:securecrt:3.4.1 + + CVE-2001-1466 + 2001-12-30T00:00:00.000-05:00 + 2008-09-05T16:26:38.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#216227 + + + XF + securecrt-ssh1-protocol-bo(10111) + + + VULN-DEV + 20011230 blackshell1: Multiple Prolems with Vandykes SecureCRT + + Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password. + + + + + + + + + cpe:/a:don_libes:expect:5.2.8 + + CVE-2001-1467 + 2001-04-11T00:00:00.000-04:00 + 2008-09-05T16:26:38.247-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#527736 + + + XF + mkpasswd-weak-passwords(6382) + + + BID + 2632 + + + SECTRACK + 1001303 + + + BUGTRAQ + 20010412 Re: flaw in RH ``mkpasswd'' command (importance of seeds & algorithms) + + + BUGTRAQ + 20010411 flaw in RH ``mkpasswd'' command + + mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:secure_reality:phpsecurepages:0.24_beta + cpe:/a:secure_reality:phpsecurepages:0.18_beta + cpe:/a:secure_reality:phpsecurepages:0.19_beta + cpe:/a:secure_reality:phpsecurepages:0.23_beta + cpe:/a:secure_reality:phpsecurepages:0.13_beta + cpe:/a:secure_reality:phpsecurepages:0.17_beta + cpe:/a:secure_reality:phpsecurepages:0.11_beta + cpe:/a:secure_reality:phpsecurepages:0.15_beta + cpe:/a:secure_reality:phpsecurepages:0.21_beta + cpe:/a:secure_reality:phpsecurepages:0.20_beta + cpe:/a:secure_reality:phpsecurepages:0.14_beta + cpe:/a:secure_reality:phpsecurepages:0.16_beta + cpe:/a:secure_reality:phpsecurepages:0.22_beta + cpe:/a:secure_reality:phpsecurepages:0.12_beta + + CVE-2001-1468 + 2001-02-07T00:00:00.000-05:00 + 2008-09-05T16:26:38.403-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#391347 + + + XF + phpsecurepages-checklogin-execute-code(6774) + + + BID + 2970 + + + SECTRACK + 1001408 + + PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1469 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:38.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#25309 + + + XF + ssh-rc4-modify-packets(6449) + + The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1470 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:38.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#315308 + + + XF + ssh-idea-modify-packets(6472) + + The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message. + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:1.2.0 + cpe:/a:phpbb_group:phpbb:1.2.1 + cpe:/a:phpbb_group:phpbb:1.0.0 + cpe:/a:phpbb_group:phpbb:1.4.0 + + CVE-2001-1471 + 2001-07-31T00:00:00.000-04:00 + 2008-09-10T15:10:34.913-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#920931 + + + BID + 3167 + + + XF + phpbb-admin-access(6944) + + + BUGTRAQ + 20010804 Re: phpBB 1.4.0 bug leads to easy admin privileges + + + BUGTRAQ + 20010810 Easily and Remotely Pipe a Covert Shell on phpBB version 1.4.0 and below + + prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement. + + + + + + + + + + cpe:/a:phpbb_group:phpbb:1.4.1 + cpe:/a:phpbb_group:phpbb:1.4.0 + + CVE-2001-1472 + 2001-08-03T00:00:00.000-04:00 + 2008-09-05T16:26:39.047-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#314347 + + + XF + phpbb-admin-access(6944) + + + BID + 3142 + + + BUGTRAQ + 20010803 phpBB 1.4.0 bug leads to easy admin privileges + + SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1473 + 2001-01-18T00:00:00.000-05:00 + 2009-03-06T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#684820 + + + XF + ssh-authentication-forwarding(6603) + + The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1474 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:39.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#786900 + + + XF + ssh-dns-authentication-bypass(6604) + + SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by poisoning the client's DNS cache. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1475 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:39.513-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#665372 + + + XF + ssh-rc4-replay-conversation(6490) + + SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated. + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.24 + + CVE-2001-1476 + 2001-01-18T00:00:00.000-05:00 + 2008-09-05T16:26:39.670-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#565052 + + + XF + ssh-rc4-replay-conversation(6490) + + SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not. + + + + + + + + + cpe:/a:bea:tuxedo:7.1 + + CVE-2001-1477 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:39.827-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-11T14:31:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + bea-tuxedo-remote-access(6326) + + + CONFIRM + http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA00-08.jsp + + The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain. + + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + cpe:/a:caldera:unixware:7.1.0 + + CVE-2001-1478 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:39.967-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-21T08:45:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3555 + + + CALDERA + CSSA-2001-SCO.34 + + + XF + unixware-openunix-xlock-bo(7573) + + Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code. + + + + + + + + + cpe:/a:sun:management%2bcenter:2.0 + + CVE-2001-1479 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.123-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-20T11:47:00.000-04:00 + + + + BID + 3763 + + + XF + sun-smcboot-tmp-symlink(7756) + + + MISC + http://www.securiteam.com/unixfocus/6K00S203FC.html + + smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sun:jre:1.2.2_003::linux_production + cpe:/a:sun:jre:1.2.2_007::solaris + cpe:/a:sun:jdk:1.2.2_07::windows + cpe:/a:sun:jre:1.2.2_007::windows + cpe:/a:sun:jdk:1.3.0_02::solaris + cpe:/a:sun:jre:1.2.2_07::solaris + cpe:/a:sun:jdk:1.3.0_02::windows + cpe:/a:apple:mac_os_runtime_for_java:2.2.4::java + cpe:/a:sun:jre:1.3.0:update2:solaris + cpe:/a:sun:jre:1.3.0:update2:linux + cpe:/a:sun:jre:1.2.2_006::linux + cpe:/a:sun:jre:1.3.0:update2:windows + cpe:/a:sun:jre:1.3.0:update1:linux + cpe:/a:sun:jre:1.2.2_007::linux + cpe:/a:sun:jdk:1.3.0_02::linux + cpe:/a:sun:sdk:1.3.0 + cpe:/a:sun:jre:1.3.0::linux + cpe:/a:sun:jdk:1.2.2_07::solaris + cpe:/a:sun:jre:1.2.2::linux_production + cpe:/a:sun:sdk:1.1.3 + cpe:/a:sun:jdk:1.2.2_07::linux + cpe:/a:sun:jre:1.2.2_004::linux + cpe:/a:sun:jdk:1.2.2_07a::solaris + cpe:/a:sun:jre:1.2.2_005::linux + + CVE-2001-1480 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.280-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T11:53:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + jre-system-clipboard-access(7333) + + + BID + 3441 + + + HP + HPSBUX0110-174 + + + BUGTRAQ + 20011017 Mac OS X v10.0.x J2SE v1.3 clipboard tapping vulnerability + + Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard. + + + + + + + + + + + cpe:/a:imatix:xitami:2.5_b4 + cpe:/a:imatix:xitami:2.5 + cpe:/a:imatix:xitami:2.4 + + CVE-2001-1481 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.467-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-24T07:45:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xitami-default-password-plaintext(7600) + + + BID + 3582 + + + MISC + http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html + + + BUGTRAQ + 20011126 Xitami Webserver stores admin password in clear text. + + Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges. + + + + + + + + + cpe:/a:phpbb_group:phpbb:1.4.2 + + CVE-2001-1482 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T12:33:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + phpbb-bbmemberlist-modify-sql(7253) + + + BID + 3411 + + SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable. + + + + + + + + + + cpe:/a:nrl:opie:2.4 + cpe:/a:nrl:opie:2.32 + + CVE-2001-1483 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.763-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-20T12:34:00.000-04:00 + + + + XF + opie-verify-accounts(7572) + + + BID + 3549 + + One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist. + + + + + + + + + + cpe:/h:alcatel:adsl_modem_1000 + cpe:/h:alcatel:speed_touch_adsl_modem:home + + CVE-2001-1484 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:40.920-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T12:37:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#211736 + + + CERT + CA-2001-08 + + + XF + alcatel-tftp-lan-access(6336) + + Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication. + + + + + + + + + cpe:/a:qualcomm:qpopper:4.0 + + CVE-2001-1487 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:41.060-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T12:39:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + qpopper-popauth-symlink(7707) + + popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option. + + + + + + + + + cpe:/a:open_projects_network:open_projects_network_ircd:u2.10.05.18 + + CVE-2001-1488 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:41.200-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-20T12:41:00.000-04:00 + + + + XF + irc-openprojects-dns-spoofing(7283) + + Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon. + + + + + + + + + cpe:/a:microsoft:ie:6:windows_server_2003_sp1 + + CVE-2001-1489 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:41.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-20T13:06:00.000-04:00 + + + + XF + win-browser-image-dos(7709) + + + BID + 3684 + + Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. + + + + + + + + + cpe:/a:mozilla:mozilla:0.9.6 + + CVE-2001-1490 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:41.497-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-20T13:44:00.000-04:00 + + + + XF + win-browser-image-dos(7709) + + + BID + 3684 + + Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:5.1.1::win32 + + CVE-2001-1491 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:41.637-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-20T13:48:00.000-04:00 + + + + XF + win-browser-image-dos(7709) + + + BID + 3684 + + Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. + + + CVE-2001-1492 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:36.447-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-1460. Reason: This candidate is a refinement duplicate of CVE-2001-1460. Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/a:andries_brouwer:util-linux:2.11m + + CVE-2001-1494 + 2001-12-31T00:00:00.000-05:00 + 2010-08-21T00:09:05.090-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-20T13:52:00.000-04:00 + + + + + XF + util-linux-script-hardlink(7718) + + + REDHAT + RHSA-2005:782 + + + BUGTRAQ + 20011212 Silly 'script' hardlink bug + + + BUGTRAQ + 20011213 Silly 'script' hardlink bug - fixed + + + BID + 16280 + + + MISC + http://support.avaya.com/elmodocs2/security/ASA-2006-014.htm + + + + + script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. + + + + + + + + + + cpe:/a:freshmeat:network_query_tool_phpnuke:1.0 + cpe:/a:freshmeat:network_query_tool:1.0 + + CVE-2001-1495 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:36.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-21T08:41:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + nqt-php-command-execution(7322) + + + BID + 3455 + + + BUGTRAQ + 20011022 [Advisory iSecureLabs] Network Query Tool remote command execution + + network_query.php in Network Query Tool 1.0 allows remote attackers execute arbitrary commands via shell metacharacters in the target parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:acme_labs:thttpd:2.11 + cpe:/a:acme_labs:thttpd:2.0.8 + cpe:/a:acme_labs:thttpd:2.0.7 + cpe:/a:acme_labs:thttpd:2.10 + cpe:/a:acme_labs:thttpd:2.0.9 + cpe:/a:acme_labs:thttpd:2.0 + cpe:/a:acme_labs:thttpd:2.20 + cpe:/a:acme_labs:thttpd:2.20b + cpe:/a:acme_labs:thttpd:2.18 + cpe:/a:acme_labs:thttpd:2.19 + cpe:/a:acme_labs:thttpd:2.16 + cpe:/a:acme_labs:thttpd:2.0.1 + cpe:/a:acme_labs:thttpd:2.17 + cpe:/a:acme_labs:thttpd:1.95 + cpe:/a:acme_labs:thttpd:2.0.2 + cpe:/a:acme_labs:thttpd:2.14 + cpe:/a:acme_labs:thttpd:2.0.3 + cpe:/a:acme_labs:thttpd:2.15 + cpe:/a:acme_labs:thttpd:2.0.4 + cpe:/a:acme_labs:thttpd:2.12 + cpe:/a:acme_labs:thttpd:2.0.5 + cpe:/a:acme_labs:thttpd:2.13 + cpe:/a:acme_labs:thttpd:2.0.6 + + CVE-2001-1496 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:42.170-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-21T08:55:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + thttpd-basic-authentication-bo(7595) + + + BID + 3562 + + + BUGTRAQ + 20011123 Re: Off-by-one vulnerability in thttpd!!! + + + BUGTRAQ + 20011120 Off-by-one vulnerability in thttpd!!! + + Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:4.1::windows_98 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:4.0::windows_nt + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:4.1::windows_95 + cpe:/a:microsoft:ie:4.0.1::windows_98 + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:4.0.1::windows_nt + cpe:/a:microsoft:ie:4.1::windows_nt_4.0 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:4.0.1:sp2 + + CVE-2001-1497 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:42.357-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-21T10:43:00.000-04:00 + + + + BID + 3563 + + + BUGTRAQ + 20011120 Re: MS IE Password inputs + + + BUGTRAQ + 20011121 MS IE Password inputs + + + XF + ie-password-character-information(7592) + + Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack. + + + + + + + + + cpe:/a:markus_kliegl:mod_bf:0.2 + + CVE-2001-1498 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:42.530-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-21T10:53:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + brainf*ck-modbf-bo(7730) + + + BID + 3713 + + + MISC + http://www.bugtraq.org/advisories/GOBBLES-15.txt + + Buffer overflow in mod_bf 0.2 allows local users execute arbitrary commands via a long script. + + + + + + + + + cpe:/a:checkpoint:vpn-1:4.1:sp4 + + CVE-2001-1499 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:42.687-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-21T11:12:00.000-04:00 + + + + XF + vpn1-securemote-brute-force(7343) + + + BID + 3470 + + + BUGTRAQ + 20011024 RE: Check Point VPN-1 SecuRemote Flaw + + + BUGTRAQ + 20011023 Check Point VPN-1 SecuRemote Flaw + + + OSVDB + 20210 + + Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:proftpd_project:proftpd:1.2.0_rc3 + cpe:/a:proftpd_project:proftpd:1.2_pre9 + cpe:/a:proftpd_project:proftpd:1.2 + cpe:/a:proftpd_project:proftpd:1.2.2 + cpe:/a:proftpd_project:proftpd:1.2.1 + cpe:/a:proftpd_project:proftpd:1.2_pre10 + cpe:/a:proftpd_project:proftpd:1.2_pre11 + cpe:/a:proftpd_project:proftpd:1.2_pre7 + cpe:/a:proftpd_project:proftpd:1.2_pre8 + cpe:/a:proftpd_project:proftpd:1.2_pre5 + cpe:/a:proftpd_project:proftpd:1.2_pre6 + cpe:/a:proftpd_project:proftpd:1.2.2_rc1 + cpe:/a:proftpd_project:proftpd:1.2_pre3 + cpe:/a:proftpd_project:proftpd:1.2.2_rc2 + cpe:/a:proftpd_project:proftpd:1.2_pre4 + cpe:/a:proftpd_project:proftpd:1.2_pre1 + cpe:/a:proftpd_project:proftpd:1.2_pre2 + + CVE-2001-1500 + 2001-12-31T00:00:00.000-05:00 + 2011-03-07T21:07:26.563-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-21T11:22:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3310 + + + XF + proftpd-unresolved-hostname(7126) + + + BUGTRAQ + 20010907 ProFTPd and reverse DNS + + + CONECTIVA + CLA-2002:450 + + + MANDRAKE + MDKSA-2002:005 + + ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged. + + + + + + + + + cpe:/a:proftpd_project:proftpd:1.2.1 + + CVE-2001-1501 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:51.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-21T15:01:00.000-04:00 + + + + CONECTIVA + CLA-2002:450 + + + MANDRAKE + MDKSA-2002:005 + + The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument. + + + + + + + + + cpe:/a:mountain_network_systems:webcart:8.4 + + CVE-2001-1502 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:43.153-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-23T13:18:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + webcart-cgi-command-execution(7315) + + + BID + 3453 + + + BUGTRAQ + 20011019 Webcart v.8.4 + + webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.8 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:sunos:5.7 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:sunos:5.5.1::x86 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:sunos:5.5.1 + cpe:/o:sun:sunos:5.5::x86 + cpe:/o:sun:sunos:5.8::x86 + cpe:/o:sun:sunos:5.7::x86 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:sunos:5.6::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:sunos:5.5 + cpe:/o:sun:sunos:5.6 + + CVE-2001-1503 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:43.293-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-21T15:28:00.000-04:00 + + + + XF + solaris-fingerd-list-accounts(7334) + + + BID + 3457 + + + SUNALERT + 27116 + + + VULNWATCH + 20011022 Solaris fingerd disclose complete user list + + The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host. + + + + + + + + + + cpe:/a:ibm:lotus_notes:4.6 + cpe:/a:ibm:lotus_notes:5.0 + + CVE-2001-1504 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:43.483-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-21T15:33:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + lotus-notes-execute-objects(7323) + + + BID + 3458 + + + BUGTRAQ + 20011023 Re: Security BugWare Advisory + + + BUGTRAQ + 20011022 Security BugWare Advisory + + Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message. + + + + + + + + + + cpe:/a:tinc:tinc:1.0pre4 + cpe:/a:tinc:tinc:1.0pre3 + + CVE-2001-1505 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:43.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-21T15:39:00.000-04:00 + + + + XF + vpn-replay-attack(7870) + + + BID + 3837 + + + BUGTRAQ + 20020109 Security flaws in tinc + + tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets. + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + + CVE-2001-1506 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:43.780-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-21T15:45:00.000-04:00 + + + + XF + hp-secure-unauth-privileges(7342) + + + BID + 3468 + + + HP + HPSBTL0110-001 + + Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files. + + + + + + + + + + cpe:/a:openbsd:openssh:3.0 + cpe:/a:openbsd:openssh:3.0p1 + + CVE-2001-1507 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:51.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-23T13:23:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.openbsd.org/errata30.html#sshd + + + XF + openssh-kerberos-elevate-privileges(7598) + + + BUGTRAQ + 20011119 OpenSSH 3.0.1 (fwd) + + + BID + 3560 + + OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged. + + + + + + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.3 + cpe:/o:sco:openserver:5.0.4 + cpe:/o:sco:openserver:5.0.1 + cpe:/o:sco:openserver:5.0.2 + cpe:/o:sco:openserver:5.0 + cpe:/o:sco:openserver:5.0.6a + + CVE-2001-1508 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:44.060-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-23T13:21:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 2597 + + + CALDERA + CSSA-2001-SCO.38 + + + XF + sco-openserver-lpstat-bo(6413) + + Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument. + + + + + + + + + cpe:/o:hp:hp-ux:11.20 + + CVE-2001-1509 + 2001-12-31T00:00:00.000-05:00 + 2009-03-04T00:10:51.717-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-23T13:25:00.000-04:00 + + + ALLOWS_USER_ACCESS + + + BID + 3452 + + + HP + HPSBUX0110-171 + + + XF + hpux-ia-geteuid-gain-privileges(7324) + + + + + geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges. + + + + + + + + + + + cpe:/a:macromedia:jrun:2.3.3 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1510 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:44.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T13:28:00.000-04:00 + + + + BID + 3592 + + + ALLAIRE + MPSB01-13 + + + XF + allaire-jrun-view-directory(7623) + + Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL. + + + + + + + + + + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1511 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:44.513-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T13:29:00.000-04:00 + + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22288&Method=Full + + + XF + allaire-jrun-view-jsp-source(7676) + + JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570". + + + + + + + + + cpe:/a:macromedia:jrun:3.1 + + CVE-2001-1512 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:52.413-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T13:36:00.000-04:00 + + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22287 + + + XF + allaire-jrun-webinf-metainf-jsp(7677) + + + BID + 3662 + + Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050. + + + + + + + + + + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1513 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:52.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-23T13:44:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full + + + XF + allaire-jrun-sessionid-duplicated(7680) + + + BID + 3600 + + Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx. + + + + + + + + + + cpe:/a:macromedia:coldfusion:5.0 + cpe:/a:macromedia:coldfusion:4.5 + + CVE-2001-1514 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:44.950-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-23T13:48:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263 + + ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account. + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2001-1515 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:52.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T13:53:00.000-04:00 + + + + SECTRACK + 1002626 + + + BID + 3479 + + Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. + + + + + + + + + + + + + + cpe:/a:hans_wolters:phpreview:0.9_final + cpe:/a:hans_wolters:phpreview:0.2.1 + cpe:/a:hans_wolters:phpreview:0.1 + cpe:/a:hans_wolters:phpreview:0.2 + cpe:/a:hans_wolters:phpreview:0.9_rc1 + cpe:/a:hans_wolters:phpreview:0.9_rc2 + + CVE-2001-1516 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:45.233-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T13:57:00.000-04:00 + + + + BID + 3380 + + + XF + phpreview-cross-site-scripting(7218) + + Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews. + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + + CVE-2001-1517 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:45.387-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T14:07:00.000-04:00 + + + + XF + win2k-runas-reveal-information(7531) + + + VULNWATCH + 20011112 RADIX1112200102 + + + BID + 3184 + + + BUGTRAQ + 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103 + + ** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information. + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + + CVE-2001-1518 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:45.543-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-23T14:24:00.000-04:00 + + + + BID + 3291 + + + XF + win2k-runas-dos(7533) + + + BUGTRAQ + 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103 + + RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability. + + + + + + + + + cpe:/o:microsoft:windows_2000 + + CVE-2001-1519 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:45.687-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T14:36:00.000-04:00 + + + + BID + 3185 + + + XF + win2k-runas-pipe-authentication(7532) + + + BUGTRAQ + 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103 + + + BUGTRAQ + 20011112 RADIX1112200101 + + ** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it. + + + + + + + + + + cpe:/h:intel:xircom_rex_6000:1 + cpe:/h:intel:xircom_rex_6000 + + CVE-2001-1520 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:45.840-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T14:53:00.000-04:00 + + + + BID + 3574 + + + XF + rex6000-pda-password-retrieval(7584) + + + BUGTRAQ + 20011123 Xircom REX6000 PDA Password Retrieval + + Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN. + + + + + + + + + + + cpe:/a:postnuke_software_foundation:postnuke:0.64 + cpe:/a:postnuke_software_foundation:postnuke:0.63 + cpe:/a:postnuke_software_foundation:postnuke:0.62 + + CVE-2001-1521 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:53.430-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:00:00.000-04:00 + + + + BID + 3609 + + + XF + phpnuke-postnuke-css(7654) + + + BUGTRAQ + 20011203 Phpnuke Cross site scripting vulnerability + + + BUGTRAQ + 20011215 PHPNuke holes + + Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:8.0_final + + CVE-2001-1522 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:46.137-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:03:00.000-04:00 + + + + VULN-DEV + 20011215 Serious bug in IMessenger ( php-nuke ) + + + VULN-DEV + 20011215 Security hole in IMessenger ( PHP-Nuke ) + + Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via a message. + + + + + + + + + cpe:/a:dmozgateway:dmozgateway + + CVE-2001-1523 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:46.277-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:25:00.000-04:00 + + + + VULN-DEV + 20011216 CSS in DMOZGateway ( php-nuke ) + + Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter. + + + + + + + + + + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.2 + cpe:/a:francisco_burzi:php-nuke:4.0 + cpe:/a:francisco_burzi:php-nuke:5.1 + cpe:/a:francisco_burzi:php-nuke:5.0 + cpe:/a:francisco_burzi:php-nuke:4.3 + cpe:/a:francisco_burzi:php-nuke:4.4 + cpe:/a:francisco_burzi:php-nuke:5.0.1 + cpe:/a:francisco_burzi:php-nuke:5.3.1 + cpe:/a:francisco_burzi:php-nuke:4.4.1a + cpe:/a:francisco_burzi:php-nuke:3.0 + cpe:/a:francisco_burzi:php-nuke:5.2a + + CVE-2001-1524 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:53.633-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:27:00.000-04:00 + + + + CONFIRM + http://prdownloads.sourceforge.net/phpnuke/PHP-Nuke-5.5.tar.gz + + + XF + phpnuke-postnuke-css(7654) + + + BID + 3609 + + Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php. + + + + + + + + + cpe:/a:easyscripts:easynews:1.5 + + CVE-2001-1525 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:46.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:27:00.000-04:00 + + + + BID + 3643 + + + XF + easynews-php-modify-data(7657) + + + BUGTRAQ + 20011201 easynews 1.5 let's remote users modify database + + Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter. + + + + + + + + + cpe:/a:easyscripts:easynews:1.5 + + CVE-2001-1526 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:46.777-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-23T15:28:00.000-04:00 + + + + XF + easynews-php-css(7658) + + + BUGTRAQ + 20011201 easynews 1.5 let's remote users modify database + + Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. + + + + + + + + + cpe:/a:easyscripts:easynews:1.5 + + CVE-2001-1527 + 2001-12-31T00:00:00.000-05:00 + 2009-04-03T00:11:16.610-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-23T15:30:00.000-04:00 + + + + XF + easynews-php-admin-passwd(7659) + + + BUGTRAQ + 20011201 easynews 1.5 let's remote users modify database + + easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access. + + + + + + + + + cpe:/a:amtote_international:homebet + + CVE-2001-1528 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.077-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-26T08:50:00.000-04:00 + + + + BID + 3371 + + + XF + homebet-brute-force-account(7185) + + + BUGTRAQ + 20010929 Vulnerability in Amtote International homebet self service wagering system. + + AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2001-1529 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.233-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T08:54:00.000-04:00 + + + ALLOWS_USER_ACCESS + + AIXAPAR + IY21609 + + Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779. + + + + + + + + + + cpe:/a:webmin:webmin:0.88 + cpe:/a:webmin:webmin:0.80 + + CVE-2001-1530 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.373-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T08:23:00.000-04:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.securiteam.com/unixfocus/6R00M0K2UC.html + + + VULNWATCH + 20011022 Webmin 0.88 temporary insecure file creation, root compromise + + run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands. + + + + + + + + + cpe:/a:apple:claris_emailer:2.0v2 + + CVE-2001-1531 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.513-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T15:55:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3454 + + + XF + claris-long-filename-bo(7314) + + + BUGTRAQ + 20011019 Claris Emailer buffer over flow vulnerabirity + + Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename. + + + + + + + + + cpe:/a:web_crossing:webx + + CVE-2001-1532 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.653-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-26T15:59:00.000-04:00 + + + + BUGTRAQ + 20011030 Web Forum Account Hijacking Vuln. + + + XF + webcrossing-webx-session-hijack(7458) + + WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions. + + + + + + + + + cpe:/a:microsoft:isa_server:2000 + + CVE-2001-1533 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.793-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-26T16:03:00.000-04:00 + + + + BID + 3501 + + + XF + isa-udp-flood-dos(7446) + + + BUGTRAQ + 20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability + + + BUGTRAQ + 20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability + + ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE. + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.12 + + CVE-2001-1534 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:47.937-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-26T16:18:00.000-04:00 + + + + BID + 3521 + + + XF + apache-modusertrack-predicticable-sessionid(7494) + + + BUGTRAQ + 20011113 Brute-Forcing Web Application Session IDs + + mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication. + + + + + + + + + cpe:/a:open_source_development_network:slashcode:2.0 + + CVE-2001-1535 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.090-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T16:26:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3519 + + + XF + slashcode-sessionid-brute-force(7493) + + + BUGTRAQ + 20011113 Brute-Forcing Web Application Session IDs + + Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack. + + + + + + + + + cpe:/a:autogalaxy:autogalaxy + + CVE-2001-1536 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-26T16:31:00.000-04:00 + + + + BID + 3587 + + + XF + audiogalaxy-plaintext-password(7621) + + + BUGTRAQ + 20011127 Audiogalaxy again + + Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack. + + + + + + + + + cpe:/a:twig:webmail:2.7.4 + + CVE-2001-1537 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-26T16:36:00.000-04:00 + + + + XF + twig-password-plaintext-cookie(7619) + + + BUGTRAQ + 20011128 TWIG default configurations may lead to insecure auth-cookie password storage + + + BID + 3591 + + The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges. + + + + + + + + + cpe:/h:speedxess:ha-120_dsl_router + + CVE-2001-1538 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T16:40:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20011203 SpeedXess HASE-120 router default password + + + BID + 3617 + + + XF + speedxess-hase-default-password(7655) + + SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain access. + + + + + + + + + cpe:/a:microsoft:ie:6.0.2900 + + CVE-2001-1539 + 2001-12-31T00:00:00.000-05:00 + 2010-01-08T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-27T08:31:00.000-04:00 + + + + + XF + ie-settimeout-dos(7661) + + + BUGTRAQ + 20011204 RE: Stack overflow in all Internet Explorer Versions!! + + + BUGTRAQ + 20011202 Stack overflow in all Internet Explorer Versions!! + + Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem. + + + + + + + + + + + cpe:/a:david_f._mischler:iproute:0.974 + cpe:/a:david_f._mischler:iproute:0.973 + cpe:/a:david_f._mischler:iproute:1.18 + + CVE-2001-1540 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.810-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-26T16:50:00.000-04:00 + + + + XF + iproute-fragmented-packet-dos(7664) + + + BUGTRAQ + 20011205 IPRoute Fragmentation Denial of Service Vulnerability + + IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header. + + + + + + + + + + + + + + cpe:/o:bsdi:bsd_os:4.2 + cpe:/o:bsdi:bsd_os:4.1 + cpe:/o:bsdi:bsd_os:4.0 + cpe:/o:bsdi:bsd_os:3.0 + cpe:/o:bsdi:bsd_os:3.1 + cpe:/o:bsdi:bsd_os:4.0.1 + + CVE-2001-1541 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:48.967-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-26T16:53:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3603 + + + BUGTRAQ + 20011129 UUCP + + + XF + bsd-uucp-bo(7633) + + Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitrary code via a long command line argument. + + + + + + + + + + cpe:/a:network_associates:webshield_smtp:4.5_mr1a + cpe:/a:network_associates:webshield_smtp:4.5 + + CVE-2001-1542 + 2001-12-31T00:00:00.000-05:00 + 2011-03-07T21:07:32.187-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T16:58:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3601 + + + XF + webshield-smtp-mime-attachments(7637) + + + BUGTRAQ + 20011130 Re: NAI Webshield SMTP for WinNT MIME header vuln that allows BadTrans to pass] + + NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments. + + + + + + + + + + + + + cpe:/h:axis:neteye_200%2b + cpe:/h:axis:2120_network_camera + cpe:/h:axis:2100_network_camera + cpe:/h:axis:neteye_200 + cpe:/h:axis:2110_network_camera + + CVE-2001-1543 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.263-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-26T17:01:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3640 + + + XF + axis-default-admin-passwd(7665) + + + BUGTRAQ + 20011206 Re: Axis Network Camera known default password vulnerability + + + BUGTRAQ + 20011205 Axis Network Camera known default password vulnerability + + Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera. + + + + + + + + + + + cpe:/a:macromedia:jrun:2.3.3 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1544 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-27T08:36:00.000-04:00 + + + + BID + 3666 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&Method=Full + + + XF + allaire-jrun-jws-directory-traversal(7678) + + Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request. + + + + + + + + + + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2001-1545 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.560-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-27T08:40:00.000-04:00 + + + + BID + 3665 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=Full + + + XF + allaire-jrun-jsessionid-appended(7679) + + Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing. + + + + + + + + + cpe:/a:mckesson:pathways_homecare:6.5 + + CVE-2001-1546 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.717-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T08:45:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3653 + + + XF + pathways-homecare-weak-encryption(7682) + + Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file. + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + + CVE-2001-1547 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T08:49:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + oe-blocked-attachment-forward(7670) + + Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code. + + + + + + + + + + + + + + + + cpe:/a:zonelabs:zonealarm:2.6 + cpe:/a:zonelabs:zonealarm:2.5 + cpe:/a:zonelabs:zonealarm:2.2 + cpe:/a:zonelabs:zonealarm:2.4::pro + cpe:/a:zonelabs:zonealarm:2.1 + cpe:/a:zonelabs:zonealarm:2.4 + cpe:/a:zonelabs:zonealarm:2.6::pro + cpe:/a:zonelabs:zonealarm:2.3 + + CVE-2001-1548 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:49.997-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-27T08:57:00.000-04:00 + + + + BID + 3647 + + + XF + zonealarm-tiny-bypass-filter(7671) + + + BUGTRAQ + 20011206 Re: Flawed outbound packet filtering in various personal firewalls + + + BUGTRAQ + 20011205 Flawed outbound packet filtering in various personal firewalls + + ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters. + + + + + + + + + + cpe:/a:tiny_software:tiny_personal_firewall:2.0 + cpe:/a:tiny_software:tiny_personal_firewall:1.0 + + CVE-2001-1549 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:50.153-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-27T09:01:00.000-04:00 + + + + BID + 3647 + + + XF + zonealarm-tiny-bypass-filter(7671) + + + BUGTRAQ + 20011205 Flawed outbound packet filtering in various personal firewalls + + Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters. + + + + + + + + + + + cpe:/a:centra:smart_connect:cen5.2-03 + cpe:/a:centra:asp + cpe:/a:centra:centraone:5.2 + + CVE-2001-1550 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:50.310-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-27T09:08:00.000-04:00 + + + + XF + centraone-log-file-info(7820) + + + NTBUGTRAQ + 20011226 Dangerous information in CentraOne log files - VENDOR RESPONSE + + + BID + 3704 + + + VULNWATCH + 20011217 Dangerous information in CentraOne Log files, possible user impersonation + + CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users. + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.19 + + CVE-2001-1551 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:50.450-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-27T09:14:00.000-04:00 + + + + BUGTRAQ + 20011022 Overriding qouta limits in Linux kernel + + Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs. + + + + + + + + + cpe:/o:microsoft:windows_me + + CVE-2001-1552 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:56.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:17:00.000-04:00 + + + + BID + 3442 + + + XF + winme-ssdp-dos(7318) + + + BUGTRAQ + 20011017 Ssdpsrv.exe in WindowsME + + ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. NOTE: multiple replies to the original post state that the problem could not be reproduced. + + + + + + + + + cpe:/a:university_of_california:seti_at_home:3.03 + + CVE-2001-1553 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:50.747-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:18:00.000-04:00 + + + ALLOWS_USER_ACCESS + + VULN-DEV + 20011202 Vulnerability in SETI@home + + Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiathome is not setuid, perhaps this issue should not be included in CVE. + + + + + + + + + cpe:/o:ibm:aix:430 + + CVE-2001-1554 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:50.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:21:00.000-04:00 + + + + AIXAPAR + IY25096 + + IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets. + + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-1555 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.027-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:26:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3522 + + + SUNALERT + 43929 + + + SECTRACK + 1004035 + + + SECTRACK + 1002732 + + pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY. + + + + + + + + + cpe:/a:apache:http_server + + CVE-2001-1556 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-27T09:32:00.000-04:00 + + + + XF + apache-hidden-http-request(7363) + + + CONFIRM + http://httpd.apache.org/docs/logs.html + + + BUGTRAQ + 20011024 Hidden requests to Apache + + The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep. + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:5.1 + + CVE-2001-1557 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.310-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:46:00.000-04:00 + + + ALLOWS_USER_ACCESS + + AIXAPAR + IY23674 + + + AIXAPAR + IY20486 + + Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges. + + + + + + + + + + + cpe:/a:snort:snort:1.8.0 + cpe:/a:snort:snort:1.8.2 + cpe:/a:snort:snort:1.8.1 + + CVE-2001-1558 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.450-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-27T09:52:00.000-04:00 + + + + MLIST + [Snort-announce] 20011129 Snort 1.8.3 Released + + Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash). + + + + + + + + + + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:openbsd:openbsd:2.9 + + CVE-2001-1559 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.607-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-29T17:47:00.000-04:00 + + + + XF + openbsd-retval-null-dos(7690) + + + MLIST + [OpenBSD] 20011202 Code that crashes kernel at will + proposed patch + + + BUGTRAQ + 20011202 OpenBSD local DoS + + The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2001-1560 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.747-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-29T18:42:00.000-04:00 + + + + BID + 3481 + + + XF + win-gid-dos(7409) + + + NTBUGTRAQ + 20011027 A GDI bug. + + Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by calling the ShowWindow function after receiving a WM_NCCREATE message. + + + + + + + + + + + + + + cpe:/a:john_bovey:xvt:2.1 + cpe:/o:debian:debian_linux:2.2 + + CVE-2001-1561 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:51.903-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-29T18:56:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2964 + + + DEBIAN + DSA-082 + + + BID + 2955 + + + XF + xvt-command-line-bo(6781) + + + BUGTRAQ + 20010702 Xvt 2.1 vulnerability + + Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments. + + + + + + + + + cpe:/o:bsd:nvi:1.79 + + CVE-2001-1562 + 2001-12-31T00:00:00.000-05:00 + 2011-03-07T21:07:33.847-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-29T19:11:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-085 + + + BID + 3456 + + + XF + nvi-format-string(7317) + + + SUSE + SuSE-SA:2001:040 + + Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename. + + + + + + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + cpe:/a:apache:tomcat:3.2.1 + + CVE-2001-1563 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:52.200-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-29T19:25:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBTL0112-004 + + + XF + tomcat-unspecified-unauthorized-access(42892) + + Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers. + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.01 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:hp-ux:11.04 + + CVE-2001-1564 + 2001-12-31T00:00:00.000-05:00 + 2009-03-04T00:10:56.907-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-30T14:39:00.000-04:00 + + + + + BID + 3416 + + + XF + hpux-setrlimit-dos(6810) + + + HP + HPSBUX0107-156 + + + + + setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropeed, which could allow local users to cause a denial of service by exhausting available disk space. + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.1 + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + + CVE-2001-1565 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:52.513-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-30T14:43:00.000-04:00 + + + + BID + 3753 + + + MLIST + [Macsec] 20011229 MacOSX ppp + + + XF + macos-ppp-auth-disclosure(7750) + + Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command. + + + + + + + + + + cpe:/a:vanessa:vanessa_logger:0.0.1 + cpe:/a:verge:perdition:0.1.8 + + CVE-2001-1566 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:52.670-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-30T14:46:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3740 + + + BUGTRAQ + 20011225 Remote Root Hole in FreeBSD Ports + + + VULNWATCH + 20011225 GOBBLES #17: perdition/vanessa_logger format string vuln + + Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function. + + + + + + + + + + + + + + + + + + + + cpe:/a:ibm:lotus_domino:5.0.1 + cpe:/a:ibm:lotus_domino:5.0.2 + cpe:/a:ibm:lotus_domino:5.0.6 + cpe:/a:ibm:lotus_domino:5.0.4::solaris + cpe:/a:ibm:lotus_domino:5.0.5 + cpe:/a:ibm:lotus_domino:5.0.3 + cpe:/a:ibm:lotus_domino_server:5.0.9a + cpe:/a:ibm:lotus_domino:5.0.7a + cpe:/a:ibm:lotus_domino:5.0.9 + cpe:/a:ibm:lotus_domino:5.0.7::solaris + cpe:/a:ibm:lotus_domino:5.0 + cpe:/a:ibm:lotus_domino:5.0.8 + + CVE-2001-1567 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:52.810-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-30T14:55:00.000-04:00 + + + + BID + 4022 + + + MISC + http://www.nextgenss.com/papers/hpldws.pdf + + + XF + lotus-domino-auth-bypass(8072) + + + BUGTRAQ + 20020204 Lotus Domino password bypass + + + BUGTRAQ + 20020204 Re: Lotus Domino password bypass + + + BUGTRAQ + 20020203 Lotus Domino password bypass + + Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino. + + + + + + + + + cpe:/a:cmg:wap_gateway + + CVE-2001-1568 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:52.980-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-30T14:59:00.000-04:00 + + + + XF + wap-gateway-ssl-certificates(6814) + + + BUGTRAQ + 20010709 Many WAP gateways do not properly check SSL certificates + + CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. + + + + + + + + + cpe:/a:cmg:openwave_wap_gateway + + CVE-2001-1569 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.123-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-30T19:51:00.000-04:00 + + + + BUGTRAQ + 20010709 Many WAP gateways do not properly check SSL certificates + + + XF + wap-gateway-ssl-certificates(6814) + + Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + + CVE-2001-1570 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.263-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-30T19:59:00.000-04:00 + + + + BID + 3717 + + + XF + winxp-fastswitch-account-lockout(7731) + + + BUGTRAQ + 20011220 Windows XP security concerns + + Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple times, which causes other accounts to be locked out. + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + + CVE-2001-1571 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-30T20:05:00.000-04:00 + + + + BID + 3720 + + + XF + winxp-remote-desktop-username(7732) + + + BUGTRAQ + 20011220 Windows XP security concerns + + The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing. + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + + CVE-2001-1572 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-30T20:19:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3418 + + + BUGTRAQ + 20011008 Bug in Linux 2.4 / iptables MAC match module + + + XF + linux-netfilter-bypass-filter(7267) + + The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.51::windows_nt + + CVE-2001-1573 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.730-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-30T20:24:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010628 [SNS Advisory No.34] TrendMicro InterScan VirusWall 3.51 smtpscan.dll Buffer Overflow + + Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.5.1 + + CVE-2001-1574 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:53.873-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-30T20:27:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20010628 [SNS Advisory No.35] TrendMicro InterScan VirusWall 3.51 HttpSaveC*P.dll Buffer Overflow + + Buffer overflow in (1) HttpSaveCVP.dll and (2) HttpSaveCSP.dll in Trend Micro InterScan VirusWall 3.5.1 allows remote attackers to execute arbitrary code. + + + + + + + + + + + cpe:/a:apple:personal_web_sharing:1.5.5 + cpe:/a:apple:personal_web_sharing:1.1 + cpe:/a:apple:personal_web_sharing:1.5 + + CVE-2001-1575 + 2001-12-31T00:00:00.000-05:00 + 2008-09-10T15:10:59.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-30T20:35:00.000-04:00 + + + + XF + macos-personal-web-sharing-dos(6759) + + + BID + 2945 + + + BUGTRAQ + 20010628 MacOS Personal Wed Sharing DoS + + Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attackers to cause a denial of service via a long password, possibly due to a buffer overflow. + + + + + + + + + cpe:/a:caldera:unixware:7 + + CVE-2001-1576 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.153-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-30T20:39:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CALDERA + CSSA-2001-SCO.3 + + Buffer overflow in cron in Caldera UnixWare 7 allows local users to execute arbitrary code via a command line argument. + + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + cpe:/a:caldera:unixware:7.1.0 + + CVE-2001-1577 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-10-03T08:56:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + cde-xterm-gain-privileges(7666) + + + BID + 3646 + + + XF + cde-xterm-gain-privileges(7666) + + + CALDERA + CSSA-2001-SCO.37 + + Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when the session is reused. + + + + + + + + + cpe:/o:sco:openserver:5.0.6 + + CVE-2001-1578 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.450-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-10-03T09:03:00.000-04:00 + + + + CALDERA + CSSA-2001-SCO.35 + + Unknown vulnerability in SCO OpenServer 5.0.6 and earlier allows local users to modify critical information such as certain CPU registers and segment descriptors. + + + + + + + + + + cpe:/o:sco:unixware:7 + cpe:/o:sco:open_unix:8.0.0 + + CVE-2001-1579 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-10-03T09:10:00.000-04:00 + + + + CALDERA + CSSA-2001-SCO.39 + + The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service. + + + + + + + + + + + + + + + + cpe:/a:nombas:scriptease_webserver:4.30b + cpe:/a:nombas:scriptease_webserver:4.30d + cpe:/o:novell:netware:5.1:sp2a + cpe:/o:novell:netware:5.1 + + CVE-2001-1580 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-10-03T09:15:00.000-04:00 + + + + BID + 3715 + + + XF + netware-webserver-directory-traversal(7726) + + + BUGTRAQ + 20011220 Re: IRM Security Advisory 002: Netware Web Server Source Disclosure + + + BUGTRAQ + 20011220 Re: IRM Security Advisory 002: Netware Web Server Source Disclosure + + + BUGTRAQ + 20011219 IRM Security Advisory 002: Netware Web Server Source Disclosure + + Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string. + + + + + + + + + cpe:/a:clearswift_limited:mailsweeper:4.2 + + CVE-2001-1581 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T16:26:54.903-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-05-31T14:09:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + mailsweeper-bypass-file-blocker(6801) + + + MISC + http://www.mimesweeper.com/support/technotes/notes/1102.asp + + The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filtering policies via a modified name in a Content-Type header. + + + + + + + + + + cpe:/o:sun:solaris:8.0:unkown:x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-1582 + 2001-12-31T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-10-02T11:17:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 2931 + + + MISC + http://www.securiteam.com/unixfocus/5IP0O2A4KS.html + + + BUGTRAQ + 20010626 Solaris 8 libsldap buffer overflow + + + BUGTRAQ + 20010706 Re: Solaris 8 libsldap exploit + + + BUGTRAQ + 20010705 Solaris 8 libsldap exploit + + Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.3 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.4 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:8.0:unkown:x86 + cpe:/o:sun:solaris:2.0 + cpe:/o:sun:solaris:2.1 + cpe:/o:sun:solaris:2.4::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.2 + cpe:/o:sun:solaris:2.5::x86 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2001-1583 + 2001-12-31T00:00:00.000-05:00 + 2010-06-24T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-10-02T12:19:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + solaris-lpd-sendmail-commands(7087) + + + BID + 3274 + + + OSVDB + 15131 + + + SF-INCIDENTS + 20010829 solaris lpd, KARMAPOLICE? + + + MISC + http://metasploit.com/projects/Framework/modules/exploits/solaris_lpd_exec.pm + + + BUGTRAQ + 20010831 Solaris LPD Exploit (fwd) + + lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220. + + + + + + + + + cpe:/a:michael_barretto:cardboard:2.4 + + CVE-2001-1584 + 2001-12-31T00:00:00.000-05:00 + 2010-06-24T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-10-10T10:46:00.000-04:00 + + + + + XF + cardboard-recipient-command-execution(7178) + + + BID + 3360 + + + MISC + http://www.securiteam.com/unixfocus/5MP0M2K5FC.html + + CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient field. + + + + + + + + + cpe:/a:openbsd:openssh:2.3.1 + + CVE-2001-1585 + 2001-12-31T00:00:00.000-05:00 + 2010-06-24T16:27:46.157-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-10-10T10:54:00.000-04:00 + + + + + CONFIRM + http://www.openbsd.org/advisories/ssh_bypass.txt + + + BID + 2356 + + + XF + openssh-bypass-authentication(6084) + + + BUGTRAQ + 20010208 Authentication By-Pass Vulnerability in OpenSSH-2.3.1 (devel snapshot) + + SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file. + + + + + + + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.0.8 + cpe:/a:analogx:simpleserver_www:1.01 + cpe:/a:analogx:simpleserver_www:1.13 + cpe:/a:analogx:simpleserver_www:1.03 + cpe:/a:analogx:simpleserver_www:1.05 + cpe:/a:analogx:simpleserver_www:1.04 + cpe:/a:analogx:simpleserver_www:1.06 + + CVE-2001-1586 + 2010-02-12T16:30:00.487-05:00 + 2010-04-28T00:10:42.267-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2010-02-15T10:38:00.000-05:00 + + + + + XF + simpleserverwww-cgibin-directory-traversal(56631) + + + BID + 3112 + + + MISC + http://www.securiteam.com/windowsntfocus/5TP0B1P4UK.html + + + CONFIRM + http://www.analogx.com/contents/download/network/sswww.htm + + + BUGTRAQ + 20010727 SimpleServer:WWW Command Execution Vulnerability Exploit Code Released + + Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664. + + + + + + + + + cpe:/o:novell:netware + + CVE-2001-1587 + 2010-04-05T11:30:00.547-04:00 + 2010-04-05T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2010-04-05T13:51:00.000-04:00 + + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command. + + + + + + + + + + + + + + cpe:/a:gnu:a2ps:4.13b + cpe:/a:gnu:a2ps:4.10.3 + cpe:/a:gnu:a2ps:4.10.4 + cpe:/a:gnu:a2ps:4.14 + cpe:/a:gnu:a2ps:4.13 + cpe:/a:gnu:a2ps:4.12 + + CVE-2001-1593 + 2014-04-05T17:55:06.097-04:00 + 2014-04-30T21:20:51.027-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2014-04-07T11:31:06.027-04:00 + + + + + CONFIRM + https://bugzilla.redhat.com/show_bug.cgi?id=1060630 + + + CONFIRM + https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385 + + + DEBIAN + DSA-2892 + + + MLIST + [oss-security] 20140205 Re: CVE request: a2ps insecure temporary file use + + + MLIST + [oss-security] 20140204 Re: CVE request: a2ps insecure temporary file use + + + MLIST + [oss-security] 20140205 Re: CVE request: a2ps insecure temporary file use + + + CONFIRM + http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch + + The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file. + + + + + + + + + + cpe:/a:mutt:mutt:1.3.25 + cpe:/a:mutt:mutt:1.2.5.1 + + CVE-2002-0001 + 2002-02-27T00:00:00.000-05:00 + 2008-09-05T16:26:55.670-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:003 + + + DEBIAN + DSA-096 + + + BUGTRAQ + 20020101 [Announce] SECURITY: mutt-1.2.5.1 and mutt-1.3.25 released. + + + BID + 3774 + + + SUSE + SuSE-SA:2002:001 + + + CONFIRM + http://www.mutt.org/announce/mutt-1.2.5.1-1.3.25.html + + + XF + mutt-address-handling-bo(7759) + + + HP + HPSBTL0201-011 + + + CONECTIVA + CLA-2002:449 + + + FREEBSD + FreeBSD-SA-02:04 + + + CALDERA + CSSA-2002-002.0 + + Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:engardelinux:secure_linux:1.0.1 + cpe:/o:redhat:linux:7.2 + cpe:/a:stunnel:stunnel:3.3 + cpe:/a:stunnel:stunnel:3.20 + cpe:/a:stunnel:stunnel:3.12 + cpe:/a:stunnel:stunnel:3.21 + cpe:/a:stunnel:stunnel:3.22 + cpe:/a:stunnel:stunnel:3.13 + cpe:/a:stunnel:stunnel:3.8 + cpe:/a:stunnel:stunnel:3.10 + cpe:/a:stunnel:stunnel:3.7 + cpe:/a:stunnel:stunnel:3.24 + cpe:/a:stunnel:stunnel:3.11 + cpe:/a:stunnel:stunnel:3.16 + cpe:/a:stunnel:stunnel:3.9 + cpe:/a:stunnel:stunnel:3.4a + cpe:/a:stunnel:stunnel:3.17 + cpe:/a:stunnel:stunnel:3.14 + cpe:/a:stunnel:stunnel:3.15 + cpe:/a:stunnel:stunnel:3.18 + cpe:/a:stunnel:stunnel:3.19 + cpe:/a:stunnel:stunnel:3.21a + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/a:stunnel:stunnel:3.21b + cpe:/a:stunnel:stunnel:3.21c + + CVE-2002-0002 + 2002-01-31T00:00:00.000-05:00 + 2011-03-07T21:07:36.313-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2002:002 + + + CONFIRM + http://stunnel.mirt.net/news.html + + + MISC + http://marc.theaimsgroup.com/?l=stunnel-users&m=100869449828705&w=2 + + + XF + stunnel-client-format-string(7741) + + + BID + 3748 + + + MANDRAKE + MDKSA-2002:004 + + + BUGTRAQ + 20020102 Stunnel: Format String Bug update + + + BUGTRAQ + 20011227 Stunnel: Format String Bug in versions <3.22 + + Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. + + + + + + + + + cpe:/a:gnu:groff:1.16 + + CVE-2002-0003 + 2002-02-27T00:00:00.000-05:00 + 2008-09-05T16:26:56.013-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:004 + + + XF + linux-groff-preprocessor-bo(7881) + + + BID + 3869 + + + MANDRAKE + MDKSA-2002:012 + + + HP + HPSBTL0201-014 + + Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::ia-32 + cpe:/o:suse:suse_linux:7.0::i386 + cpe:/o:suse:suse_linux:6.4::i386 + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:suse:suse_linux:7.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/o:suse:suse_linux:7.3::i386 + cpe:/o:suse:suse_linux:7.1:alpha + cpe:/o:freebsd:freebsd:4.3 + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:suse:suse_linux:7.0:alpha + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:slackware:slackware_linux:8.0 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:7.2::alpha + cpe:/o:slackware:slackware_linux:7.1 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:slackware:slackware_linux:7.0 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:suse:suse_linux:7.3::ppc + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/o:suse:suse_linux:7.0::ppc + cpe:/o:suse:suse_linux:6.4:alpha + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:suse:suse_linux:7.1::ppc + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:mandrakesoft:mandrake_linux:8.1::ia64 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:suse:suse_linux:7.1::x86 + cpe:/o:suse:suse_linux:7.0::sparc + cpe:/a:caldera:openlinux_server:3.1 + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:suse:suse_linux:7.1::sparc + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:suse:suse_linux:7.3::sparc + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2002-0004 + 2002-02-27T00:00:00.000-05:00 + 2008-09-10T15:11:01.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3886 + + + REDHAT + RHSA-2002:015 + + + DEBIAN + DSA-102 + + + BUGTRAQ + 20020117 '/usr/bin/at 31337 + vuln' problem + exploit + + + XF + linux-at-exetime-heap-corruption(7909) + + + SUSE + SuSE-SA:2002:003 + + + HP + HPSBTL0302-034 + + + HP + HPSBTL0201-021 + + + MANDRAKE + MDKSA-2002:007 + + Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.3 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.8.2616 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:4.7.2480 + cpe:/a:aol:instant_messenger:4.3.2229 + + CVE-2002-0005 + 2002-01-31T00:00:00.000-05:00 + 2008-09-05T16:26:56.420-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#907819 + + + XF + aim-game-overflow(7743) + + + BID + 3769 + + + BUGTRAQ + 20020102 AIM addendum + + + NTBUGTRAQ + 20020102 w00w00 on AOL Instant Messenger (serious vulnerability) + + + BUGTRAQ + 20020102 w00w00 on AOL Instant Messenger (serious vulnerability) + + + NTBUGTRAQ + 20020102 AIM addendum + + Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). + + + + + + + + + + cpe:/a:xchat:xchat:1.4.2 + cpe:/a:xchat:xchat:1.4.3 + + CVE-2002-0006 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:26:56.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-099 + + + BUGTRAQ + 20020109 xchat IRC session hijacking vulnerability (versions 1.4.1, 1.4.2) + + + XF + xchat-ctcp-ping-command(7856) + + + BID + 3830 + + + REDHAT + RHSA-2002:005 + + + HP + HPSBTL0201-016 + + + CONECTIVA + CLA-2002:453 + + XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the percascii variable is set. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + + CVE-2002-0007 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:02.697-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older + + + CONFIRM + http://www.bugzilla.org/security2_14_1.html + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=54901 + + + XF + bugzilla-ldap-auth-bypass(7812) + + + BID + 3792 + + + REDHAT + RHSA-2002:001 + + CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + + CVE-2002-0008 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:02.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.bugzilla.org/security2_14_1.html + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=108516 + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=108385 + + + BUGTRAQ + 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older + + + BID + 3794 + + + BID + 3793 + + + XF + bugzilla-processbug-comment-spoofing(7805) + + + XF + bugzilla-postbug-report-spoofing(7804) + + + REDHAT + RHSA-2002:001 + + Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + + CVE-2002-0009 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:02.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older + + + CONFIRM + http://www.bugzilla.org/security2_14_1.html + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=102141 + + + BID + 3798 + + + XF + bugzilla-showbug-reveal-bugs(7802) + + + REDHAT + RHSA-2002:001 + + show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + + CVE-2002-0010 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:03.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older + + + CONFIRM + http://www.bugzilla.org/security2_14_1.html + + + MISC + http://www.bugzilla.org/bugzilla2.14to2.14.1.patch + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=109690 + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=109679 + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=108822 + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=108821 + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=108812 + + + BID + 3805 + + + BID + 3804 + + + BID + 3802 + + + BID + 3801 + + + XF + bugzilla-editusers-change-groupset(7814) + + + XF + bugzilla-buglist-sql-logic(7813) + + + XF + bugzilla-longlist-modify-sql(7811) + + + XF + bugzilla-userprefs-change-groupset(7809) + + + XF + bugzilla-buglist-modify-sql(7807) + + + REDHAT + RHSA-2002:001 + + + BUGTRAQ + 20020106 Inproper input validation in Bugzilla <=2.14 - exploit + + Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges. + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + + CVE-2002-0011 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:03.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older + + + CONFIRM + http://www.bugzilla.org/security2_14_1.html + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=98146 + + + BID + 3800 + + + XF + bugzilla-doeditvotes-login-information(7803) + + + REDHAT + RHSA-2002:001 + + Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login. + + + + + + + + + cpe:/a:snmp:snmp + + CVE-2002-0012 + 2002-02-13T00:00:00.000-05:00 + 2008-09-10T15:11:03.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + + + CERT-VN + VU#107186 + + + CERT + CA-2002-03 + + + BID + 5043 + + + HP + HPSBMP0206-015 + + + MS + MS02-006 + + + SGI + 20020201-01-A + + + REDHAT + RHSA-2001:163 + + + ISS + 20020212 PROTOS Remote SNMP Attack Tool + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html + + + + + + + + + + + Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available. + + + + + + + + + cpe:/a:snmp:snmp + + CVE-2002-0013 + 2002-02-13T00:00:00.000-05:00 + 2008-09-10T15:11:03.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + CERT-VN + VU#854306 + + + CERT + CA-2002-03 + + + MS + MS02-006 + + + SUNALERT + 57404 + + + SGI + 20020201-01-A + + + REDHAT + RHSA-2001:163 + + + ISS + 20020212 PROTOS Remote SNMP Attack Tool + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html + + + + + + + + Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available. + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.30 + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.20 + cpe:/a:university_of_washington:pine:4.33 + + CVE-2002-0014 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:11:03.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2002:009 + + + BUGTRAQ + 20020105 Pine 4.33 (at least) URL handler allows embedded commands. + + + HP + HPSBTL0201-015 + + + BID + 3815 + + + CONECTIVA + CLA-2002:460 + + URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0017 + 2002-04-03T00:00:00.000-05:00 + 2008-09-05T16:26:57.950-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SGI + 20020201-01-P + + + ISS + 20020403 Remote Buffer Overflow Vulnerability in IRIX SNMP Daemon + + + BID + 4421 + + + XF + irix-snmp-bo(7846) + + Buffer overflow in SNMP daemon (snmpd) on SGI IRIX 6.5 through 6.5.15m allows remote attackers to execute arbitrary code via an SNMP request. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt + + CVE-2002-0018 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:03.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MS + MS02-001 + + + XF + win-sid-gain-privileges(8023) + + + BID + 3997 + + + + + + + + In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/a:microsoft:interix:2.2 + + CVE-2002-0020 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:26:58.277-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4061 + + + MS + MS02-004 + + + XF + ms-telnet-option-bo(8094) + + + + + Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options. + + + + + + + + + cpe:/a:microsoft:office:v.x::mac + + CVE-2002-0021 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:03.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-002 + + + BID + 4045 + + + OSVDB + 2041 + + Network Product Identification (PID) Checker in Microsoft Office v. X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0022 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:26:58.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT + CA-2002-04 + + + MS + MS02-005 + + + XF + ie-html-directive-bo(8116) + + + BUGTRAQ + 20020213 dH & SECURITY.NNOV: buffer overflow in mshtml.dll + + + BID + 4080 + + + BUGTRAQ + 20020227 Details and exploitation of buffer overflow in mshtml.dll (and few sidenotes on Unicode overflows in general) + + + + + Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0023 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:26:58.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + + BID + 3767 + + + MS + MS02-005 + + + BUGTRAQ + 20020101 IE GetObject() problems + + + XF + ie-getobject-directory-traversal(7758) + + + OSVDB + 3030 + + + + + + + + + + + + + + Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0024 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:26:58.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4087 + + + MS + MS02-005 + + File Download box in Internet Explorer 5.01, 5.5 and 6.0 allows an attacker to use the Content-Disposition and Content-Type HTML header fields to modify how the name of the file is displayed, which could trick a user into believing that a file is safe to download. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0025 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:04.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-005 + + + XF + ie-application-invocation(8118) + + + BID + 4085 + + + BUGTRAQ + 20020212 [ GFISEC04102001 ] Internet Explorer and Access allow macros to be executed automatically + + Internet Explorer 5.01, 5.5 and 6.0 does not properly handle the Content-Type HTML header field, which allows remote attackers to modify which application is used to process a document. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0026 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:04.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + MS + MS02-005 + + + BID + 4082 + + + + + + + + + + + Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0027 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:26:59.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 3721 + + + MS + MS02-005 + + + BUGTRAQ + 20011219 Internet Explorer Document.Open() Without Close() Cookie Stealing, File Reading, Site Spoofing Bug + + + OSVDB + 3031 + + + + + Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874. + + + + + + + + + + + + + cpe:/a:mirabilis:icq:2001b_build3636 + cpe:/a:mirabilis:icq:2001b_build3638 + cpe:/a:mirabilis:icq:2000.0b_build3278 + cpe:/a:mirabilis:icq:2000.0a + cpe:/a:mirabilis:icq:2001a + + CVE-2002-0028 + 2002-02-27T00:00:00.000-05:00 + 2008-09-05T16:26:59.450-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#570167 + + + CERT + CA-2002-02 + + + BID + 3813 + + + VULN-DEV + 20020107 ICQ remote buffer overflow vulnerability + + + BUGTRAQ + 20020106 ICQ remote buffer overflow vulnerability + + + XF + aim-game-overflow(7743) + + Buffer overflow in ICQ before 2001B Beta v5.18 Build #3659 allows remote attackers to execute arbitrary code via a Voice Video & Games request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:astaro:security_linux:3.2.10 + cpe:/o:astaro:security_linux:3.2.11 + cpe:/a:isc:bind:4.9.9 + cpe:/a:isc:bind:4.9.4 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.2 + cpe:/o:astaro:security_linux:3.2.0 + cpe:/a:isc:bind:4.9.10 + cpe:/a:isc:bind:4.9.8 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + cpe:/o:astaro:security_linux:2.0.30 + cpe:/o:astaro:security_linux:2.0.25 + cpe:/o:astaro:security_linux:2.0.26 + cpe:/o:astaro:security_linux:2.0.27 + cpe:/o:astaro:security_linux:2.0.23 + cpe:/o:astaro:security_linux:2.0.24 + + CVE-2002-0029 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:11:05.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2002-31 + + + CERT-VN + VU#844360 + + + CONFIRM + http://www.isc.org/products/BIND/bind-security.html + + + BID + 6186 + + + XF + bind-dns-libresolv-bo(10624) + + + SGI + 20021201-01-P + + + NETBSD + NetBSD-SA2002-028 + + + APPLE + 2002-11-21 + + Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684. + + + + + + + + + + + + + + + + + + + + cpe:/a:adobe:acrobat_reader:4.0.5c + cpe:/a:adobe:acrobat_reader:4.0 + cpe:/a:adobe:acrobat:5.0.5 + cpe:/a:adobe:acrobat:4.0 + cpe:/a:adobe:acrobat_reader:5.0.5 + cpe:/a:adobe:acrobat_reader:4.0.5 + cpe:/a:adobe:acrobat:5.0 + cpe:/a:adobe:acrobat_reader:5.0 + cpe:/a:adobe:acrobat:4.0.5 + cpe:/a:adobe:acrobat:4.0.5c + cpe:/a:adobe:acrobat:4.0.5a + cpe:/a:adobe:acrobat_reader:4.0.5a + + CVE-2002-0030 + 2003-04-02T00:00:00.000-05:00 + 2008-09-10T15:11:05.507-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#549913 + + + CONFIRM + http://www.kb.cert.org/vuls/id/JSHA-5EZQGZ + + + FULLDISC + 20030324 Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged + + + VULNWATCH + 20030324 Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged + + The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-0031 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:26:59.967-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-16 + + + CERT-VN + VU#137115 + + + BID + 4837 + + + BUGTRAQ + 20020527 Yahoo Messenger - Multiple Vulnerabilities + + Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-0032 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:00.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#172315 + + + CERT + CA-2002-16 + + + BID + 4838 + + + BUGTRAQ + 20020527 Yahoo Messenger - Multiple Vulnerabilities + + + XF + yahoo-messenger-script-injection(9184) + + Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5.1::sparc + cpe:/o:sun:solaris:7.0::sparc + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.6::sparc + + CVE-2002-0033 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:00.247-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT + CA-2002-11 + + + CERT-VN + VU#635811 + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309 + + + BUGTRAQ + 20020505 [LSD] Solaris cachefsd remote buffer overflow vulnerability + + + BID + 4674 + + + XF + solaris-cachefsd-name-bo(8999) + + + + + + + + Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name. + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_2000:::professional + + CVE-2002-0034 + 2004-02-03T00:00:00.000-05:00 + 2008-09-10T15:11:06.663-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#361065 + + + MS + Q237399 + + The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected. + + + + + + + + + + + + cpe:/a:mit:kerberos:5-1.2.2 + cpe:/a:mit:kerberos:5-1.2.3 + cpe:/a:mit:kerberos:5-1.2.4 + cpe:/a:mit:kerberos:5-1.2.1 + + CVE-2002-0036 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:11:06.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#587579 + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt + + + XF + kerberos-kdc-neglength-bo(11190) + + + BID + 6713 + + + REDHAT + RHSA-2003:168 + + + REDHAT + RHSA-2003:052 + + + REDHAT + RHSA-2003:051 + + + OSVDB + 4896 + + + MANDRAKE + MDKSA-2003:043 + + + CONECTIVA + CLA-2003:639 + + Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value. + + + + + + + + + + + cpe:/a:ibm:lotus_domino_server:4.6 + cpe:/a:ibm:lotus_domino_server:4.5 + cpe:/a:ibm:lotus_domino_server:5 + + CVE-2002-0037 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:00.700-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#657899 + + + XF + lotus-domino-nsfdbreadobject(10095) + + + BUGTRAQ + 20010917 Re: Lotus Notes: File attachments may be extracted regardless of document security + + + BUGTRAQ + 20010917 Lotus Notes: File attachments may be extracted regardless of document security + + Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object. + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0038 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:07.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20020102-01-I + + + XF + irix-nsd-cache-dos(7907) + + + BID + 3882 + + + SGI + 20020102-03-P + + + SGI + 20020102-02-I + + Vulnerability in the cache-limiting function of the unified name service daemon (nsd) in IRIX 6.5.4 through 6.5.11 allows remote attackers to cause a denial of service by forcing the cache to fill the disk. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0039 + 2002-03-28T00:00:00.000-05:00 + 2008-09-05T16:27:01.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20020306-01-P + + rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0040 + 2002-03-28T00:00:00.000-05:00 + 2008-09-05T16:27:01.230-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20020306-01-P + + + BID + 4388 + + + OSVDB + 2058 + + + XF + irix-hostaliases-gain-privileges(8669) + + Vulnerability in SGI IRIX 6.5.11 through 6.5.15f allows local users to cause privileged applications to dump core via the HOSTALIASES environment variable, which might allow the users to gain privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0041 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:01.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20020401-01-P + + + BID + 4499 + + + XF + irix-mail-core-dump(8835) + + + CIAC + M-067 + + Unknown vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, when running with the -R option, allows local and remote attackers to cause a core dump. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.10m + + CVE-2002-0042 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:27:01.607-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4511 + + + XF + irix-xfs-dos(8839) + + + SGI + 20020402-01-P + + Vulnerability in the XFS file system for SGI IRIX before 6.5.12 allows local users to cause a denial of service (hang) by creating a file that is not properly processed by XFS. + + + + + + + + + + + + + + + + + + + cpe:/a:todd_miller:sudo:1.6 + cpe:/a:todd_miller:sudo:1.6.3_p5 + cpe:/a:todd_miller:sudo:1.6.3_p6 + cpe:/a:todd_miller:sudo:1.6.3_p7 + cpe:/a:todd_miller:sudo:1.6.2 + cpe:/a:todd_miller:sudo:1.6.1 + cpe:/a:todd_miller:sudo:1.6.3_p2 + cpe:/a:todd_miller:sudo:1.6.3_p1 + cpe:/a:todd_miller:sudo:1.6.3 + cpe:/a:todd_miller:sudo:1.6.3_p4 + cpe:/a:todd_miller:sudo:1.6.3_p3 + + CVE-2002-0043 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:09.040-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2002:013 + + + MISC + http://www.sudo.ws/sudo/alerts/postfix.html + + + BUGTRAQ + 20020114 Sudo version 1.6.4 now available (fwd) + + + XF + sudo-unclean-env-root(7891) + + + BID + 3871 + + + IMMUNIX + IMNX-2002-70-001-01 + + + REDHAT + RHSA-2002:011 + + + SUSE + SuSE-SA:2002:002 + + + DEBIAN + DSA-101 + + + BUGTRAQ + 20020116 Sudo +Postfix Exploit + + + MANDRAKE + MDKSA-2002:003 + + + CONECTIVA + CLA-2002:451 + + + FREEBSD + FreeBSD-SA-02:06 + + sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked. + + + + + + + + + + + + + + + + + + + + cpe:/a:gnu:enscript:1.6.1 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2002-0044 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:09.117-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + gnu-enscript-tmpfile-symlink(7932) + + + BID + 3920 + + + HP + HPSBTL0201-019 + + + REDHAT + RHSA-2002:012 + + + MANDRAKE + MDKSA-2002:010 + + + DEBIAN + DSA-105 + + GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files. + + + + + + + + + + + + + + + + + cpe:/a:openldap:openldap:2.0.19 + cpe:/a:openldap:openldap:2.0 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + + CVE-2002-0045 + 2002-01-31T00:00:00.000-05:00 + 2008-09-10T15:11:09.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + openldap-slapd-delete-attributes(7978) + + + HP + HPSBTL0201-020 + + + BID + 3945 + + + REDHAT + RHSA-2002:014 + + + OSVDB + 5395 + + + CONFIRM + http://www.openldap.org/lists/openldap-announce/200201/msg00002.html + + + MANDRAKE + MDKSA-2002:013 + + + CONECTIVA + CLA-2002:459 + + + CALDERA + CSSA-2002-001.0 + + slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs. + + + + + + + + + cpe:/o:linux:linux_kernel:2.6.20.1 + + CVE-2002-0046 + 2002-01-31T00:00:00.000-05:00 + 2008-09-05T16:27:02.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020120 remote memory reading through tcp/icmp + + + XF + icmp-read-memory(7998) + + + REDHAT + RHSA-2002:007 + + + OSVDB + 5394 + + Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet. + + + + + + + + + cpe:/a:olaf_titz:cipe:1.3.0-3 + + CVE-2002-0047 + 2002-01-31T00:00:00.000-05:00 + 2008-09-05T16:27:02.433-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-104 + + + XF + cipe-packet-handling-dos(7883) + + + REDHAT + RHSA-2002:007 + + CIPE VPN package before 1.3.0-3 allows remote attackers to cause a denial of service (crash) via a short malformed packet. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::ppc + cpe:/a:andrew_tridgell:rsync:2.5.0_1 + cpe:/a:andrew_tridgell:rsync:2.5.1 + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::alpha + cpe:/a:andrew_tridgell:rsync:2.4.1 + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::arm + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::m68k + cpe:/a:andrew_tridgell:rsync:2.4.3 + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::sparc + cpe:/a:andrew_tridgell:rsync:2.3.2_1.2::intel + cpe:/a:andrew_tridgell:rsync:2.4.4 + cpe:/a:andrew_tridgell:rsync:2.3.1 + cpe:/a:andrew_tridgell:rsync:2.4.6 + cpe:/a:andrew_tridgell:rsync:2.3.2 + + CVE-2002-0048 + 2002-02-27T00:00:00.000-05:00 + 2008-09-10T15:11:09.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#800635 + + + BID + 3958 + + + DEBIAN + DSA-106 + + + SUSE + SuSE-SA:2002:004 + + + REDHAT + RHSA-2002:018 + + + ENGARDE + ESA-20020125-004 + + + MANDRAKE + MDKSA-2002:009 + + + XF + linux-rsync-root-access(7993) + + + CALDERA + CSSA-2002-003.0 + + + HP + HPSBTL0201-022 + + + BUGTRAQ + 20020127 rsync-2.5.2 has security fix (was: Re: [RHSA-2002:018-05] New rsync packages available) + + + FREEBSD + FreeBSD-SA-02:10 + + + BUGTRAQ + 20020128 TSLSA-2002-0025 - rsync + + + CONECTIVA + CLA-2002:458 + + Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server. + + + + + + + + + cpe:/a:microsoft:exchange_server:2000 + + CVE-2002-0049 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:02.747-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4053 + + + MS + MS02-003 + + + XF + exchange-attendant-incorrect-permissions(8092) + + + OSVDB + 2042 + + + + + Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys. + + + + + + + + + cpe:/a:microsoft:commerce_server:2000 + + CVE-2002-0050 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:09.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-010 + + + BID + 4157 + + Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2002-0051 + 2002-04-04T00:00:00.000-05:00 + 2008-09-05T16:27:03.043-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-016 + + + BID + 4438 + + + BUGTRAQ + 20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain) + + + + + Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.01 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0052 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:09.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-009 + + + BID + 4158 + + + OSVDB + 763 + + + SECTRACK + 1003630 + + Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-0053 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + CERT + CA-2002-03 + + + CERT-VN + VU#854306 + + + CERT-VN + VU#107186 + + + MS + MS02-006 + + + MISC + http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html + + + MISC + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013 + + + MISC + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012 + + + + + + + + Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5:sp1 + cpe:/a:microsoft:exchange_server:5.5:sp4 + cpe:/a:microsoft:exchange_server:5.5:sp3 + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/a:microsoft:exchange_server:5.5:sp2 + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/a:microsoft:exchange_server:5.5 + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + + CVE-2002-0054 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:03.450-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4205 + + + MS + MS02-011 + + + BUGTRAQ + 20020301 IIS SMTP component allows mail relaying via Null Session + + SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000:sp2 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:2000:sp1 + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2002-0055 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:03.637-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4204 + + + MS + MS02-012 + + + XF + ms-smtp-data-transfer-dos(8307) + + + BUGTRAQ + 20020306 Vulnerability Details for MS02-012 + + + + + SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0056 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:10.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#619707 + + + MS + MS02-007 + + + BID + 4135 + + + VULN-DEV + 20020219 MSDE, Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS + + + BUGTRAQ + 20020219 MSDE, Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS + + + + + Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection. + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:xml_core_services:3.0 + cpe:/a:microsoft:xml_core_services:2.6 + cpe:/a:microsoft:xml_core_services:4.0 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0057 + 2002-03-08T00:00:00.000-05:00 + 2008-09-10T15:11:10.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-008 + + + BUGTRAQ + 20020212 Update on the MS02-005 patch, holes still remain + + + BUGTRAQ + 20011214 MSIE6 can read local files + + + XF + ie-xmlhttp-redirect(7712) + + + BID + 3699 + + + OSVDB + 3032 + + XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source. + + + + + + + + + + + + + + + + + + + cpe:/a:sun:jre:1.1.8:update7 + cpe:/a:sun:sdk:1.3_02 + cpe:/a:sun:jdk:1.1.8:update7 + cpe:/a:sun:sdk:1.2.2_10 + cpe:/a:sun:sdk:1.1.8_007 + cpe:/a:sun:jre:1.3.0:update2 + cpe:/a:microsoft:virtual_machine:3802 + cpe:/a:sun:sdk:1.2.2_010 + cpe:/a:sun:jre:1.2.2:update10 + cpe:/a:sun:jdk:1.1.8:update13 + cpe:/a:sun:jre:1.1.8:update13 + + CVE-2002-0058 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:10.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-013 + + + BUGTRAQ + 20020305 Java HTTP proxy vulnerability + + + SUN + 00216 + + Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:gnu:zlib:1.0.4 + cpe:/a:gnu:zlib:1.0.5 + cpe:/a:gnu:zlib:1.0.2 + cpe:/a:gnu:zlib:1.0.3 + cpe:/a:gnu:zlib:1.0.8 + cpe:/a:gnu:zlib:1.0.9 + cpe:/a:gnu:zlib:1.1 + cpe:/a:gnu:zlib:1.0.6 + cpe:/a:gnu:zlib:1.0.7 + cpe:/a:gnu:zlib:1.0 + cpe:/a:gnu:zlib:1.1.3 + cpe:/a:gnu:zlib:1.0.1 + cpe:/a:gnu:zlib:1.1.1 + cpe:/a:gnu:zlib:1.1.2 + + CVE-2002-0059 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:10.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#368819 + + + CERT + CA-2002-07 + + + REDHAT + RHSA-2002:027 + + + REDHAT + RHSA-2002:026 + + + MANDRAKE + MDKSA-2002:023 + + + XF + zlib-doublefree-memory-corruption(8427) + + + HP + HPSBTL0204-037 + + + HP + HPSBTL0204-036 + + + HP + HPSBTL0204-030 + + + BID + 4267 + + + MANDRAKE + MDKSA-2002:024 + + + DEBIAN + DSA-122 + + + CALDERA + CSSA-2002-014.1 + + + MANDRAKE + MDKSA-2002:022 + + + CONECTIVA + CLA-2002:469 + + + CALDERA + CSSA-2002-015.1 + + The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data. + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18:pre9 + + CVE-2002-0060 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:04.450-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#230307 + + + CONFIRM + http://www.netfilter.org/security/2002-02-25-irc-dcc-mask.html + + + BUGTRAQ + 20020227 security advisory linux 2.4.x ip_conntrack_irc + + + XF + linux-dcc-port-access(8302) + + + HP + HPSBUX0203-027 + + + BID + 4188 + + + REDHAT + RHSA-2002:028 + + + VULN-DEV + 20020227 Fwd: [ANNOUNCE] Security Advisory about IRC DCC connection tracking + + + MANDRAKE + MDKSA-2002:041 + + IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions. + + + + + + + + + + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:2.0.28:beta + + CVE-2002-0061 + 2002-03-21T00:00:00.000-05:00 + 2008-09-05T16:27:04.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020321 Vulnerability in Apache for Win32 batch file processing - Remote command execution + + + CONFIRM + http://www.apacheweek.com/issues/02-03-29#apache1324 + + + BID + 4335 + + + XF + apache-dos-batch-command-execution(8589) + + + BUGTRAQ + 20020325 Apache 1.3.24 Released! (fwd) + + Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::ia-32 + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:redhat:linux:6.1::i386 + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:6.2 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:suse:suse_linux:6.3 + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2002-0062 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:04.747-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 2116 + + + REDHAT + RHSA-2002:020 + + + DEBIAN + DSA-113 + + + XF + gnu-ncurses-window-bo(8222) + + Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling." + + + + + + + + + cpe:/a:easy_software_products:cups:1.1.14 + + CVE-2002-0063 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:04.967-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2002:015 + + + DEBIAN + DSA-110 + + + CONFIRM + http://www.cups.org/relnotes.html + + + XF + cups-ippread-bo(8192) + + + BID + 4100 + + + REDHAT + RHSA-2002:032 + + + SUSE + SuSE-SA:2002:005 + + + CONECTIVA + CLA-2002:471 + + + CALDERA + CSSA-2002-008.0 + + Buffer overflow in ippRead function of CUPS before 1.1.14 may allow attackers to execute arbitrary code via long attribute names or language values. + + + + + + + + + + + + + + cpe:/a:funk_software:funk_software_proxy:3.09a + cpe:/a:bindview:netrc:3.06 + cpe:/a:funk_software:funk_software_proxy:3.0 + cpe:/a:bindview:netrc:1.0 + cpe:/a:funk_software:funk_software_proxy:3.06 + cpe:/a:funk_software:funk_software_proxy:3.09 + + CVE-2002-0064 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:14.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BINDVIEW + 20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x + + + BID + 4458 + + + XF + funk-proxy-insecure-permissions(8791) + + Funk Software Proxy Host 3.x is installed with insecure permissions for the registry and the file system. + + + + + + + + + + + + + + cpe:/a:funk_software:funk_software_proxy:3.09a + cpe:/a:bindview:netrc:3.06 + cpe:/a:funk_software:funk_software_proxy:3.0 + cpe:/a:bindview:netrc:1.0 + cpe:/a:funk_software:funk_software_proxy:3.06 + cpe:/a:funk_software:funk_software_proxy:3.09 + + CVE-2002-0065 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:14.727-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BINDVIEW + 20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x + + + BID + 4459 + + + XF + funk-proxy-weak-password(8792) + + Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry. + + + + + + + + + + + + + cpe:/a:bindview:netrc:3.06 + cpe:/a:funk_software:funk_software_proxy:3.0 + cpe:/a:bindview:netrc:1.0 + cpe:/a:funk_software:funk_software_proxy:3.06 + cpe:/a:funk_software:funk_software_proxy:3.09 + + CVE-2002-0066 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:14.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BINDVIEW + 20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x + + + BID + 4460 + + + XF + funk-proxy-named-pipe(8793) + + Funk Software Proxy Host 3.x before 3.09A creates a Named Pipe that does not require authentication and is installed with insecure access control, which allows local and possibly remote users to use the Proxy Host's configuration utilities and gain privileges. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0::alpha + cpe:/a:squid:squid:2.4_stable_2 + + CVE-2002-0067 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:05.573-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + REDHAT + RHSA-2002:029 + + + BID + 4150 + + + OSVDB + 5379 + + + MANDRAKE + MDKSA-2002:016 + + + XF + squid-htcp-enabled(8261) + + + BUGTRAQ + 20020222 TSLSA-2002-0031 - squid + + + BUGTRAQ + 20020221 Squid HTTP Proxy Security Update Advisory 2002:1 + + + CONECTIVA + CLA-2002:464 + + + CALDERA + CSSA-2002-SCO.7 + + + FREEBSD + FreeBSD-SA-02:12 + + Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/a:squid:squid:2.4_stable_3 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0::alpha + + CVE-2002-0068 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:05.730-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:029 + + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + BID + 4148 + + + OSVDB + 5378 + + + SUSE + SuSE-SA:2002:008 + + + MANDRAKE + MDKSA-2002:016 + + + XF + squid-ftpbuildtitleurl-bo(8258) + + + CALDERA + CSSA-2002-010.0 + + + BUGTRAQ + 20020222 TSLSA-2002-0031 - squid + + + BUGTRAQ + 20020222 Squid buffer overflow + + + BUGTRAQ + 20020221 Squid HTTP Proxy Security Update Advisory 2002:1 + + + CONECTIVA + CLA-2002:464 + + + CALDERA + CSSA-2002-SCO.7 + + + FREEBSD + FreeBSD-SA-02:12 + + Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0::alpha + cpe:/a:squid:squid:2.4_stable_2 + + CVE-2002-0069 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:05.903-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + REDHAT + RHSA-2002:029 + + + BID + 4146 + + + MANDRAKE + MDKSA-2002:016 + + + XF + squid-snmp-dos(8260) + + + BUGTRAQ + 20020222 TSLSA-2002-0031 - squid + + + BUGTRAQ + 20020221 Squid HTTP Proxy Security Update Advisory 2002:1 + + + CONECTIVA + CLA-2002:464 + + + CALDERA + CSSA-2002-SCO.7 + + + FREEBSD + FreeBSD-SA-02:12 + + Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service. + + + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-0070 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + MS + MS02-014 + + + BID + 4248 + + + NTBUGTRAQ + 20020311 ADVISORY: Windows Shell Overflow + + + XF + win-shell-bo(8384) + + + BUGTRAQ + 20020312 ADVISORY: Windows Shell Overflow + + + + + + + + Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0071 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:15.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#363715 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4474 + + + OSVDB + 3325 + + + XF + iis-htr-isapi-bo(8799) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + ATSTAKE + A041002-1 + + + BUGTRAQ + 20020411 KPMG-2002010: Microsoft IIS .htr ISAPI buffer overrun + + + + + + + + + + + Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0072 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:15.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#521059 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4479 + + + OSVDB + 3326 + + + XF + iis-isapi-filter-error-dos(8800) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + BUGTRAQ + 20020411 KPMG-2002009: Microsoft IIS W3SVC Denial of Service + + + + + The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0073 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:15.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + CERT-VN + VU#412203 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + MISC + http://www.digitaloffense.net/msftpd/advisory.txt + + + BID + 4482 + + + OSVDB + 3328 + + + XF + iis-ftp-session-status-dos(8801) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + BUGTRAQ + 20020417 Microsoft FTP Service STAT Globbing DoS + + + VULNWATCH + 20020416 [VulnWatch] Microsoft FTP Service STAT Globbing DoS + + + + + + + + + + + The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0074 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:16.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#883091 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + MISC + http://www.cgisecurity.com/advisory/9.txt + + + BID + 4483 + + + OSVDB + 3338 + + + XF + iis-help-file-css(8802) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + BUGTRAQ + 20020410 Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues + + + + + + + + Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0075 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:06.823-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#520707 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4487 + + + OSVDB + 3341 + + + XF + iis-redirected-url-error-css(8804) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + BUGTRAQ + 20020411 [SNS Advisory No.49] A Possibility of Internet Information Server/Services Cross Site Scripting + + + + + + + + + + + Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sun:jre:1.1.8:update14 + cpe:/a:sun:sdk:1.3.1_01 + cpe:/a:sun:sdk:1.2.2_10 + cpe:/a:microsoft:virtual_machine:3802 + cpe:/a:hp:java_jre-jdk:1.1.8 + cpe:/a:sun:jdk:1.1.8:update8 + cpe:/a:hp:java_jre-jdk:1.2.2 + cpe:/a:sun:jre:1.2.2:update10 + cpe:/a:sun:sdk:1.3_05 + cpe:/a:sun:sdk:1.3.1_01a + cpe:/a:sun:jre:1.3.0:update5 + cpe:/a:sun:jre:1.1.8:update8 + cpe:/a:hp:java_jre-jdk:1.3 + cpe:/a:sun:jre:1.3.1:update1 + cpe:/a:sun:jre:1.3.1:update1a + cpe:/a:sun:jdk:1.1.8:update14 + cpe:/a:sun:sdk:1.2.2_010 + + CVE-2002-0076 + 2002-03-19T00:00:00.000-05:00 + 2008-09-05T16:27:06.967-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-013 + + + SUN + 00218 + + + BID + 4313 + + + XF + java-vm-verifier-variant(8480) + + Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability. + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0077 + 2002-01-13T00:00:00.000-05:00 + 2008-09-05T16:27:07.217-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-015 + + + BUGTRAQ + 20020113 Internet Explorer Pop-Up OBJECT Tag Bug + + Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability. + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0078 + 2002-03-29T00:00:00.000-05:00 + 2008-09-05T16:27:07.370-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-015 + + + BID + 4392 + + + OSVDB + 3029 + + + XF + ie-cookie-local-zone(8701) + + + BUGTRAQ + 20020330 IE: Remote webpage can script in local zone + + + + + The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0079 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:07.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#610291 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4485 + + + XF + iis-asp-chunked-encoding-bo(8795) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + BUGTRAQ + 20020410 Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow + + + + + + + + + + + Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.0::i686 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:7.2::i686 + cpe:/o:redhat:linux:7.1::i686 + cpe:/o:redhat:linux:6.2::i586 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:7.2::i586 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:6.2::i686 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.0::i586 + cpe:/o:redhat:linux:7.1::i586 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::i386 + cpe:/a:andrew_tridgell:rsync + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:7.0::alpha + + CVE-2002-0080 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T16:27:07.667-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:026 + + + BID + 4285 + + + MANDRAKE + MDKSA-2002:024 + + + XF + linux-rsync-inherit-privileges(8463) + + + CALDERA + CSSA-2002-014.1 + + rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed. + + + + + + + + + + + + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:3.0 + + CVE-2002-0081 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:27:07.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#297363 + + + CERT + CA-2002-05 + + + CONFIRM + http://www.php.net/downloads.php + + + MISC + http://security.e-matters.de/advisories/012002.html + + + BID + 4183 + + + REDHAT + RHSA-2002:040 + + + REDHAT + RHSA-2002:035 + + + SUSE + SuSE-SA:2002:007 + + + ENGARDE + ESA-20020301-006 + + + MANDRAKE + MDKSA-2002:017 + + + XF + php-file-upload-overflow(8281) + + + DEBIAN + DSA-115 + + + HP + HPSBTL0203-028 + + + VULN-DEV + 20020225 Re: Rumours about Apache 1.3.22 exploits + + + NTBUGTRAQ + 20020227 PHP remote vulnerabilities + + + BUGTRAQ + 20020304 Apache+php Proof of Concept Exploit + + + BUGTRAQ + 20020228 TSLSA-2002-0033 - mod_php + + + BUGTRAQ + 20020227 Advisory 012002: PHP remote vulnerabilities + + + CONECTIVA + CLA-2002:468 + + Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mod_ssl:mod_ssl:2.7.1 + cpe:/a:mod_ssl:mod_ssl:2.8.6 + cpe:/a:mod_ssl:mod_ssl:2.8 + cpe:/a:mod_ssl:mod_ssl:2.8.4 + cpe:/a:mod_ssl:mod_ssl:2.8.5 + cpe:/a:apache-ssl:apache-ssl:1.45 + cpe:/a:apache-ssl:apache-ssl:1.46 + cpe:/a:mod_ssl:mod_ssl:2.8.3 + cpe:/a:mod_ssl:mod_ssl:2.8.2 + cpe:/a:mod_ssl:mod_ssl:2.8.1 + cpe:/a:apache-ssl:apache-ssl:1.40 + cpe:/a:apache-ssl:apache-ssl:1.44 + cpe:/a:apache-ssl:apache-ssl:1.41 + cpe:/a:apache-ssl:apache-ssl:1.42 + + CVE-2002-0082 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:17.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + apache-modssl-bo(8308) + + + CONFIRM + http://www.apacheweek.com/issues/02-03-01#security + + + BUGTRAQ + 20020301 Apache-SSL buffer overflow (fix available) + + + BID + 4189 + + + HP + HPSBUX0204-190 + + + HP + HPSBTL0203-031 + + + REDHAT + RHSA-2002:045 + + + REDHAT + RHSA-2002:042 + + + REDHAT + RHSA-2002:041 + + + ENGARDE + ESA-20020301-005 + + + MANDRAKE + MDKSA-2002:020 + + + DEBIAN + DSA-120 + + + CALDERA + CSSA-2002-011.0 + + + BUGTRAQ + 20020227 mod_ssl Buffer Overflow Condition (Update Available) + + + BUGTRAQ + 20020304 Apache-SSL 1.3.22+1.47 - update to security fix + + + COMPAQ + SSRT0817 + + + CONECTIVA + CLA-2002:465 + + The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:7.0::i386 + cpe:/o:suse:suse_linux:6.4::i386 + cpe:/o:conectiva:linux:6.0 + cpe:/o:engardelinux:secure_linux:1.0.1 + cpe:/a:openbsd:openssh:2.9.9 + cpe:/o:suse:suse_linux:7.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/o:conectiva:linux:5.0 + cpe:/o:suse:suse_linux:7.3::i386 + cpe:/o:conectiva:linux:5.1 + cpe:/o:suse:suse_linux:7.1:alpha + cpe:/a:openbsd:openssh:2.5 + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:suse:suse_linux:7.0:alpha + cpe:/a:openpkg:openpkg:1.0 + cpe:/a:openbsd:openssh:2.9 + cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2 + cpe:/o:conectiva:linux:7.0 + cpe:/a:openbsd:openssh:2.1 + cpe:/o:suse:suse_linux:7.3::ppc + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/o:suse:suse_linux:7.0::ppc + cpe:/o:suse:suse_linux:6.4:alpha + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/a:openbsd:openssh:2.3 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:conectiva:linux:ecommerce + cpe:/o:suse:suse_linux:7.1::spa + cpe:/o:trustix:secure_linux:1.5 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:suse:suse_linux:7.1::x86 + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.1 + cpe:/a:openbsd:openssh:2.9p1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + cpe:/a:openbsd:openssh:2.9p2 + cpe:/o:suse:suse_linux:7.0::sparc + cpe:/o:suse:suse_linux:7.1::sparc + cpe:/a:immunix:immunix:7.0 + cpe:/a:openbsd:openssh:3.0.1 + cpe:/o:suse:suse_linux:7.3::sparc + cpe:/o:conectiva:linux:graficas + cpe:/a:openbsd:openssh:2.5.2 + cpe:/a:openbsd:openssh:2.5.1 + + CVE-2002-0083 + 2002-03-15T00:00:00.000-05:00 + 2008-11-20T00:00:00.000-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + ENGARDE + ESA-20020307-007 + + + BID + 4241 + + + REDHAT + RHSA-2002:043 + + + OSVDB + 730 + + + CONFIRM + http://www.openbsd.org/advisories/ssh_channelalloc.txt + + + SUSE + SuSE-SA:2002:009 + + + MANDRAKE + MDKSA-2002:019 + + + XF + openssh-channel-error(8383) + + + DEBIAN + DSA-119 + + + CALDERA + CSSA-2002-012.0 + + + BUGTRAQ + 20020328 OpenSSH channel_lookup() off by one exploit + + + HP + HPSBTL0203-029 + + + BUGTRAQ + 20020310 OpenSSH 2.9.9p2 packages for Immunix 6.2 with latest fix + + + BUGTRAQ + 20020308 [OpenPKG-SA-2002.002] OpenPKG Security Advisory (openssh) + + + BUGTRAQ + 20020307 OpenSSH Security Advisory (adv.channelalloc) + + + BUGTRAQ + 20020307 [PINE-CERT-20020301] OpenSSH off-by-one + + + CONECTIVA + CLA-2002:467 + + + VULNWATCH + 20020307 [VulnWatch] [PINE-CERT-20020301] OpenSSH off-by-one + + + BUGTRAQ + 20020311 TSLSA-2002-0039 - openssh + + + CALDERA + CSSA-2002-SCO.11 + + + CALDERA + CSSA-2002-SCO.10 + + + NETBSD + NetBSD-SA2002-004 + + + FREEBSD + FreeBSD-SA-02:13 + + Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + + CVE-2002-0084 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:18.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT-VN + VU#161931 + + + MISC + http://www.esecurityonline.com/advisories/eSO4198.asp + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309 + + + BUGTRAQ + 20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability + + + + + + + + Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + + CVE-2002-0085 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:18.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MISC + http://www.esecurityonline.com/advisories/eSO4197.asp + + + XF + solaris-cachefsd-rpc-dos(8956) + + + BID + 4634 + + + VULNWATCH + 20020429 eSecurityOnline Security Advisory 4197 - Sun Solaris cachefsd denial of service vulnerability + + + BUGTRAQ + 20020429 eSecurityOnline Security Advisory 2397 - Sun Solaris admintool -d and PRODVERS buffer overflow vulnerabilities + + + + + cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request. + + + + + + + + + + cpe:/a:ibm:lotus_domino:5.0.4::linux + cpe:/a:ibm:lotus_domino:5.0.7::linux + + CVE-2002-0086 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T16:27:08.747-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.esecurityonline.com/advisories/eSO4126.asp + + + MISC + http://www.esecurityonline.com/advisories/eSO4124.asp + + + XF + lotus-domino-path-bo(8585) + + + XF + lotus-domino-notes-execdirectory-bo(8583) + + + BID + 4319 + + + BID + 4317 + + + CONFIRM + http://www-1.ibm.com/support/docview.wss?uid=swg21100441 + + + CONFIRM + http://www-1.ibm.com/support/docview.wss?uid=swg21095569 + + Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable. + + + + + + + + + cpe:/a:lotus:domino:5.0.7::solaris + + CVE-2002-0087 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T16:27:08.887-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lotus-domino-tmpfile-symlink(8586) + + + BID + 4318 + + + MISC + http://www.esecurityonline.com/advisories/eSO4125.asp + + + CONFIRM + http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg21095671 + + bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + + CVE-2002-0088 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:18.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MISC + http://www.esecurityonline.com/advisories/eSO4123.asp + + + + + + + + Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-2002-0089 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:18.947-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MISC + http://www.esecurityonline.com/advisories/eSO2397.asp + + + BID + 4624 + + + XF + solaris-admintool-prodvers-bo(8955) + + + XF + solaris-admintool-d-bo(8954) + + + BUGTRAQ + 20020429 eSecurityOnline Security Advisory 2397 - Sun Solaris admintool -d and PRODVERS buffer overflow vulnerabilities + + + + + + + + Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file. + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + + CVE-2002-0090 + 2002-03-15T00:00:00.000-05:00 + 2008-09-10T15:11:19.023-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT-VN + VU#188507 + + + MISC + http://www.esecurityonline.com/advisories/eSO3761.asp + + + BID + 4633 + + + XF + solaris-lbxproxy-display-bo(8958) + + + SUNALERT + 44842 + + + BUGTRAQ + 20020429 eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability + + + VULNWATCH + 20020429 [VulnWatch] eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability + + + + + + + + Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option. + + + + + + + + + + cpe:/a:nswc:cider_shadow:1.5 + cpe:/a:nswc:cider_shadow:1.6 + + CVE-2002-0091 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T16:27:09.480-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.esecurityonline.com/advisories/eSO2408.asp + + + BID + 4625 + + + XF + shadow-cgi-execute-commands(8953) + + + BUGTRAQ + 20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI + + Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields. + + + + + + + + + cpe:/a:cvs:cvs:1.10.8 + + CVE-2002-0092 + 2002-03-15T00:00:00.000-05:00 + 2008-09-05T16:27:09.620-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-117 + + + VULN-DEV + 20020220 Re: [Fwd: Help needed with bufferoverflow in cvs] + + + VULN-DEV + 20020220 Help needed with bufferoverflow in cvs + + + BID + 4234 + + + REDHAT + RHSA-2002:026 + + + XF + cvs-global-var-dos(8366) + + CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability. + + + + + + + + + + + + + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:5.1a + cpe:/o:compaq:tru64:4.0f + + CVE-2002-0093 + 2002-09-05T00:00:00.000-04:00 + 2011-03-07T21:07:45.203-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#771155 + + + BID + 5241 + + + XF + tru64-ipcs-bo(9613) + + + HP + SSRT0794U + + Buffer overflow in ipcs for HP Tru64 UNIX 4.0f through 5.1a may allow attackers to execute arbitrary code, a different vulnerability than CVE-2001-0423. + + + + + + + + + + cpe:/a:fraunhofer_fit:bscw:3.4 + cpe:/a:fraunhofer_fit:bscw:4.0 + + CVE-2002-0094 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:09.917-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 3776 + + + BUGTRAQ + 20020102 BSCW: Vulnerabilities and Problems + + + XF + bscw-remote-shell-execution(7774) + + + MISC + http://bscw.gmd.de/WhatsNew.html + + config_converters.py in BSCW (Basic Support for Cooperative Work) 3.x and versions before 4.06 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name during filename conversion. + + + + + + + + + + + cpe:/a:fraunhofer_fit:bscw:3.4 + cpe:/a:fraunhofer_fit:bscw:4.0 + cpe:/a:fraunhofer_fit:bscw:4.0.6 + + CVE-2002-0095 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:10.073-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3777 + + + BUGTRAQ + 20020102 BSCW: Vulnerabilities and Problems + + + XF + bscw-default-installation-registration(7775) + + The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which could allow remote attackers to upload files and possibly join a user community that was intended to be closed. + + + + + + + + + cpe:/a:geeklog:geeklog:1.3 + + CVE-2002-0096 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:10.217-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3783 + + + BUGTRAQ + 20020103 Vulnerability in new user creation in Geeklog 1.3 + + + XF + geeklog-default-admin-privileges(7780) + + + CONFIRM + http://geeklog.sourceforge.net/index.php?topic=Security + + The installation of Geeklog 1.3 creates an extra group_assignments record which is not properly deleted, which causes the first newly created user to be added to the GroupAdmin and UserAdmin groups, which could provide that user with administrative privileges that were not intended. + + + + + + + + + cpe:/a:geeklog:geeklog:1.3 + + CVE-2002-0097 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:19.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + geeklog-modify-auth-cookie(7869) + + + BUGTRAQ + 20020110 Cookie modification allows unauthenticated user login in Geeklog 1.3 + + + CONFIRM + http://geeklog.sourceforge.net/index.php?topic=Security + + + BID + 3844 + + Geeklog 1.3 allows remote attackers to hijack user accounts, including the administrator account, by modifying the UID of a user's permanent cookie to the target account. + + + + + + + + + cpe:/a:boozt:boozt_standard:0.9.8 + + CVE-2002-0098 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:10.497-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3787 + + + XF + boozt-long-name-bo(7790) + + + CONFIRM + http://www.boozt.com/news_detail.php?id=3 + + + BUGTRAQ + 20020109 BOOZT! Standard CGI Vulnerability : Exploit Released + + + BUGTRAQ + 20020105 BOOZT! Standard 's administration cgi vulnerable to buffer overflow + + Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner. + + + + + + + + + cpe:/a:michael_lamont:savant_webserver:3.0 + + CVE-2002-0099 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:20.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + savant-long-parameter-bo(7786) + + + BUGTRAQ + 20020105 Savant Webserver Buffer Overflow Vulnerability + + + BID + 3788 + + + NTBUGTRAQ + 20020109 Savant Webserver Buffer Overflow Vulnerability + + Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name contains a large number of . (dot) characters. + + + + + + + + + cpe:/a:aol:aol_server:3.4.2::win32 + + CVE-2002-0100 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:20.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + aolserver-protected-file-access(7825) + + + BUGTRAQ + 20020106 AOLserver 3.4.2 Unauthorized File Disclosure Vulnerability + + + BID + 3791 + + + NTBUGTRAQ + 20020109 AOLserver 3.4.2 Unauthorized File Disclosure Vulnerability + + + VULNWATCH + 20020106 AOLserver 3.4.2 Unauthorized File Disclosure Vulnerability + + AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0101 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:20.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-modeless-dialog-dos(7826) + + + BID + 3789 + + + BUGTRAQ + 20020106 Internet Explorer Javascript Modeless Popup Local Denial of Service + + Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2::nt + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + + CVE-2002-0102 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:20.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/webcache2.pdf + + + XF + oracle-appserver-null-dos(7765) + + + BID + 3762 + + + BID + 3760 + + Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters. + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + + CVE-2002-0103 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:20.820-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/webcache2.pdf + + + BUGTRAQ + 20020107 [PTL-2002-01] Vulnerabilities in Oracle9iAS Web Cache + + + BID + 3764 + + + BID + 3761 + + + XF + oracle-appserver-webcache-password(7768) + + + XF + oracle-appserver-webcached-privileges(7766) + + An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml. + + + + + + + + + cpe:/a:aftpd:aftpd:5.4.4 + + CVE-2002-0104 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:02.473-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3806 + + + XF + aftpd-crash-core-dump(7832) + + + BUGTRAQ + 20020107 Aftpd core dump vulnerability + + AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump. + + + + + + + + + cpe:/a:caldera:unixware:7.1.0 + + CVE-2002-0105 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:11.510-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3818 + + + XF + unixware-dtlogin-log-symlink(7864) + + + BUGTRAQ + 20020108 CDE bug in Unixware 7.1 + + CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable. + + + + + + + + + + cpe:/a:bea:weblogic_server:6.1:sp1 + cpe:/a:bea:weblogic_server:6.1 + + CVE-2002-0106 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:11.667-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3816 + + + XF + weblogic-dos-jsp-dos(7808) + + + BUGTRAQ + 20020108 KPMG-2002003: Bea Weblogic DOS-device Denial of Service + + BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cacheflow:cacheos:3.1.02 + cpe:/a:cacheflow:cacheos:3.1.03 + cpe:/a:cacheflow:cacheos:3.1.04 + cpe:/a:cacheflow:cacheos:3.1.05 + cpe:/a:cacheflow:cacheos:3.1.06 + cpe:/a:cacheflow:cacheos:3.1.07 + cpe:/a:cacheflow:cacheos:3.1.08 + cpe:/a:cacheflow:cacheos:3.1.09 + cpe:/a:cacheflow:cacheos:4.0.12 + cpe:/a:cacheflow:cacheos:3.1.14 + cpe:/a:cacheflow:cacheos:4.0.11 + cpe:/a:cacheflow:cacheos:3.1.13 + cpe:/a:cacheflow:cacheos:3.1.16 + cpe:/a:cacheflow:cacheos:3.1.15 + cpe:/a:cacheflow:cacheos:3.1.18 + cpe:/a:cacheflow:cacheos:3.1.17 + cpe:/a:cacheflow:cacheos:3.1.19 + cpe:/a:cacheflow:cacheos:3.1.10 + cpe:/a:cacheflow:cacheos:0.0 + cpe:/a:cacheflow:cacheos:3.1.12 + cpe:/a:cacheflow:cacheos:4.0.13 + cpe:/a:cacheflow:cacheos:3.1.20 + cpe:/a:cacheflow:cacheos:3.1.11 + + CVE-2002-0107 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:11.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3841 + + + XF + cachos-insecure-web-interface(7835) + + + BUGTRAQ + 20020205 RE: svindel.net security advisory - web admin vulnerability in Ca cheOS + + + BUGTRAQ + 20020108 svindel.net security advisory - web admin vulnerability in CacheOS + + Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message. + + + + + + + + + + + + cpe:/a:allaire:forums:3.0 + cpe:/a:allaire:forums:2.0.5 + cpe:/a:allaire:forums:2.0.4 + cpe:/a:allaire:forums:3.1 + + CVE-2002-0108 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:03.190-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#575619 + + + BID + 3827 + + + XF + allaire-forums-message-spoofing(7841) + + + BUGTRAQ + 20020108 Allaire Forums Vulnerability + + Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address. + + + + + + + + + + + cpe:/h:linksys:befsr81 + cpe:/h:linksys:befsr41:0.0 + cpe:/h:linksys:befn2ps4:0.0 + + CVE-2002-0109 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:03.440-05:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3795 + + + XF + linksys-etherfast-default-snmp(7827) + + + BUGTRAQ + 20020106 Linksys 'routers', SNMP issues + + + BID + 3797 + + Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query. + + + + + + + + + cpe:/a:nevrona_designs:miramail:1.04 + + CVE-2002-0110 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:03.690-05:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#245707 + + + XF + miramail-plaintext-auth-info(7855) + + + BID + 3843 + + + BUGTRAQ + 20020109 MiraMail 1.04 can give POP account access and details + + Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file. + + + + + + + + + + cpe:/a:funsoft:dinos_webserver:1.2 + cpe:/a:funsoft:dinos_webserver:1.0 + + CVE-2002-0111 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:12.497-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + dinos-webserver-directory-traversal(7853) + + + BID + 3861 + + + BUGTRAQ + 20020109 File Transversal Vulnerability in Dino's WebServer + + Directory traversal vulnerability in Funsoft Dino's Webserver 1.2 and earlier allows remote attackers to read files or execute arbitrary commands via a .. (dot dot) in the URL. + + + + + + + + + + + + + + + cpe:/a:etype:eserv:2.92 + cpe:/a:etype:eserv:2.95_beta2 + cpe:/a:etype:eserv:2.97 + cpe:/a:etype:eserv:2.96 + cpe:/a:etype:eserv:2.95 + cpe:/a:etype:eserv:2.94 + cpe:/a:etype:eserv:2.93 + + CVE-2002-0112 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:21.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020111 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability (Solution) + + + XF + eserv-protected-file-access(7849) + + + NTBUGTRAQ + 20020109 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability + + + VULNWATCH + 20020109 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability + + + BID + 3838 + + + BUGTRAQ + 20020109 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability + + Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. + + + + + + + + + cpe:/a:emc:networker:6.1 + + CVE-2002-0113 + 2002-03-25T00:00:00.000-05:00 + 2012-03-29T21:14:51.403-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3840 + + + XF + legato-nsrd-log-permissions(7897) + + + BUGTRAQ + 20020110 Legato Vulnerable + + EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform. + + + + + + + + + cpe:/a:emc:networker:6.1 + + CVE-2002-0114 + 2002-03-25T00:00:00.000-05:00 + 2012-03-29T21:14:51.557-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3842 + + + XF + legato-nsrd-log-plaintext(7898) + + + BUGTRAQ + 20020110 Legato Vulnerable + + EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform. + + + + + + + + + cpe:/a:martin_roesch:snort:1.8.3 + + CVE-2002-0115 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + snort-icmp-dos(7874) + + + BUGTRAQ + 20020110 Re: Snort core dumped + + + BUGTRAQ + 20020110 Snort core dumped + + + BID + 3849 + + + OSVDB + 2022 + + Snort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of service (crash and core dump) via a malformed ICMP packet. + + + + + + + + + cpe:/o:palm:palm_os:3.5h + + CVE-2002-0116 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + palmos-nmap-dos(7865) + + + BUGTRAQ + 20020110 Handspring Visor D.O.S + + + BID + 3847 + + + BUGTRAQ + 20020110 Re: Handspring Visor D.O.S + + Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nmap. + + + + + + + + + + + + cpe:/a:yabb:yabb:2000-09-01 + cpe:/a:yabb:yabb:2000-09-11 + cpe:/a:yabb:yabb:0.01_release:gold + cpe:/a:yabb:yabb:0.01_sp1:gold + + CVE-2002-0117 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:13.357-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + yabb-encoded-css(7840) + + + BID + 3828 + + + BUGTRAQ + 20020108 CSS vulnerabilities in YaBB and UBB allow account hijack [Multiple Vendor] + + + CONFIRM + http://www.yabbforum.com/ + + + OSVDB + 2019 + + Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag. + + + + + + + + + + + + + + + + + cpe:/a:infopop:ultimate_bulletin_board:6.0.1 + cpe:/a:infopop:ultimate_bulletin_board:6.0.2 + cpe:/a:infopop:ultimate_bulletin_board:6.0.4f + cpe:/a:infopop:ultimate_bulletin_board:6.0.3 + cpe:/a:infopop:ultimate_bulletin_board:6.0 + cpe:/a:infopop:ultimate_bulletin_board:5.43 + cpe:/a:infopop:ultimate_bulletin_board:5.4.7e + cpe:/a:infopop:ultimate_bulletin_board:6.0beta + cpe:/a:infopop:ultimate_bulletin_board:6.2.0_beta_release_1.0 + + CVE-2002-0118 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:04.847-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020108 CSS vulnerabilities in YaBB and UBB allow account hijack [Multiple Vendor] + + + BID + 3829 + + + XF + ultimatebb-encoded-css(7838) + + Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag. + + + + + + + + + cpe:/h:alcatel:speed_touch_home:0.0%2cadsl + + CVE-2002-0119 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + alcatel-speedtouch-nmap-dos(7893) + + + BUGTRAQ + 20020111 Bug in alcatel speed touch home adsl modem + + + BID + 3851 + + Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection. + + + + + + + + + + cpe:/a:palm:palm_desktop:4.0b76 + cpe:/a:palm:palm_desktop:4.0b77 + + CVE-2002-0120 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.790-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + palm-macos-backup-permissions(7937) + + + BUGTRAQ + 20020112 Palm Desktop 4.0b76-77 for Mac OS X + + + BID + 3863 + + Apple Palm Desktop 4.0b76 and 4.0b77 creates world-readable backup files and folders when a hotsync is performed, which could allow a local user to obtain sensitive information. + + + + + + + + + + + + + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + + CVE-2002-0121 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.853-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020113 PHP 4.x session spoofing + + + XF + php-session-temp-disclosure(7908) + + + BID + 3873 + + PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections. + + + + + + + + + cpe:/h:siemens:3568i_wap:0.0 + + CVE-2002-0122 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:32.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020114 Siemens Mobie SMS Exceptional Character Vulnerability + + + XF + siemens-invalid-sms-dos(7902) + + + BID + 3870 + + Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters. + + + + + + + + + cpe:/a:mdg_computer_services:web_server_4d_ecommerce:3.5.3 + + CVE-2002-0123 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ws4d-long-url-dos(7879) + + + BUGTRAQ + 20020114 Web Server 4D/eCommerce 3.5.3 DoS Vulnerability + + + BID + 3874 + + MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. + + + + + + + + + cpe:/a:mdg_computer_services:web_server_4d_ecommerce:3.5.3 + + CVE-2002-0124 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ws4d-dot-directory-traversal(7878) + + + BUGTRAQ + 20020114 Web Server 4D/eCommerce 3.5.3 Directory Traversal Vulnerability + + + BID + 3872 + + MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request. + + + + + + + + + cpe:/a:clanlib:clanlib:0.5 + + CVE-2002-0125 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + clanlib-long-env-bo(7905) + + + BUGTRAQ + 20020114 Clanlib overflow / Super Methane Brothers overflow + + + BID + 3877 + + Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable. + + + + + + + + + + + + + + cpe:/a:selom_ofori:blackmoon_ftp_server:1.0 + cpe:/a:selom_ofori:blackmoon_ftp_server:1.1 + cpe:/a:selom_ofori:blackmoon_ftp_server:1.2 + cpe:/a:selom_ofori:blackmoon_ftp_server:1.3 + cpe:/a:selom_ofori:blackmoon_ftp_server:1.4 + cpe:/a:selom_ofori:blackmoon_ftp_server:1.5 + + CVE-2002-0126 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + blackmoon-ftpd-static-bo(7895) + + + BUGTRAQ + 20020115 BlackMoon FTPd Buffer Overflow Vulnerability + + + MISC + http://members.rogers.com/blackmoon2k/pages/news_page.html + + + BID + 3884 + + Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD. + + + + + + + + + cpe:/h:netgear:rp114:3.26 + + CVE-2002-0127 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:06.080-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3876 + + + BUGTRAQ + 20020115 Vulnerability Netgear RP-114 Router - nmap causes DOS + + Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26, when configured to block traffic below port 1024, allows remote attackers to cause a denial of service (hang) via a port scan of the WAN port. + + + + + + + + + cpe:/a:sambar:sambar_server:5.1 + + CVE-2002-0128 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:14.980-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3885 + + + BUGTRAQ + 20020116 Sambar Webserver v5.1 DoS Vulnerability + + + CONFIRM + http://www.sambar.com/security.htm + + + XF + sambar-cgitest-dos(7894) + + + BUGTRAQ + 20020206 Sambar Webserver Sample Script v5.1 DoS Vulnerability Exploit + + cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long argument. + + + + + + + + + + + cpe:/a:efax:efax:0.9 + cpe:/a:efax:efax:0.9a + cpe:/a:efax:efax:0.8a + + CVE-2002-0129 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.603-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + efax-d-read-files(7921) + + + BID + 3895 + + + BUGTRAQ + 20020116 Re: efax + + + VULN-DEV + 20020116 efax + + efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message. + + + + + + + + + + + cpe:/a:efax:efax:0.9 + cpe:/a:efax:efax:0.9a + cpe:/a:efax:efax:0.8a + + CVE-2002-0130 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.697-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + efax-x-bo(7920) + + + VULN-DEV + 20020117 Re: efax - Exploitation info + + + BID + 3894 + + + BUGTRAQ + 20020116 Re: efax + + Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument. + + + + + + + + + + cpe:/a:activestate:activepython + cpe:/a:activestate:activepython:2.1 + + CVE-2002-0131 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:33.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020116 Re: Serious privacy leak in Python for Windows + + + XF + activepython-activex-read-files(7910) + + + BID + 3893 + + + BUGTRAQ + 20020115 Serious privacy leak in Python for Windows + + ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script. + + + + + + + + + cpe:/a:chinput:chinput:3.0 + + CVE-2002-0132 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.430-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + chinput-long-env-bo(7911) + + + BUGTRAQ + 20020116 Chinput Buffer Overflow Vulnerability + + + BID + 3896 + + Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable. + + + + + + + + + + + cpe:/a:avirt:avirt_gateway:4.2 + cpe:/a:avirt:avirt_soho:4.2 + cpe:/a:avirt:avirt_gateway_suite:4.2 + + CVE-2002-0133 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3905 + + + BID + 3904 + + + XF + avirt-telnet-proxy-bo(7918) + + + XF + avirt-http-proxy-bo(7916) + + + BUGTRAQ + 20020117 Avirt Proxy Buffer Overflow Vulnerabilities + + + BUGTRAQ + 20020220 Avirt 4.2 question + + + BUGTRAQ + 20020212 Avirt Gateway 4.2 remote buffer overflow: proof of concept + + + BUGTRAQ + 20020121 [resend] Avirt Gateway Telnet Vulnerability (and more?) + + Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string to the telnet proxy. + + + + + + + + + cpe:/a:avirt:avirt_gateway_suite:4.2 + + CVE-2002-0134 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + avirt-gateway-telnet-access(7915) + + + BUGTRAQ + 20020220 Avirt 4.2 question + + + BUGTRAQ + 20020117 Avirt Gateway Suite Remote SYSTEM Level Compromise + + + BID + 3901 + + Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a "dos" command. + + + + + + + + + cpe:/a:netopia:timbuktu_pro:6.0.1 + + CVE-2002-0135 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + timbuktu-multiple-conn-dos(7935) + + + BUGTRAQ + 20020118 Timbuktu 6.0.1 and Older DoS Advisory + + + BID + 3918 + + Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420). + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + + CVE-2002-0136 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-html-form-dos(7938) + + + BUGTRAQ + 20020115 IE FORM DOS + + + BID + 3892 + + Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript. + + + + + + + + + + cpe:/a:andreas_mueller:cdrdao:1.1.4 + cpe:/a:andreas_mueller:cdrdao:1.1.5 + + CVE-2002-0137 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:34.930-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020112 cdrdao insecure filehandling + + + BID + 3865 + + CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file. + + + + + + + + + + cpe:/a:andreas_mueller:cdrdao:1.1.4 + cpe:/a:andreas_mueller:cdrdao:1.1.5 + + CVE-2002-0138 + 2002-03-25T00:00:00.000-05:00 + 2008-09-05T16:27:16.450-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020115 Re: cdrdao insecure filehandling + + + BUGTRAQ + 20020112 cdrdao insecure filehandling + + CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command. + + + + + + + + + + + + + cpe:/a:pi-soft:spoonftp:1.1 + cpe:/a:pi-soft:spoonftp:1.0 + cpe:/a:pi-soft:spoonftp:0.01.1.0.1 + cpe:/a:pi-soft:spoonftp:1.00.12 + cpe:/a:pi-soft:spoonftp:1.00.13 + + CVE-2002-0139 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:35.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + spoonftp-ftp-bounce(7943) + + + CONFIRM + http://www.pi-soft.com/spoonftp/index.shtml + + + BUGTRAQ + 20020120 Bounce vulnerability in SpoonFTP 1.1.0.1 + + + BID + 3910 + + Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:dnrd:dnrd:2.10 + cpe:/a:dnrd:dnrd:2.3 + cpe:/a:dnrd:dnrd:2.2 + cpe:/a:dnrd:dnrd:2.1 + cpe:/a:dnrd:dnrd:2.0 + cpe:/a:dnrd:dnrd:2.9 + cpe:/a:dnrd:dnrd:2.8 + cpe:/a:dnrd:dnrd:1.0 + cpe:/a:dnrd:dnrd:2.7 + cpe:/a:dnrd:dnrd:1.1 + cpe:/a:dnrd:dnrd:2.6 + cpe:/a:dnrd:dnrd:1.2 + cpe:/a:dnrd:dnrd:1.3 + cpe:/a:dnrd:dnrd:2.5 + cpe:/a:dnrd:dnrd:1.4 + cpe:/a:dnrd:dnrd:2.4 + + CVE-2002-0140 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:35.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + dnrd-dns-dos(7957) + + + BID + 3928 + + Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not handled properly by parse_query, get_objectname, and possibly other functions. + + + + + + + + + cpe:/a:maelstrom:maelstrom_gpl:3.0.1 + + CVE-2002-0141 + 2002-03-25T00:00:00.000-05:00 + 2008-11-04T00:23:09.067-05:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020120 Maelstrom 1.4.3 abartity file overwrite + + + BID + 3911 + + + XF + maelstrom-tmp-symlink(7939) + + Maelstrom GPL 3.0.1 allows local users to overwrite arbitrary files of other Maelstrom users via a symlink attack on the /tmp/f file. + + + + + + + + + cpe:/a:pi3:pi3web:2.0 + + CVE-2002-0142 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:35.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3866 + + + XF + pi3web-long-parameter-bo(7880) + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=505583&group_id=17753&atid=317753 + + + BUGTRAQ + 20020114 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability + + + NTBUGTRAQ + 20020113 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability + + + BUGTRAQ + 20020121 Re: Pi3Web Webserver v2.0 Buffer Overflow Vulnerability + + CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters. + + + + + + + + + + + + + + cpe:/a:enlightenment:imlib:2.1.0.1 + cpe:/a:enlightenment:imlib:2.1.0.3 + cpe:/a:enlightenment:imlib:2.1.0.2 + cpe:/a:enlightenment:imlib:2.0.01.0.0 + cpe:/a:enlightenment:imlib:2.1.0.4 + cpe:/a:michael_jennings:eterm:0.9.1 + + CVE-2002-0143 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T20:00:35.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eterm-home-bo(7896) + + + BUGTRAQ + 20020121 Re: Eterm SGID utmp Buffer Overflow (Local) + + + BUGTRAQ + 20020113 Eterm SGID utmp Buffer Overflow (Local) + + + BID + 3868 + + Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME environment variable. + + + + + + + + + + + cpe:/a:scott_parish:chuid:1.0 + cpe:/a:scott_parish:chuid:1.2 + cpe:/a:scott_parish:chuid:1.1 + + CVE-2002-0144 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:26.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + chuid-unauthorized-ownership-change(7976) + + + BID + 3937 + + + BUGTRAQ + 20020121 security vulnerability in chuid + + Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack. + + + + + + + + + + + cpe:/a:scott_parish:chuid:1.0 + cpe:/a:scott_parish:chuid:1.2 + cpe:/a:scott_parish:chuid:1.1 + + CVE-2002-0145 + 2002-03-25T00:00:00.000-05:00 + 2008-09-10T15:11:26.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + chuid-unauthorized-ownership-change(7976) + + + BID + 3938 + + + BUGTRAQ + 20020121 security vulnerability in chuid + + chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.9.8 + cpe:/a:fetchmail:fetchmail:5.9.4 + cpe:/a:fetchmail:fetchmail:5.9.5 + cpe:/a:fetchmail:fetchmail:5.9.0 + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.8.13 + cpe:/a:fetchmail:fetchmail:5.8.11 + cpe:/a:fetchmail:fetchmail:5.8.17 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.14 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.6 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2002-0146 + 2002-06-25T00:00:00.000-04:00 + 2011-02-15T15:45:44.017-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + REDHAT + RHSA-2002:047 + + + BID + 4788 + + + MANDRAKE + MDKSA-2002:036 + + + XF + fetchmail-imap-msgnum-bo(9133) + + + HP + HPSBTL0205-042 + + + CALDERA + CSSA-2002-027.0 + + fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0147 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:35.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#669779 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4490 + + + OSVDB + 3301 + + + XF + iis-asp-data-transfer-bo(8796) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + + + + + + + + + Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun." + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0148 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:26.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#886699 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4486 + + + OSVDB + 3339 + + + XF + iis-http-error-page-css(8803) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + + + + + + + + + Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0149 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:36.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#721963 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4478 + + + OSVDB + 3320 + + + XF + iis-ssi-safety-check-bo(8798) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + + + + + + + + + Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0150 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:26.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#454091 + + + CERT + CA-2002-09 + + + MS + MS02-018 + + + BID + 4476 + + + OSVDB + 3316 + + + XF + iis-asp-http-header-bo(8797) + + + CISCO + 20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 + + + + + + + + + + + Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + + CVE-2002-0151 + 2002-04-04T00:00:00.000-05:00 + 2008-09-05T16:27:18.480-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + MS + MS02-017 + + + BUGTRAQ + 20020404 NSFOCUS SA2002-02 : Microsoft Windows MUP overlong request kernel overflow + + + BID + 4426 + + + XF + win-mup-bo(8752) + + + + + + + + Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:powerpoint:2001::macos + cpe:/a:microsoft:excel:x::mac_os_x + cpe:/a:microsoft:office:2001:sr1:mac_os + cpe:/a:microsoft:office:v.x::mac + cpe:/a:microsoft:powerpoint:98::macos + cpe:/a:microsoft:outlook_express:5.0::macos + cpe:/a:microsoft:entourage:v._x::macos + cpe:/a:microsoft:excel:2001::mac_os_x + cpe:/a:microsoft:entourage:2001::macos + cpe:/a:microsoft:outlook_express:5.0.1::macos + cpe:/a:microsoft:office:2001::macos + cpe:/a:microsoft:outlook_express:5.0.2::macos + cpe:/a:microsoft:outlook_express:5.0.3::macos + cpe:/a:microsoft:ie:5.1::mac_os + cpe:/a:microsoft:powerpoint:v.x::macos + + CVE-2002-0152 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:36.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-019 + + + BUGTRAQ + 20020416 w00w00 on Microsoft IE/Office for Mac OS + + + BID + 4517 + + + OSVDB + 5357 + + + XF + ms-mac-html-file-bo(8850) + + Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh. + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:4.0:a_mac_os + cpe:/a:microsoft:ie:5.1::mac_os + cpe:/a:microsoft:ie:5.0::macos + cpe:/a:microsoft:ie:3.0::mac_os + cpe:/a:microsoft:ie:4.5::macintosh + cpe:/a:microsoft:ie:3.1::mac_os + cpe:/a:microsoft:ie:4.0::mac_os + cpe:/a:microsoft:ie:4.0.1::mac_os + + CVE-2002-0153 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:36.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-019 + + + XF + ie-macos-file-execution(7969) + + + BID + 3935 + + + BUGTRAQ + 20020122 Macinosh IE file execuion + + + OSVDB + 5356 + + + XF + ie-mac-applescript-execution(8851) + + Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability. + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0154 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T15:11:27.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#627275 + + + CERT + CA-2002-22 + + + MS + MS02-020 + + + BUGTRAQ + 20020312 Many, many, many Sql Server 7 & 2000 Buffer Overflows + + + BUGTRAQ + 20020305 Another Sql Server 7 Buffer Overflow + + + + + Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments. + + + + + + + + + + + + + cpe:/a:microsoft:msn_messenger_service_for_exchange:4.5 + cpe:/a:microsoft:msn_messenger_service_for_exchange:4.6 + cpe:/a:microsoft:msn_chat_control + cpe:/a:microsoft:msn_messenger:4.5 + cpe:/a:microsoft:msn_messenger:4.6 + + CVE-2002-0155 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:36.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-13 + + + MS + MS02-022 + + + BUGTRAQ + 20020508 ADVISORY: MSN Messenger OCX Buffer Overflow + + + BID + 4707 + + + XF + msn-chatcontrol-resdll-bo(9041) + + Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX. + + + + + + + + + cpe:/a:eazel:nautilus:1.0.4 + + CVE-2002-0157 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:19.277-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4373 + + + BUGTRAQ + 20020502 R7-0003: Nautilus Symlink Vulnerability + + + REDHAT + RHSA-2002:064 + + + XF + nautilus-metafile-xml-symlink(8995) + + Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0::sparc + cpe:/o:sun:solaris:8.0::sparc + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.6::sparc + + CVE-2002-0158 + 2002-04-02T00:00:00.000-05:00 + 2008-09-05T16:27:19.433-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BUGTRAQ + 20020402 NSFOCUS SA2002-01: Sun Solaris Xsun "-co" heap overflow + + + VULNWATCH + 20020402 NSFOCUS SA2002-01: Sun Solaris Xsun "-co" heap overflow + + + CONFIRM + http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F108652 + + + XF + solaris-xsun-co-bo(8703) + + + BID + 4408 + + + + + + + + Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument. + + + + + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:2.6 + cpe:/a:cisco:secure_access_control_server:2.6.2 + cpe:/a:cisco:secure_access_control_server:3.0.1 + cpe:/a:cisco:secure_access_control_server:2.6.3 + cpe:/a:cisco:secure_access_control_server:3.0 + cpe:/a:cisco:secure_access_control_server:2.6.4 + + CVE-2002-0159 + 2002-04-22T00:00:00.000-04:00 + 2011-02-10T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CISCO + 20020403 Web Interface Vulnerabilities in Cisco Secure ACS for Windows + + + BUGTRAQ + 20020403 iXsecurity.20020314.csadmin_fmt.a + + + BID + 4416 + + + OSVDB + 2062 + + + XF + ciscosecure-acs-format-string(8742) + + Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002. + + + + + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:2.6 + cpe:/a:cisco:secure_access_control_server:2.6.2 + cpe:/a:cisco:secure_access_control_server:3.0.1 + cpe:/a:cisco:secure_access_control_server:2.6.3 + cpe:/a:cisco:secure_access_control_server:3.0 + cpe:/a:cisco:secure_access_control_server:2.6.4 + + CVE-2002-0160 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:19.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20020403 Web Interface Vulnerabilities in Cisco Secure ACS for Windows + + + BUGTRAQ + 20020403 iXsecurity.20020316.csadmin_dir.a + + + OSVDB + 5352 + + The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002. + + + + + + + + + cpe:/a:logwatch:logwatch:2.5 + + CVE-2002-0162 + 2002-03-27T00:00:00.000-05:00 + 2008-09-10T20:00:37.307-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + logwatch-tmp-race-condition(8652) + + + VULN-DEV + 20020327 Root compromise through LogWatch 2.1.1 + + + BUGTRAQ + 20020327 Root compromise through LogWatch 2.1.1 + + + CONFIRM + http://list.kaybee.org/archives/logwatch-announce/2002-March/000002.html + + + BID + 4374 + + LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory. + + + + + + + + + cpe:/a:squid:squid:2.4_9 + + CVE-2002-0163 + 2002-03-26T00:00:00.000-05:00 + 2008-09-10T15:11:27.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.squid-cache.org/Advisories/SQUID-2002_2.txt + + + BID + 4363 + + + MANDRAKE + MDKSA-2002:027 + + + XF + squid-dns-reply-dos(8628) + + + REDHAT + RHSA-2002:051 + + + BUGTRAQ + 20020326 updated squid advisory + + + FREEBSD + FreeBSD-SA-02:19 + + + CALDERA + CSSA-2002-017.1 + + Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses. + + + + + + + + + + + + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/a:caldera:openlinux_server:3.1 + cpe:/a:caldera:openlinux_workstation:3.1.1 + cpe:/a:caldera:openlinux_server:3.1.1 + + CVE-2002-0164 + 2002-03-15T00:00:00.000-05:00 + 2010-05-25T00:11:27.157-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + xfree86-mitshm-memory-access(8706) + + + BID + 4396 + + + REDHAT + RHSA-2003:067 + + + CALDERA + CSSA-2002-009.0 + + + DEBIAN + DSA-380 + + + SUNALERT + 1017429 + + + SUNALERT + 228529 + + + CALDERA + CSSA-2002-SCO.14 + + + SGI + 20021001-01-P + + + BUGTRAQ + 20021024 GLSA: xfree + + + CONECTIVA + CLSA-2002:529 + + Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges. + + + + + + + + + cpe:/a:logwatch:logwatch:2.5 + + CVE-2002-0165 + 2002-04-03T00:00:00.000-05:00 + 2008-09-05T16:27:20.340-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + logwatch-tmp-race-condition(8652) + + + BUGTRAQ + 20020403 LogWatch 2.5 still vulnerable + + + CONFIRM + http://list.kaybee.org/archives/logwatch-announce/2002-March/000003.html + + LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:stephen_turner:analog:5.1a + cpe:/a:stephen_turner:analog:5.03 + cpe:/a:stephen_turner:analog:4.1 + cpe:/a:stephen_turner:analog:5.02 + cpe:/a:stephen_turner:analog:5.01 + cpe:/a:stephen_turner:analog:3.90_beta2 + cpe:/a:stephen_turner:analog:4.11 + cpe:/a:stephen_turner:analog:5.0 + cpe:/a:stephen_turner:analog:3.90_beta1 + cpe:/a:stephen_turner:analog:4.01 + cpe:/a:stephen_turner:analog:4.90_beta3 + cpe:/a:stephen_turner:analog:4.90_beta2 + cpe:/a:stephen_turner:analog:5.2 + cpe:/a:stephen_turner:analog:4.90_beta4 + cpe:/a:stephen_turner:analog:4.02 + cpe:/a:stephen_turner:analog:4.15 + cpe:/a:stephen_turner:analog:4.03 + cpe:/a:stephen_turner:analog:4.16 + cpe:/a:stephen_turner:analog:4.91_beta1 + cpe:/a:stephen_turner:analog:4.04 + cpe:/a:stephen_turner:analog:4.14 + + CVE-2002-0166 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:37.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-125 + + + BID + 4389 + + + REDHAT + RHSA-2002:059 + + + OSVDB + 2059 + + + XF + analog-logfile-css(8656) + + + FREEBSD + FreeBSD-SN-02:02 + + Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display. + + + + + + + + + + + + + + + + + + + + + cpe:/a:enlightenment:imlib:1.9 + cpe:/a:enlightenment:imlib:1.9.3 + cpe:/a:enlightenment:imlib:1.9.4 + cpe:/a:enlightenment:imlib:1.9.12 + cpe:/a:enlightenment:imlib:1.9.1 + cpe:/a:enlightenment:imlib:1.9.2 + cpe:/a:enlightenment:imlib:1.9.6 + cpe:/a:enlightenment:imlib:1.9.11 + cpe:/a:enlightenment:imlib:1.9.5 + cpe:/a:enlightenment:imlib:1.9.10 + cpe:/a:enlightenment:imlib:1.9.8 + cpe:/a:enlightenment:imlib:1.9.7 + cpe:/a:enlightenment:imlib:1.9.9 + + CVE-2002-0167 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:37.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:048 + + + BID + 4339 + + + SUSE + SuSE-SA:2002:015 + + + MANDRAKE + MDKSA-2002:029 + + + CONECTIVA + CLA-2002:470 + + + CALDERA + CSSA-2002-019.0 + + Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weaknesses of NetPBM. + + + + + + + + + + + + + + + + + + + + + cpe:/a:enlightenment:imlib:1.9 + cpe:/a:enlightenment:imlib:1.9.3 + cpe:/a:enlightenment:imlib:1.9.4 + cpe:/a:enlightenment:imlib:1.9.12 + cpe:/a:enlightenment:imlib:1.9.1 + cpe:/a:enlightenment:imlib:1.9.2 + cpe:/a:enlightenment:imlib:1.9.6 + cpe:/a:enlightenment:imlib:1.9.11 + cpe:/a:enlightenment:imlib:1.9.5 + cpe:/a:enlightenment:imlib:1.9.10 + cpe:/a:enlightenment:imlib:1.9.8 + cpe:/a:enlightenment:imlib:1.9.7 + cpe:/a:enlightenment:imlib:1.9.9 + + CVE-2002-0168 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:37.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:048 + + + BID + 4336 + + + SUSE + SuSE-SA:2002:015 + + + MANDRAKE + MDKSA-2002:029 + + + CONECTIVA + CLA-2002:470 + + + CALDERA + CSSA-2002-019.0 + + Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a heap corruption. + + + + + + + + + + + cpe:/a:redhat:docbook_utils:0.6.9-2 + cpe:/a:redhat:docbook_stylesheets:1.54.13 + cpe:/a:redhat:docbook_utils:0.6.13 + + CVE-2002-0169 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:37.993-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:062 + + + BID + 4654 + + + OSVDB + 5349 + + + XF + linux-docbook-stylesheet-insecure(8983) + + + HP + HPSBTL0205-038 + + The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:zope:zope:2.4.1 + cpe:/a:zope:zope:2.5.1b1 + cpe:/a:zope:zope:2.4.0 + cpe:/a:zope:zope:2.2.1 + cpe:/a:zope:zope:2.2.0 + cpe:/a:zope:zope:2.2.3 + cpe:/a:zope:zope:2.2.2 + cpe:/a:zope:zope:2.3.3 + cpe:/a:zope:zope:2.3.1 + cpe:/a:zope:zope:2.3.2 + cpe:/a:zope:zope:2.3.0 + cpe:/a:zope:zope:2.2.4 + cpe:/a:zope:zope:2.2.5 + cpe:/a:zope:zope:2.4.2 + cpe:/a:zope:zope:2.4.3 + cpe:/a:zope:zope:2.5.0 + cpe:/a:zope:zope:2.4.4b1 + + CVE-2002-0170 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:38.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.zope.org/Products/Zope/hotfixes/ + + + BID + 4229 + + + REDHAT + RHSA-2002:060 + + + OSVDB + 5350 + + + XF + zope-proxy-role-privileges(8334) + + + BUGTRAQ + 20020301 [matt@zope.com: [Zope-Annce] Zope Hotfix 2002-03-01 (Ownership Roles Enforcement)] + + Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration. + + + + + + + + + cpe:/a:sgi:irisconsole:2.0 + + CVE-2002-0171 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:38.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#498707 + + + SGI + 20020406-01-P + + + BID + 4588 + + + OSVDB + 5351 + + + XF + irix-irisconsole-icadmin-access(8933) + + IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges. + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0172 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:38.227-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#770891 + + + SGI + 20020408-01-I + + + BID + 4648 + + + OSVDB + 4695 + + + XF + irix-ipfilter-dos(8960) + + /dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:5.1.1 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.2f + cpe:/o:sgi:irix:6.5.8m + cpe:/o:sgi:irix:6.5.4m + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.6m + cpe:/o:sgi:irix:5.0 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.8f + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.4f + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.6f + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sgi:irix:6.5.10m + cpe:/o:sgi:irix:6.5.9m + cpe:/o:sgi:irix:6.5.5m + cpe:/o:sgi:irix:5.0.1 + cpe:/o:sgi:irix:6.5.7m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.9f + cpe:/o:sgi:irix:6.5.5f + cpe:/o:sgi:irix:6.5.7f + cpe:/o:sgi:irix:6.5.3f + + CVE-2002-0173 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:38.367-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20020409-01-I + + + BID + 4644 + + + OSVDB + 5359 + + + XF + irix-cpr-bo(8959) + + Buffer overflow in cpr for the eoe.sw.cpr SGI Checkpoint-Restart Software package on SGI IRIX 6.5.10 and earlier may allow local users to gain root privileges. + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0174 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:38.447-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20020501-01-I + + + BID + 4655 + + + XF + irix-nsd-symlink(8981) + + nsd on SGI IRIX before 6.5.11 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the nsd.dump file. + + + + + + + + + + + + + + + cpe:/a:avaya:libsafe:1.3.4 + cpe:/a:avaya:libsafe:2.0.5 + cpe:/a:avaya:libsafe:1.3.8 + cpe:/a:avaya:libsafe:2.0.9 + cpe:/a:avaya:libsafe:2.0.10 + cpe:/a:avaya:libsafe:2.0.11 + cpe:/a:avaya:libsafe:2.0.2 + + CVE-2002-0175 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:38.540-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MANDRAKE + MDKSA-2002:026 + + + BUGTRAQ + 20020320 Bypassing libsafe format string protection + + + BID + 4326 + + + XF + libsafe-flagchar-protection-bypass(8593) + + + VULNWATCH + 20020320 [VulnWatch] Bypassing libsafe format string protection + + libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe. + + + + + + + + + + + + + + + cpe:/a:avaya:libsafe:1.3.4 + cpe:/a:avaya:libsafe:2.0.5 + cpe:/a:avaya:libsafe:1.3.8 + cpe:/a:avaya:libsafe:2.0.9 + cpe:/a:avaya:libsafe:2.0.10 + cpe:/a:avaya:libsafe:2.0.11 + cpe:/a:avaya:libsafe:2.0.2 + + CVE-2002-0176 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:38.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MANDRAKE + MDKSA-2002:026 + + + BUGTRAQ + 20020320 Bypassing libsafe format string protection + + + BID + 4327 + + + XF + libsafe-argnum-protection-bypass(8594) + + + VULNWATCH + 20020320 [VulnWatch] Bypassing libsafe format string protection + + The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe. + + + + + + + + + + + + cpe:/a:icecast:icecast:1.3.8_beta2 + cpe:/a:icecast:icecast:1.3.7 + cpe:/a:icecast:icecast:1.3.10 + cpe:/a:icecast:icecast:1.3.11 + + CVE-2002-0177 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T20:00:38.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#596387 + + + CONFIRM + http://www.xiph.org/archives/icecast/2616.html + + + BUGTRAQ + 20020404 Full analysis of multiple remotely exploitable bugs in Icecast 1.3.11 + + + BID + 4415 + + + BUGTRAQ + 20020403 Icecast temp patch (OR: Patches? We DO need stinkin' patches!!@$!) + + + BUGTRAQ + 20020402 icecast 1.3.11 remote shell/root exploit - #temp + + Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. + + + + + + + + + cpe:/a:gnu:sharutils:4.2 + + CVE-2002-0178 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:38.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#336083 + + + REDHAT + RHSA-2002:065 + + + BID + 4742 + + + REDHAT + RHSA-2003:180 + + + OSVDB + 8274 + + + MANDRAKE + MDKSA-2002:052 + + + XF + sharutils-uudecode-symlink(9075) + + + MISC + http://www.aerasec.de/security/index.html?id=ae-200204-033&lang=en + + + HP + HPSBTL0205-040 + + + BUGTRAQ + 20021030 GLSA: sharutils + + + CALDERA + CSSA-2002-040.0 + + uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands. + + + + + + + + + cpe:/a:xpilot:xpilot:4.5.0 + + CVE-2002-0179 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:27:22.683-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-127 + + + BID + 4534 + + + XF + xpilot-server-bo(8852) + + Buffer overflow in xpilot-server for XPilot 4.5.0 and earlier allows remote attackers to execute arbitrary code. + + + + + + + + + + cpe:/a:bradford_barrett:webalizer:2.0.1.9 + cpe:/a:bradford_barrett:webalizer:2.0.1.6 + + CVE-2002-0180 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:29.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#582923 + + + XF + webalizer-reverse-dns-bo(8837) + + + BID + 4504 + + + CONFIRM + http://www.mrunix.net/webalizer/news.html + + + BUGTRAQ + 20020415 Remote buffer overflow in Webalizer + + Buffer overflow in Webalizer 2.01-06, when configured to use reverse DNS lookups, allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname. + + + + + + + + + + cpe:/a:horde:imp:2.2.8 + cpe:/a:horde:horde:1.2.7 + + CVE-2002-0181 + 2002-04-22T00:00:00.000-04:00 + 2008-09-10T15:11:29.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-126 + + + BUGTRAQ + 20020406 IMP 2.2.8 (SECURITY) released + + + MISC + http://bugs.horde.org/show_bug.cgi?id=916 + + + BID + 4444 + + + OSVDB + 5345 + + + XF + imp-status-php3-css(8769) + + + CALDERA + CSSA-2002-016.1 + + + CONECTIVA + CLA-2001:473 + + Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:todd_miller:sudo:1.6.4p1 + cpe:/a:todd_miller:sudo:1.6.4p2 + cpe:/a:todd_miller:sudo:1.6 + cpe:/a:todd_miller:sudo:1.5.9 + cpe:/a:todd_miller:sudo:1.6.3p6 + cpe:/a:todd_miller:sudo:1.6.3p7 + cpe:/a:todd_miller:sudo:1.6.3p4 + cpe:/a:todd_miller:sudo:1.6.3p5 + cpe:/a:todd_miller:sudo:1.6.3p2 + cpe:/a:todd_miller:sudo:1.6.3p3 + cpe:/a:todd_miller:sudo:1.6.3p1 + cpe:/a:todd_miller:sudo:1.6.5p2 + cpe:/a:todd_miller:sudo:1.6.5p1 + cpe:/a:todd_miller:sudo:1.6.2 + cpe:/a:todd_miller:sudo:1.6.1 + cpe:/a:todd_miller:sudo:1.6.4 + cpe:/a:todd_miller:sudo:1.6.3 + cpe:/a:todd_miller:sudo:1.6.5 + + CVE-2002-0184 + 2002-05-16T00:00:00.000-04:00 + 2011-03-07T21:07:53.797-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#820083 + + + ENGARDE + ESA-20020429-010 + + + BUGTRAQ + 20020425 [Global InterSec 2002041701] Sudo Password Prompt + + + BUGTRAQ + 20020429 TSLSA-2002-0046 - sudo + + + BID + 4593 + + + REDHAT + RHSA-2002:072 + + + REDHAT + RHSA-2002:071 + + + SUSE + SuSE-SA:2002:014 + + + MANDRAKE + MDKSA-2002:028 + + + XF + sudo-password-expansion-overflow(8936) + + + DEBIAN + DSA-128 + + + BUGTRAQ + 20020425 [slackware-security] sudo upgrade fixes a potential vulnerability + + + BUGTRAQ + 20020425 Sudo version 1.6.6 now available (fwd) + + + CONECTIVA + CLA-2002:475 + + Heap-based buffer overflow in sudo before 1.6.6 may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded. + + + + + + + + + cpe:/a:apache:mod_python:2.7.6 + + CVE-2002-0185 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:23.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.modpython.org/pipermail/mod_python/2002-April/002003.html + + + MISC + http://www.modpython.org/pipermail/mod_python/2002-April/001991.html + + + BID + 4656 + + + REDHAT + RHSA-2002:070 + + + XF + modpython-imported-module-access(8997) + + + CONECTIVA + CLA-2002:477 + + mod_python version 2.7.6 and earlier allows a module indirectly imported by a published module to then be accessed via the publisher, which allows remote attackers to call possibly dangerous functions from the imported module. + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0186 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T20:00:40.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#811371 + + + MS + MS02-030 + + + VULNWATCH + 20020613 [VulnWatch] wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting + + + BID + 5004 + + + OSVDB + 5347 + + + XF + mssql-sqlxml-isapi-bo(9328) + + + BUGTRAQ + 20020613 wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting + + + + + + + + Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension." + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0187 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:11:31.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-030 + + + VULNWATCH + 20020613 [VulnWatch] wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting + + + BUGTRAQ + 20020613 wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting + + Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag." + + + + + + + + + + + + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0188 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:23.760-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-023 + + + MISC + http://www.lac.co.jp/security/english/snsadv_e/48_e.html + + + XF + ie-content-disposition-variant2(9086) + + + BUGTRAQ + 20020516 [SNS Advisory No.48] Microsoft Internet Explorer Still Download And Execute ANY Program Automatically + + Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability. + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0189 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T15:11:31.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-023 + + + + + Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0190 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:41.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#242891 + + + MS + MS02-023 + + + BID + 4753 + + + XF + ie-netbios-incorrect-security-zone(9084) + + + + + Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0191 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:41.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-023 + + + XF + ie-css-read-files (8740) + + + BID + 4411 + + + BUGTRAQ + 20020402 Reading portions of local files in IE, depending on structure (GM#004-IE) + + Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability. + + + CVE-2002-0192 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T15:11:32.103-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0193, CVE-2002-1564. Reason: This candidate was published with a description that identified a different vulnerability than what was identified in the original authoritative reference. Notes: Consult CVE-2002-0193 or CVE-2002-1564 to find the identifier for the proper issue. + + + + + + + + + + + + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0193 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:41.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + MS + MS02-023 + + + XF + ie-content-disposition-variant(9085) + + + BID + 4752 + + + + + + + + Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability. + + + + + + + + + cpe:/a:acd_incorporated:cwpapi:1.1 + + CVE-2002-0196 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:41.383-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cwpapi-getrelativepath-view-files(7981) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=144966 + + + BID + 3924 + + + BUGTRAQ + 20020122 (Repost) CwpApi : GetRelativePath() returns invalid paths (security advisory) + + GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root. + + + + + + + + + cpe:/a:psychoid:psybnc:2.3 + + CVE-2002-0197 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:24.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3931 + + + XF + psybnc-view-encrypted-messages(7985) + + + BUGTRAQ + 20020122 psyBNC2.3 Beta - encrypted text spoofable in others irc terminal + + + BUGTRAQ + 20020122 psyBNC 2.3 Beta - encrypted text "spoofable" in others' irc terminals + + psyBNC 2.3 beta and earlier allows remote attackers to spoof encrypted, trusted messages by sending lines that begin with the "[B]" sequence, which makes the message appear legitimate. + + + + + + + + + + + + + + + + cpe:/a:paul_l_daniels:ripmime:1.2.5 + cpe:/a:paul_l_daniels:ripmime:1.2.4 + cpe:/a:paul_l_daniels:ripmime:1.2.3 + cpe:/a:paul_l_daniels:inflex:1.0.10 + cpe:/a:paul_l_daniels:ripmime:1.2.2 + cpe:/a:paul_l_daniels:ripmime:1.2.6 + cpe:/a:paul_l_daniels:ripmime:1.2.1 + cpe:/a:paul_l_daniels:ripmime:1.2.0 + + CVE-2002-0198 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:41.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ripmime-long-filename-bo(7983) + + + CONFIRM + http://pldaniels.org/ripmime/CHANGELOG + + + BUGTRAQ + 20020122 pldaniels - ripMime 1.2.6 and lower? + + + BID + 3941 + + Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename. + + + + + + + + + cpe:/a:nullsoft:shoutcast_server:1.8.3 + + CVE-2002-0199 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:41.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020119 Shoutcast server 1.8.3 win32 + + + BID + 3934 + + Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes. + + + + + + + + + cpe:/a:cyberstop:cyberstop_web_server + + CVE-2002-0200 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:41.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cyberstop-device-name-dos(7959) + + + BUGTRAQ + 20020122 CyberStop-Server-DoS-remote-attacks + + + BID + 3929 + + Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name. + + + + + + + + + cpe:/a:cyberstop:cyberstop_web_server + + CVE-2002-0201 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cyberstop-long-request-dos(7960) + + + BUGTRAQ + 20020122 CyberStop-Server-DoS-remote-attacks + + + BID + 3930 + + Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow. + + + + + + + + + cpe:/a:paintbbs:paintbbs:1.2 + + CVE-2002-0202 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.227-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + paintbbs-insecure-permissions(7982) + + + BUGTRAQ + 20020123 Vulnerabilty in PaintBBS v1.2 + + + BID + 3948 + + PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable /oekaki/ folder. + + + + + + + + + + + cpe:/a:tarantella:tarantella_enterprise:3.20 + cpe:/a:tarantella:tarantella_enterprise:3.10 + cpe:/a:tarantella:tarantella_enterprise:3.0 + + CVE-2002-0203 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:25.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.tarantella.com/security/bulletin-03.html + + + BUGTRAQ + 20020124 ISSTW Security Advisory Tarantella Enterprise 3.11.903 Directory Index Disclosure Vulnerability + + ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter. + + + + + + + + + cpe:/a:gnu:chess:5.02 + + CVE-2002-0204 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + gnu-chess-bo(7991) + + + BUGTRAQ + 20020124 gnuchess buffer overflow vulnerabilty + + + BID + 3949 + + Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command. + + + + + + + + + + + + + + cpe:/a:plumtree:plumtree_corporate_portal:4.0i_sp1 + cpe:/a:plumtree:plumtree_corporate_portal:3.5 + cpe:/a:plumtree:plumtree_corporate_portal:4.0 + cpe:/a:plumtree:plumtree_corporate_portal:4.0i + cpe:/a:plumtree:plumtree_corporate_portal:4.0_sp1 + cpe:/a:plumtree:plumtree_corporate_portal:4.5 + + CVE-2002-0205 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + plumtree-css-error(7817) + + + VULN-DEV + 20020104 Cross-Site Scripting in PlumTree? + + + BID + 3799 + + + BUGTRAQ + 20020124 Plumtree Corporate Portal Cross-Site Scripting (Patch Available) + + Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter. + + + + + + + + + + + + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.0 + cpe:/a:francisco_burzi:php-nuke:4.3 + cpe:/a:francisco_burzi:php-nuke:4.4 + cpe:/a:francisco_burzi:php-nuke:1.0 + cpe:/a:francisco_burzi:php-nuke:2.5 + cpe:/a:francisco_burzi:php-nuke:5.0.1 + cpe:/a:francisco_burzi:php-nuke:5.3.1 + cpe:/a:francisco_burzi:php-nuke:4.4.1a + cpe:/a:francisco_burzi:php-nuke:3.0 + cpe:/a:francisco_burzi:php-nuke:5.2 + cpe:/a:francisco_burzi:php-nuke:5.1 + cpe:/a:francisco_burzi:php-nuke:5.0 + cpe:/a:francisco_burzi:php-nuke:5.2a + + CVE-2002-0206 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#221683 + + + XF + phpnuke-index-command-execution(7914) + + + BUGTRAQ + 20020116 PHP-Nuke allows Command Execution & Much more + + + BID + 3889 + + index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter. + + + + + + + + + + + + + + + + + + + cpe:/a:realnetworks:realplayer_intranet:7.0 + cpe:/a:realnetworks:realplayer:8.0::mac_os + cpe:/a:realnetworks:realplayer::g2 + cpe:/a:realnetworks:realplayer:8.0::unix + cpe:/a:realnetworks:realplayer:7.0::mac_os + cpe:/a:realnetworks:realplayer:7.0::win32 + cpe:/a:realnetworks:realplayer:7.0::unix + cpe:/a:realnetworks:realone_player + cpe:/a:realnetworks:realplayer_intranet:8.0 + cpe:/a:realnetworks:realplayer:8.0::win32 + cpe:/a:realnetworks:realone_player:2.2::alpha%2c_linux + + CVE-2002-0207 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + realplayer-file-header-bo(7839) + + + MISC + http://sentinelchicken.com/advisories/realplayer/ + + + VULN-DEV + 20020105 RealPlayer Buffer Problem + + + BID + 3809 + + + BUGTRAQ + 20020124 RealPlayer Buffer Overflow [Sentinel Chicken Networks Security Advisory #01] + + + BUGTRAQ + 20020124 Potential RealPlayer 8 Vulnerability + + Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header. + + + + + + + + + cpe:/a:pgp_security:pgpfire:7.1 + + CVE-2002-0208 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:42.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + pgpfire-icmp-fingerprint(8008) + + + BUGTRAQ + 20020125 Identifying PGP Corporate Desktop 7.1 with PGPfire Personal Desktop Firewall installed (no need to be enabled) on Microsoft Windows Based OSs + + + BID + 3961 + + PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire. + + + + + + + + + cpe:/h:nortel:alteon_acedirector:9.0 + + CVE-2002-0209 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + acedirector-http-reveal-ip(8010) + + + BUGTRAQ + 20020125 Alteon ACEdirector signature/security bug + + + BID + 3964 + + + BUGTRAQ + 20020312 Re: Alteon ACEdirector signature/security bug + + Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send packets from the server without changing the address to the virtual IP address. + + + + + + + + + cpe:/a:tolis_group:bru:17.0 + + CVE-2002-0210 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.133-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + bru-tmp-file-symlink(8003) + + + BUGTRAQ + 20020126 bru backup program + + + BID + 3970 + + setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file. + + + + + + + + + + + + + cpe:/a:tarantella:tarantella_enterprise:3.3.20 + cpe:/a:tarantella:tarantella_enterprise:3.3.0.1 + cpe:/a:tarantella:tarantella_enterprise:3.3.10 + cpe:/a:tarantella:tarantella_enterprise:3.3.11 + cpe:/a:tarantella:tarantella_enterprise:3.3.0 + + CVE-2002-0211 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.210-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.tarantella.com/security/bulletin-04.html + + + XF + tarantella-gunzip-tmp-race(7996) + + + BUGTRAQ + 20020404 Exploit for Tarantella Enterprise 3 installation (BID 3966) + + + BUGTRAQ + 20020126 Vulnerability report for Tarantella Enterprise 3. + + + BID + 3966 + + Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed. + + + + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4b + cpe:/a:hosting_controller:hosting_controller:1.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + cpe:/a:hosting_controller:hosting_controller:1.3 + + CVE-2002-0212 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hosting-controller-brute-force(8006) + + + BUGTRAQ + 20020126 [ARL02-A01] Vulnerability in Hosting Controller + + + MISC + http://hostingcontroller.com/English/patches/ForAll/index.html + + + BID + 3971 + + The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/a:xinet:k-ashare:11.01 + cpe:/o:sgi:irix:6.5.15 + + CVE-2002-0213 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.413-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kashare-xkas-icon-symlink(8002) + + + BUGTRAQ + 20020128 [ Hackerslab bug_paper ] Xkas application vulnerability + + + BID + 3969 + + + SGI + 20020604-01-I + + xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory. + + + + + + + + + + cpe:/o:intel:intel_pro_wireless_2011b_lan_usb_device_driver:1.5.16.0 + cpe:/o:intel:intel_pro_wireless_2011b_lan_usb_device_driver:1.5.18.0 + + CVE-2002-0214 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.493-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + intel-wlan-wep-plaintext(8015) + + + BUGTRAQ + 20020128 Intel WLAN Driver storing 128bit WEP-Key in plain text! + + + BID + 3968 + + Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:steve_kneizys:agora.cgi:3.3i + cpe:/a:steve_kneizys:agora.cgi:3.3j + cpe:/a:steve_kneizys:agora.cgi:3.3d + cpe:/a:steve_kneizys:agora.cgi:4.0 + cpe:/a:steve_kneizys:agora.cgi:3.3e + cpe:/a:steve_kneizys:agora.cgi:3.3f + cpe:/a:steve_kneizys:agora.cgi:3.3a + cpe:/a:steve_kneizys:agora.cgi:3.3b + cpe:/a:steve_kneizys:agora.cgi:3.3c + cpe:/a:steve_kneizys:agora.cgi:3.2 + cpe:/a:steve_kneizys:agora.cgi:3.2r + cpe:/a:steve_kneizys:agora.cgi:3.2q + cpe:/a:steve_kneizys:agora.cgi:3.2p + cpe:/a:steve_kneizys:agora.cgi:3.2ja + cpe:/a:steve_kneizys:agora.cgi:4.0b + cpe:/a:steve_kneizys:agora.cgi:3.2i + cpe:/a:steve_kneizys:agora.cgi:4.0c + cpe:/a:steve_kneizys:agora.cgi:3.2j + cpe:/a:steve_kneizys:agora.cgi:4.0d + cpe:/a:steve_kneizys:agora.cgi:3.2g + cpe:/a:steve_kneizys:agora.cgi:4.0e + cpe:/a:steve_kneizys:agora.cgi:3.2h + cpe:/a:steve_kneizys:agora.cgi:3.2m + cpe:/a:steve_kneizys:agora.cgi:3.2n + cpe:/a:steve_kneizys:agora.cgi:3.2k + cpe:/a:steve_kneizys:agora.cgi:4.0a + cpe:/a:steve_kneizys:agora.cgi:3.2l + cpe:/a:steve_kneizys:agora.cgi:3.2a + cpe:/a:steve_kneizys:agora.cgi:3.2b + cpe:/a:steve_kneizys:agora.cgi:3.2e + cpe:/a:steve_kneizys:agora.cgi:3.2f + cpe:/a:steve_kneizys:agora.cgi:3.2c + cpe:/a:steve_kneizys:agora.cgi:3.2d + + CVE-2002-0215 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + agora-cgi-revel-path(8011) + + + BUGTRAQ + 20020128 [SUPERPETZ ADVISORY #001 - agora.cgi Secret Path Disclosure Vulnerability] + + + BID + 3976 + + Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message. + + + + + + + + + cpe:/a:xoops:xoops:1.0_rc1 + + CVE-2002-0216 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xoops-userinfo-information-disclosure(8028) + + + BUGTRAQ + 20020129 Xoops SQL fragment disclosure and SQL injection vulnerability + + + BID + 3977 + + userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter. + + + + + + + + + cpe:/a:xoops:xoops:1.0_rc1 + + CVE-2002-0217 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + xoops-pmlite-image-css(8030) + + + XF + xoops-private-message-css(8025) + + + BUGTRAQ + 20020129 Xoops Private Message System Script injection + + + BID + 3981 + + + BID + 3978 + + Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php. + + + + + + + + + + + + cpe:/a:sas:sas_integration_technologies:8.1 + cpe:/a:sas:sas_integration_technologies:8.0 + cpe:/a:sas:sas_base:8.1 + cpe:/a:sas:sas_base:8.0 + + CVE-2002-0218 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.853-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.sas.com/service/techsup/unotes/SN/004/004201.html + + + XF + sas-sastcpd-spawner-format-string(8018) + + + VULNWATCH + 20020129 sastcpd Buffer Overflow and Format String Vulnerabilities + + + BID + 3980 + + Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument. + + + + + + + + + + + + cpe:/a:sas:sas_integration_technologies:8.1 + cpe:/a:sas:sas_integration_technologies:8.0 + cpe:/a:sas:sas_base:8.1 + cpe:/a:sas:sas_base:8.0 + + CVE-2002-0219 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:43.930-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.sas.com/service/techsup/unotes/SN/004/004201.html + + + XF + sas-sastcpd-spawner-bo(8017) + + + VULNWATCH + 20020129 sastcpd Buffer Overflow and Format String Vulnerabilities + + + BID + 3979 + + Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument. + + + + + + + + + cpe:/a:phpsmssend:phpsmssend:1.0 + + CVE-2002-0220 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + phpsmssend-command-execution(8019) + + + BID + 3982 + + phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters. + + + + + + + + + cpe:/a:etype:eserv:2.97 + + CVE-2002-0221 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + eserv-pasv-dos(8020) + + + BUGTRAQ + 20020129 Vulnerabilities in EServ 2.97 + + + BID + 3983 + + Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV. + + + + + + + + + cpe:/a:etype:eserv:2.97 + + CVE-2002-0222 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + eserv-ftp-bounce(8021) + + + BUGTRAQ + 20020129 Vulnerabilities in EServ 2.97 + + + BID + 3986 + + Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command. + + + + + + + + + + + + + cpe:/a:wired_community_software:wwwthreads:5.0.6 + cpe:/a:wired_community_software:wwwthreads:5.0 + cpe:/a:infopop:ultimate_bulletin_board:5.4 + cpe:/a:wired_community_software:wwwthreads:5.0.9 + cpe:/a:wired_community_software:wwwthreads:5.0.8 + + CVE-2002-0223 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ubbthreads-file-upload(8022) + + + BUGTRAQ + 20020130 [ WWWThreads, UBBThreads ] Security Hole in upload system + + + BID + 3993 + + Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/a:microsoft:sql_server:2000 + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:sql_server:7.0 + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:6.5 + + CVE-2002-0224 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4006 + + + XF + msdtc-default-port-dos(8046) + + + BUGTRAQ + 20020419 KPMG-2002015: Microsoft Distributed Transaction Coordinator DoS + + + BUGTRAQ + 20020131 msdtc on 3372 + + The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input. + + + + + + + + + cpe:/a:cisco:tacacs%2b:f4.0.4alpha + + CVE-2002-0225 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:29.183-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4003 + + + XF + tacplus-insecure-accounting-files(8061) + + + BUGTRAQ + 20020130 tac_plus version F4.0.4.alpha on at least Solaris 8 sparc + + tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files. + + + + + + + + + + + + cpe:/a:dcscripts:dcforum:6.21 + cpe:/a:dcscripts:dcforum:5.0 + cpe:/a:dcscripts:dcforum:2000 + cpe:/a:dcscripts:dcforum:6.0 + + CVE-2002-0226 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:29.323-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4014 + + + XF + dcforum-cgi-recover-passwords(8044) + + + BUGTRAQ + 20020201 Vulnerability in all versions of DCForum from dcscripts.com + + + CONFIRM + http://www.dcscripts.com/bugtrac/DCForumID7/3.html + + + OSVDB + 3866 + + + OSVDB + 2038 + + retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user. + + + + + + + + + + + + + + cpe:/o:kde:kde:2.1.2 + cpe:/a:kicq:kicq:2.0.0b1 + + CVE-2002-0227 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kicq-telnet-dos(8064) + + + BUGTRAQ + 20020201 KICQ 2.0.0b1 can be remotely crashed + + + BID + 4018 + + KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. + + + + + + + + + + + + + cpe:/a:microsoft:msn_messenger:3.0 + cpe:/a:microsoft:msn_messenger:4.0 + cpe:/a:microsoft:msn_messenger:4.5 + cpe:/a:microsoft:msn_messenger:2.2 + cpe:/a:microsoft:msn_messenger:4.6 + + CVE-2002-0228 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too) + + + XF + msn-messenger-reveal-information(8084) + + + BID + 4028 + + Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:3.0 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:3.0.16 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2002-0229 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:44.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + php-mysql-safemode-bypass(8105) + + + BUGTRAQ + 20020203 PHP Safe Mode Filesystem Circumvention Problem + + + BID + 4026 + + + NTBUGTRAQ + 20020206 DW020203-PHP clarification + + + NTBUGTRAQ + 20020205 Re: PHP Safe Mode Filesystem Circumvention Problem + + + NTBUGTRAQ + 20020203 PHP Safe Mode Filesystem Circumvention Problem + + + BUGTRAQ + 20020206 DW020203-PHP clarification + + Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements. + + + + + + + + + cpe:/a:faq-o-matic:faq-o-matic:2.712 + + CVE-2002-0230 + 2002-05-16T00:00:00.000-04:00 + 2008-09-05T16:27:29.980-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-109 + + + CONFIRM + http://sourceforge.net/mailarchive/forum.php?thread_id=464940&forum_id=6367 + + + BUGTRAQ + 20020205 Faq-O-Matic Cross-Site Scripting + + + BUGTRAQ + 20020204 [SUPERPETZ ADVISORY #002- Faq-O-Matic Cross-Site Scripting Vulnerability] + + Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc:2.3a + cpe:/a:khaled_mardam-bey:mirc:2.5a + cpe:/a:khaled_mardam-bey:mirc:2.1a + cpe:/a:khaled_mardam-bey:mirc:2.8c + cpe:/a:khaled_mardam-bey:mirc:5.91 + cpe:/a:khaled_mardam-bey:mirc:5.1 + cpe:/a:khaled_mardam-bey:mirc:5.4 + cpe:/a:khaled_mardam-bey:mirc:5.3 + cpe:/a:khaled_mardam-bey:mirc:5.6 + cpe:/a:khaled_mardam-bey:mirc:5.5 + cpe:/a:khaled_mardam-bey:mirc:5.8 + cpe:/a:khaled_mardam-bey:mirc:2.4 + cpe:/a:khaled_mardam-bey:mirc:5.7 + cpe:/a:khaled_mardam-bey:mirc:3.5 + cpe:/a:khaled_mardam-bey:mirc:4.7 + cpe:/a:khaled_mardam-bey:mirc:5.9 + cpe:/a:khaled_mardam-bey:mirc:3.6 + cpe:/a:khaled_mardam-bey:mirc:4.6 + cpe:/a:khaled_mardam-bey:mirc:3.3 + cpe:/a:khaled_mardam-bey:mirc:3.4 + cpe:/a:khaled_mardam-bey:mirc:3.9 + cpe:/a:khaled_mardam-bey:mirc:3.7 + cpe:/a:khaled_mardam-bey:mirc:4.5 + cpe:/a:khaled_mardam-bey:mirc:3.8 + cpe:/a:khaled_mardam-bey:mirc:5.0 + cpe:/a:khaled_mardam-bey:mirc:2.4a + cpe:/a:khaled_mardam-bey:mirc:4.0 + cpe:/a:khaled_mardam-bey:mirc:4.1 + cpe:/a:khaled_mardam-bey:mirc:2.7a + cpe:/a:khaled_mardam-bey:mirc:3.1 + cpe:/a:khaled_mardam-bey:mirc:3.2 + + CVE-2002-0231 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T20:00:45.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mirc-nickname-bo(8083) + + + MISC + http://www.uuuppz.com/research/adv-001-mirc.htm + + + BUGTRAQ + 20020204 Re: Buffer overflow in mIRC allowing arbitary code to be executed. + + + BID + 4027 + + + BUGTRAQ + 20020203 Buffer overflow in mIRC allowing arbitary code to be executed. + + Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. + + + + + + + + + + cpe:/a:mrtg:multi_router_traffic_grapher_cgi:2.9.17::win32 + cpe:/a:mrtg:multi_router_traffic_grapher_cgi:2.9.17::unix + + CVE-2002-0232 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:30.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020202 new advisory + + + BID + 4017 + + + XF + mrtg-cgi-view-files(8062) + + Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi. + + + + + + + + + + cpe:/a:eshare_communications_inc.:eshare_expressions:1.0 + cpe:/a:eshare_communications_inc.:eshare_expressions:2.0 + + CVE-2002-0233 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:30.480-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4029 + + + XF + expressions-dot-directory-traversal(8079) + + + BUGTRAQ + 20020205 Viewing arbitrary file from the file system using Eshare Expressions 4 server + + Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. + + + + + + + + + cpe:/o:juniper:netscreen_screenos:2.6.1 + + CVE-2002-0234 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:30.637-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4015 + + + XF + netscreen-screenos-scan-dos(8057) + + + BUGTRAQ + 20020205 NetScreen Response to ScreenOS Port Scan DoS Vulnerability + + + BUGTRAQ + 20020201 RE: NetScreen ScreenOS 2.6 Subject to Trust Interface DoS + + + BUGTRAQ + 20020201 NetScreen ScreenOS 2.6 Subject to Trust Interface DoS + + NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections. + + + + + + + + + cpe:/a:castelle:faxpress:6.3 + + CVE-2002-0235 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:30.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020205 Castelle Faxpress: Password used for NT Print queue can be discl osed in Plain Text + + + BID + 4030 + + + XF + faxpress-plaintext-password(8086) + + Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in plaintext in an error event. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:lucent:vitalnet:8.0 + cpe:/a:lucent:vitalnet:8.1 + cpe:/a:lucent:vitalnet:8.2 + cpe:/a:lucent:vitalsuite:8.0 + cpe:/a:lucent:vitalsuite:8.2 + cpe:/a:lucent:vitalsuite:8.1 + cpe:/a:lucent:vitalanalysis:8.1 + cpe:/a:lucent:vitalanalysis:8.2 + cpe:/a:lucent:vitalanalysis:8.0 + cpe:/a:lucent:vitalevent:8.0 + cpe:/a:lucent:vitalhelp:8.2 + cpe:/a:lucent:vitalevent:8.1 + cpe:/a:lucent:vitalhelp:8.1 + cpe:/a:lucent:vitalevent:8.2 + cpe:/a:lucent:vitalhelp:8.0 + + CVE-2002-0236 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:30.917-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3784 + + + XF + vitalnet-unauth-access(7936) + + + BUGTRAQ + 20020205 Published Report of Vulnerability in Lucent VitalSuite Software + + Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user. + + + + + + + + + + + + + + + cpe:/a:iss:realsecure_server_sensor:6.0.1 + cpe:/a:iss:blackice_defender:2.9cap + cpe:/a:iss:blackice_defender:2.9caq + cpe:/a:iss:blackice_defender:2.9 + cpe:/a:iss:realsecure_server_sensor:6.5 + cpe:/a:iss:blackice_agent:3.1 + cpe:/a:iss:blackice_agent:3.0 + + CVE-2002-0237 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + blackice-ping-flood-dos(8058) + + + ISS + 20020204 DoS and Potential Overflow Vulnerability in BlackICE Products + + + BUGTRAQ + 20020209 ALERT: ISS BlackICE Kernel Overflow Exploitable + + + BID + 4025 + + + NTBUGTRAQ + 20020209 ALERT: ISS BlackICE Kernel Overflow Exploitable + + + BUGTRAQ + 20020206 Black ICE Ping Vulnerability Side Note + + + BUGTRAQ + 20020204 Vulnerability in Black ICE Defender + + Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping packets. + + + + + + + + + + + cpe:/h:netgear:rt314:3.25 + cpe:/h:netgear:rt314:3.24 + cpe:/h:netgear:rt314:3.22 + + CVE-2002-0238 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + netgear-web-interface-css(8082) + + + BUGTRAQ + 20020203 Netgear RT311/RT314 + + + BID + 4024 + + Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script. + + + + + + + + + + cpe:/a:hanterm:hanterm:3.3.1 + cpe:/a:hanterm:hanterm:3.3 + + CVE-2002-0239 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.197-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hanterm-command-line-bo(8109) + + + DEBIAN + DSA-112 + + + BUGTRAQ + 20020207 another hanterm exploit + + + BUGTRAQ + 20020207 Overflow Vulnerabilities in hanterm + + + BID + 4050 + + + SECTRACK + 1001950 + + + FREEBSD + FreeBSD-SA-01:41 + + Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument. + + + + + + + + + cpe:/a:apache:http_server:2.0.28:beta + + CVE-2002-0240 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:31.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4057 + + + XF + apache-php-options-information(8119) + + + BUGTRAQ + 20020207 PHP Advisory #2 + + PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message. + + + + + + + + + cpe:/a:cisco:secure_access_control_server:3.0.1::windows_nt + + CVE-2002-0241 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:31.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4048 + + + XF + ciscosecure-nds-authentication(8106) + + + CISCO + 20020207 Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability + + NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server. + + + + + + + + + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0242 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:31.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020207 Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA) + + Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0 + + CVE-2002-0243 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:32.010-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020207 Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA) + + Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed. + + + + + + + + + cpe:/a:atheos:atheos:0.3.7 + + CVE-2002-0244 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:32.150-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + atheos-dot-directory-traversal(8108) + + + BID + 4051 + + + BUGTRAQ + 20020207 AtheOS: escaping from a chroot jail + + Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir. + + + + + + + + + + + + + + + + + + + + + cpe:/a:lotus:domino:5.0 + cpe:/a:lotus:domino:5.0.5 + cpe:/a:lotus:domino:5.0.4 + cpe:/a:lotus:domino:5.0.7 + cpe:/a:lotus:domino:5.0.6 + cpe:/a:lotus:domino:5.0.1 + cpe:/a:lotus:domino:5.0.3 + cpe:/a:lotus:domino:5.0.2 + cpe:/a:lotus:domino:5.0.4a + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:5.0.9 + cpe:/a:lotus:domino:5.0.6a + cpe:/a:lotus:domino:5.0.7a + + CVE-2002-0245 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + lotus-domino-reveal-information(8160) + + + BUGTRAQ + 20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service + + + BID + 4049 + + + CONFIRM + http://www-1.ibm.com/support/manager.wss?rs=1&rt=0&org=sims&doc=07B32060E4CC97E985256B64005AEB0F + + Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message. + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + + CVE-2002-0246 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.867-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + unixware-msg-catalog-format-string(8113) + + + CALDERA + CSSA-2002-SCO.3 + + + BUGTRAQ + 20020210 Unixware Message catalog exploit code + + + BID + 4060 + + Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint. + + + + + + + + + cpe:/a:wliang:wmtv:0.6.5 + + CVE-2002-0247 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:47.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + wmtv-local-bo(8111) + + + DEBIAN + DSA-108 + + + BID + 4054 + + Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges. + + + + + + + + + cpe:/a:wliang:wmtv:0.6.5 + + CVE-2002-0248 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:48.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-108 + + + XF + wmtv-config-file-symlink(8110) + + + BID + 4052 + + wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file. + + + + + + + + + cpe:/a:apache:http_server:2.0.28:beta + + CVE-2002-0249 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:32.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4056 + + + XF + php-123-path-information(8121) + + + BUGTRAQ + 20020207 Security Advisory - #1 + + PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message. + + + + + + + + + + + + + + + cpe:/h:hp:advancestack_10base-t_switching_hub_j3200a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3202a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3201a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3210a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3205a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3203a:a.03.07 + cpe:/h:hp:advancestack_10base-t_switching_hub_j3204a:a.03.07 + + CVE-2002-0250 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:33.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-advancestack-bypass-auth(8124) + + + HP + HPSBUX0202-185 + + + BID + 4062 + + + BUGTRAQ + 20020208 Hewlett Packard AdvanceStack Switch Managment Authentication Bypass Vulnerability + + Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password. + + + + + + + + + + + + + cpe:/a:licq:licq:1.0 + cpe:/a:licq:licq:1.0.2 + cpe:/a:licq:licq:1.0.1 + cpe:/a:licq:licq:1.0.4 + cpe:/a:licq:licq:1.0.3 + + CVE-2002-0251 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:33.213-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4036 + + + BUGTRAQ + 20020206 -Possible- licq D.o.S + + + XF + licq-static-bo(8107) + + + BUGTRAQ + 20020208 RE: -Possible- licq D.o.S + + Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d". + + + + + + + + + + cpe:/a:apple:quicktime:5.0.2 + cpe:/a:apple:quicktime:5.0.1 + + CVE-2002-0252 + 2002-05-29T00:00:00.000-04:00 + 2009-08-19T00:09:07.390-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4064 + + + MILW0RM + 4673 + + + XF + quicktime-content-header-bo(8126) + + + BUGTRAQ + 20020208 [SPSadvisory#46]Apple QuickTime Player "Content-Type" Buffer Overflow + + Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header. + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.0 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.0.1 + + CVE-2002-0253 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:48.460-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020207 Advisory #3 - PHP & JSP + + + XF + php-slash-path-information(8122) + + + BID + 4063 + + PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path. + + + + + + + + + cpe:/a:mirabilis:icq:2001b_build3659 + + CVE-2002-0254 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:33.683-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020208 -possible- Bufferoverflow in ICQ 2001b + + ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails. + + + + + + + + + cpe:/h:arescom:netdsl:800u + + CVE-2002-0255 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:33.823-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4066 + + + XF + netdsl-telnet-bypass-authentication(8125) + + + BUGTRAQ + 20020208 arescom 800 authentification flaw + + The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router. + + + + + + + + + cpe:/h:arescom:netdsl:1000 + + CVE-2002-0256 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:33.980-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4067 + + + XF + netdsl-telnet-dos(8123) + + + BUGTRAQ + 20020209 Arescom NetDSL-1000 telnetd DoS + + The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop. + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.22 + cpe:/a:usanet_creations:makebid_auction_deluxe:3.30 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.20 + + CVE-2002-0257 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:34.120-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4069 + + + XF + makebid-description-css(8161) + + + BUGTRAQ + 20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30 + + + CONFIRM + http://www.netcreations.addr.com/dcforum/DCForumID2/126.html + + Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4. + + + + + + + + + + cpe:/a:merak:mail_server + cpe:/a:icewarp:web_mail + + CVE-2002-0258 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:34.277-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020209 Security Issue in Icewarp + + Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs. + + + + + + + + + cpe:/a:instantservers_inc.:miniportal:1.1.5 + + CVE-2002-0259 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:34.417-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4076 + + + XF + miniportal-plaintext-information(8170) + + + CONFIRM + http://www.instantservers.com/releases.html + + + BUGTRAQ + 20020209 InstantServers MiniPortal Multiple Vulnerabilities + + InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges. + + + + + + + + + cpe:/a:instantservers_inc.:miniportal:1.1.5 + + CVE-2002-0260 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:34.573-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4073 + + + XF + miniportal-ftp-login-bo(8172) + + + CONFIRM + http://www.instantservers.com/releases.html + + + BUGTRAQ + 20020209 InstantServers MiniPortal Multiple Vulnerabilities + + Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility. + + + + + + + + + cpe:/a:instantservers_inc.:miniportal:1.1.5 + + CVE-2002-0261 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:34.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4075 + + + XF + miniportal-ftp-directory-traversal(8171) + + + CONFIRM + http://www.instantservers.com/releases.html + + + BUGTRAQ + 20020209 InstantServers MiniPortal Multiple Vulnerabilities + + Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command. + + + + + + + + + cpe:/a:sybex:e-trainer + + CVE-2002-0262 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:49.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sybex-etrainer-directory-traversal(8175) + + + BUGTRAQ + 20020210 Sybex E-Trainer Directory Traversal Vulnerability + + + BID + 4071 + + Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. + + + + + + + + + cpe:/a:ezne.net:ezboard_2000:1.27 + + CVE-2002-0263 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:35.010-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4068 + + + XF + ezboard-bbs-contenttype-bo(8162) + + + BUGTRAQ + 20020211 EasyBoard 2000 Remote Buffer Overflow Vulnerability + + Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi. + + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + cpe:/a:cooolsoft:powerftp:2.10 + + CVE-2002-0264 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:35.150-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4074 + + + BUGTRAQ + 20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities + + + XF + powerftp-ftpserver-ini-plaintext(8183) + + PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sawmill:sawmill:6.2.12 + cpe:/a:sawmill:sawmill:6.2.11 + cpe:/a:sawmill:sawmill:6.2.10 + cpe:/a:sawmill:sawmill:6.2.8a + cpe:/a:sawmill:sawmill:6.2.8 + cpe:/a:sawmill:sawmill:6.2.9 + cpe:/a:sawmill:sawmill:6.2.6 + cpe:/a:sawmill:sawmill:6.2.7 + cpe:/a:sawmill:sawmill:6.2.4 + cpe:/a:sawmill:sawmill:6.2.5 + cpe:/a:sawmill:sawmill:6.2.2 + cpe:/a:sawmill:sawmill:6.2.3 + cpe:/a:sawmill:sawmill:6.2.13 + cpe:/a:sawmill:sawmill:6.2.1 + cpe:/a:sawmill:sawmill:6.2.14 + cpe:/a:sawmill:sawmill:6.2 + + CVE-2002-0265 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:35.307-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4077 + + + XF + sawmill-admin-password-insecure(8173) + + + BUGTRAQ + 20020211 Vulnerability in Sawmill for Solaris v. 6.2.14 + + + CONFIRM + http://www.sawmill.net/version_history.html + + Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file. + + + + + + + + + cpe:/a:thunderstone_software:texis:3.0 + + CVE-2002-0266 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:49.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + texis-cgi-information-disclosure(8103) + + + BUGTRAQ + 20020206 texis(CGI) Path Disclosure Vulnerability + + + BID + 4035 + + + BUGTRAQ + 20020211 Re: texis(CGI) Path Disclosure Vulnerability + + Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname. + + + + + + + + + + + + cpe:/a:sips:sips:0.3.0 + cpe:/a:sips:sips:0.3.0pl2 + cpe:/a:sips:sips:0.3.0pl1 + cpe:/a:sips:sips:0.2.4 + + CVE-2002-0267 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:50.057-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://sips.sourceforge.net/adminvul.html + + + BUGTRAQ + 20020212 SIPS - vulnerable to anyone gaining admin access. + + + BID + 4097 + + + XF + sips-theme-admin-access(8193) + + preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into the password file. + + + + + + + + + cpe:/a:identix:biologon:3.0 + + CVE-2002-0268 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:50.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020212 Identix BioLogon 3 + + + BID + 4101 + + + XF + biologon3-gina-bypass-authentication(8201) + + Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges. + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.01 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0269 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:35.933-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020212 [GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting + + Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:9.10 + + CVE-2002-0270 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T00:00:00.000-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BUGTRAQ + 20020212 [GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting + + Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. + + + + + + + + + + + cpe:/a:ada_core_technologies:gnat_pro_native:3.13p + cpe:/a:ada_core_technologies:gnat_pro_native:3.12p + cpe:/a:ada_core_technologies:gnat_pro_native:3.14p + + CVE-2002-0271 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:00:50.447-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4086 + + + BUGTRAQ + 20020212 RUS-CERT Advisory 2002-02:01: Temporary file handling in GNAT + + Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files. + + + + + + + + + + + cpe:/a:mpg321:mpg321:0.2.9 + cpe:/a:mpg321:mpg321:0.2.3 + cpe:/a:mpg321:mpg321:0.2.2 + + CVE-2002-0272 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:50.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=79237 + + + VULN-DEV + 20020212 mpg321 + + + BID + 4091 + + + BUGTRAQ + 20020213 Re: mpg321 + + Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netwin:cwmail:2.7t + cpe:/a:netwin:cwmail:2.7s + cpe:/a:netwin:cwmail:2.7q + cpe:/a:netwin:cwmail:2.7l + cpe:/a:netwin:cwmail:2.7k + cpe:/a:netwin:cwmail:2.7j + cpe:/a:netwin:cwmail:2.7i + cpe:/a:netwin:cwmail:2.7p + cpe:/a:netwin:cwmail:2.7o + cpe:/a:netwin:cwmail:2.7n + cpe:/a:netwin:cwmail:2.7m + cpe:/a:netwin:cwmail:2.7c + cpe:/a:netwin:cwmail:2.7d + cpe:/a:netwin:cwmail:2.7a + cpe:/a:netwin:cwmail:2.7b + cpe:/a:netwin:cwmail:2.7f + cpe:/a:netwin:cwmail:2.7 + + CVE-2002-0273 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:50.603-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020213 NetWin CWMail.exe Buffer Overflow + + + BID + 4093 + + + XF + cwmail-item-bo(8185) + + Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter. + + + + + + + + + cpe:/a:university_of_cambridge:exim:3.34 + + CVE-2002-0274 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T15:11:41.320-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020213 Exim 3.34 and lower (fwd) + + + BID + 4096 + + + REDHAT + RHSA-2002:208 + + + XF + exim-config-arg-bo(8194) + + Exim 3.34 and earlier may allow local users to gain privileges via a buffer overflow in long -C (configuration file) and other command line arguments. + + + + + + + + + + cpe:/a:blueface:falcon_web_server:2.0.0.1009 + cpe:/a:blueface:falcon_web_server:2.0.0.1020 + + CVE-2002-0275 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:50.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020213 Falcon Web Server Authentication Circumvention Vulnerability + + + XF + falcon-protected-dir-access(8189) + + + BID + 4099 + + + BUGTRAQ + 20020526 [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability + + + VULNWATCH + 20020526 [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability + + Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL. + + + + + + + + + cpe:/a:ettercap:ettercap:0.6.3.1 + + CVE-2002-0276 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:51.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020213 [NGSEC-2002-1] Ettercap, remote root compromise + + + CONFIRM + http://ettercap.sourceforge.net/index.php?s=history + + + BID + 4104 + + + XF + ettercap-memcpy-bo(8200) + + Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers to execute arbitrary code via large packets. + + + + + + + + + cpe:/a:add2it:mailman_free:1.73 + + CVE-2002-0277 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:37.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.add2it.com/scripts/mailman-free-history.shtml + + + BUGTRAQ + 20020214 Add2it Mailman command execution + + + BID + 4105 + + + XF + mailman-open-execute-commands(8202) + + Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter. + + + + + + + + + cpe:/a:add2it:mailman_free:1.73 + + CVE-2002-0278 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:37.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.add2it.com/scripts/mailman-free-history.shtml + + + BUGTRAQ + 20020214 Add2it Mailman command execution + + + XF + mailman-open-execute-commands(8202) + + Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter. + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + + CVE-2002-0279 + 2002-05-31T00:00:00.000-04:00 + 2009-03-04T00:11:32.530-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#726187 + + + HP + HPSBUX0202-183 + + + BID + 4094 + + + XF + hpux-setrlimit-kernel-panic(8195) + + + + + The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges. + + + + + + + + + cpe:/a:codeblue:codeblue:4 + + CVE-2002-0280 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:37.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://freshmeat.net/releases/71514/ + + + BUGTRAQ + 20020215 codeblue remote root + + Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply. + + + + + + + + + + + + cpe:/a:codeworx_technologies:dcp-portal:4.0 + cpe:/a:codeworx_technologies:dcp-portal:4.1 + cpe:/a:codeworx_technologies:dcp-portal:4.2 + cpe:/a:codeworx_technologies:dcp-portal:3.7 + + CVE-2002-0281 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:51.727-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + dcpportal-userupdate-css(8197) + + + BID + 4112 + + + MISC + http://www.dcp-portal.com/contents.php?id=18 + + + BUGTRAQ + 20020215 [ARL02-A03] DCP-Portal Cross Site Scripting Vulnerability + + Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php. + + + + + + + + + + + + + cpe:/a:codeworx_technologies:dcp-portal:4.0 + cpe:/a:codeworx_technologies:dcp-portal:4.1 + cpe:/a:codeworx_technologies:dcp-portal:4.2 + cpe:/a:codeworx_technologies:dcp-portal:4.5 + cpe:/a:codeworx_technologies:dcp-portal:3.7 + + CVE-2002-0282 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:51.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dcpportal-language-path-disclosure(8310) + + + XF + dcpportal-adduser-path-disclosure(8196) + + + BID + 4113 + + + CONFIRM + http://www.dcp-portal.com/files.php?action=viewcat&fcat_id=1 + + + BUGTRAQ + 20020228 [ARL02-A04] DCP-Portal System Information Path Disclosure + + + BUGTRAQ + 20020215 [ARL02-A02] DCP-Portal Root Path Disclosure Vulnerability + + DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message. + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + + CVE-2002-0283 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:38.120-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020215 Windows XP Remote DOS attacks with SYN Flag. Make CPU 100% + + Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data. + + + + + + + + + + cpe:/a:nullsoft:winamp:2.77 + cpe:/a:nullsoft:winamp:2.78 + + CVE-2002-0284 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:38.260-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020215 winamp and wma Song Licenses + + Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname. + + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2002-0285 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:52.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020212 Outlook will see non-existing attachments + + + BID + 4092 + + + XF + outlook-express-return-bypass(8198) + + Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers. + + + + + + + + + + + + + + + + + + + cpe:/a:sitenews:sitenews:0.08_beta + cpe:/a:sitenews:sitenews:0.06_beta + cpe:/a:sitenews:sitenews:0.04_beta + cpe:/a:sitenews:sitenews:0.02_beta + cpe:/a:sitenews:sitenews:0.11_beta + cpe:/a:sitenews:sitenews:0.07_beta + cpe:/a:sitenews:sitenews:0.01_beta + cpe:/a:sitenews:sitenews:0.09_beta + cpe:/a:sitenews:sitenews:0.10_beta + cpe:/a:sitenews:sitenews:0.05_beta + cpe:/a:sitenews:sitenews:0.03_beta + + CVE-2002-0286 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020216 SiteNews remote add user exploit + + + XF + sitenews-getpassword-add-users(8181) + + + BID + 4046 + + The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user. + + + + + + + + + cpe:/a:powie:pforum:1.14 + + CVE-2002-0287 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.087-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.powie.de/news/index.php + + + BUGTRAQ + 20020216 pforum: mysql-injection-bug + + + BID + 4114 + + + XF + pforum-quotes-sql-injection(8203) + + pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default. + + + + + + + + + cpe:/a:bbshareware.com:phusion_webserver:1.0 + + CVE-2002-0288 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020217 Phusion-Webserver-v1.0-Bugs&Exploits-Remotes + + + BID + 4117 + + Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request. + + + + + + + + + cpe:/a:bbshareware.com:phusion_webserver:1.0 + + CVE-2002-0289 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020217 Phusion-Webserver-v1.0-Bugs&Exploits-Remotes + + + BID + 4119 + + + BID + 4118 + + Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. + + + + + + + + + + + cpe:/a:netwin:webnews:1.1j + cpe:/a:netwin:webnews:1.1h + cpe:/a:netwin:webnews:1.1i + + CVE-2002-0290 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020218 Netwin Webnews Buffer Overflow Vulnerability (#NISR18022002) + + + CONFIRM + ftp://netwinsite.com/pub/webnews/beta/webnews11m_solaris.tar.Z + + + BID + 4124 + + + XF + webnews-cgi-group-bo(8220) + + Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument. + + + + + + + + + + cpe:/a:funsoft:dinos_webserver:1.2 + cpe:/a:funsoft:dinos_webserver:1.0 + + CVE-2002-0291 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dino-log-tag-bo(8233) + + + BUGTRAQ + 20020218 Dino's Webserver v1.2 DoS, possible overflow + + + BID + 4123 + + Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time. + + + + + + + + + + + + + + + + + cpe:/a:open_source_development_network:slashcode:1.0.8 + cpe:/a:open_source_development_network:slashcode:2.2.1 + cpe:/a:open_source_development_network:slashcode:2.2.2 + cpe:/a:open_source_development_network:slashcode:2.1.1 + cpe:/a:open_source_development_network:slashcode:2.0 + cpe:/a:open_source_development_network:slashcode:2.2.4 + cpe:/a:open_source_development_network:slashcode:2.1 + cpe:/a:open_source_development_network:slashcode:2.2.3 + cpe:/a:open_source_development_network:slashcode:2.2 + + CVE-2002-0292 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.540-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020219 [SA-2002:01] Slashcode login vulnerability + + + BID + 4116 + + + XF + slashcode-site-xss(8221) + + Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field. + + + + + + + + + cpe:/a:alcatel-lucent:omnipcx:4400 + + CVE-2002-0293 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:39.637-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + omnipcx-ftp-root-access(8225) + + + BUGTRAQ + 20020219 Security BugWare : Alcatel 4400 PBX hack + + FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file. + + + + + + + + + cpe:/a:alcatel-lucent:omnipcx:4400 + + CVE-2002-0294 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.710-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020219 Security BugWare : Alcatel 4400 PBX hack + + + BID + 4130 + + Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. + + + + + + + + + cpe:/a:alcatel-lucent:omnipcx:4400 + + CVE-2002-0295 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:53.853-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020219 Security BugWare : Alcatel 4400 PBX hack + + + BID + 4133 + + Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. + + + + + + + + + + + + + cpe:/a:tarantella:tarantella_enterprise:3.20 + cpe:/a:tarantella:tarantella_enterprise:3.11 + cpe:/a:tarantella:tarantella_enterprise:3.10 + cpe:/a:tarantella:tarantella_enterprise:3.01 + cpe:/a:tarantella:tarantella_enterprise:3.0 + + CVE-2002-0296 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:40.073-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + tarantella-tmp-spinning-symlink(8223) + + + BID + 4115 + + + BUGTRAQ + 20020219 Another local root vulnerability during installation of Tarantella Enterprise 3. + + + BUGTRAQ + 20020224 Exploit for Tarantella Enterprise installation (bid 4115) + + The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file. + + + + + + + + + cpe:/a:nombas:scriptease_webserver:0.95 + + CVE-2002-0297 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4128 + + + BUGTRAQ + 20020219 ScriptEase MiniWeb Server DoS Vulnerability + + Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request. + + + + + + + + + cpe:/a:nombas:scriptease_webserver:0.95 + + CVE-2002-0298 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4145 + + + BUGTRAQ + 20020219 Four More ScriptEase MiniWeb Server v0.95 DoS Attacks + + ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character. + + + + + + + + + cpe:/a:cnet:catchup:1.3 + + CVE-2002-0299 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.197-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020220 CNet CatchUp arbitrary code execution + + + BID + 3975 + + + XF + cnet-catchup-gain-privileges(8035) + + CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan. + + + + + + + + + + cpe:/a:gnujsp:gnujsp:1.0.0 + cpe:/a:gnujsp:gnujsp:1.0.1 + + CVE-2002-0300 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-114 + + + BUGTRAQ + 20020219 gnujsp: dir- and script-disclosure + + + BID + 4125 + + + XF + gnujsp-jserv-information-disclosure(8240) + + + BUGTRAQ + 20020220 Re: gnujsp: dir- and script-disclosure + + gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file. + + + + + + + + + cpe:/a:citrix:nfuse:1.6 + + CVE-2002-0301 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020220 Re: Citrix NFuse 1.6 - additional network exposure + + + BID + 4142 + + Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. + + + + + + + + + + cpe:/a:symantec:enterprise_firewall:7.0 + cpe:/a:symantec:enterprise_firewall:6.5.2 + + CVE-2002-0302 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20a.html + + + BUGTRAQ + 20020220 Symantec Enterprise Firewall (SEF) Notify Daemon data loss via SN MP + + + XF + sef-snmp-notify-loss(8253) + + + BID + 4139 + + The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack. + + + + + + + + + cpe:/a:novell:groupwise:6.0 + + CVE-2002-0303 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:54.710-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020220 Security issue with GroupWise 6 and LDAP authentication in PostOffice + + + BID + 4154 + + GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password. + + + + + + + + + cpe:/a:summit_computer_networks:lil_http_server:2.1 + + CVE-2002-0304 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T15:11:45.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020320 LilHTTP Web Server Protected File Access Vulnerability (Solution) + + + MISC + http://www.summitcn.com/lilhttp/lildocs.html#WhatsNew + + + BUGTRAQ + 20020220 SecurityOffice Security Advisory:// LilHTTP Web Server Protected File Access Vulnerability + + + BID + 4153 + + Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request. + + + + + + + + + cpe:/h:zero_one_tech:p100s + + CVE-2002-0305 + 2002-05-31T00:00:00.000-04:00 + 2008-09-05T16:27:41.400-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + zot-default-snmp-string(8270) + + + BID + 4155 + + + BUGTRAQ + 20020221 Zero One Tech (ZOT) P100s PrintServer and SNMP + + Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge. + + + + + + + + + + cpe:/a:avengers_news_system:avengers_news_system:2.01 + cpe:/a:avengers_news_system:avengers_news_system:2.11 + + CVE-2002-0306 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020221 "Cthulhu xhAze" - Command execution in Ans.pl + + + BID + 4149 + + ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter. + + + + + + + + + + cpe:/a:avengers_news_system:avengers_news_system:2.01 + cpe:/a:avengers_news_system:avengers_news_system:2.11 + + CVE-2002-0307 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020221 "Cthulhu xhAze" - Command execution in Ans.pl + + + BID + 4147 + + Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function. + + + + + + + + + cpe:/a:stefan_holmberg:admentor:2.11 + + CVE-2002-0308 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.197-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020221 AdMentor Login Flaw + + + XF + admentor-asp-gain-access(8245) + + + BID + 4152 + + admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments. + + + + + + + + + cpe:/a:symantec:enterprise_firewall:6.5.2 + + CVE-2002-0309 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020221 Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.02.20.html + + + BUGTRAQ + 20020220 Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies + + + BID + 4141 + + + XF + sef-smtp-proxy-information(8251) + + SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information. + + + + + + + + + + + + cpe:/a:netwin:webnews:1.1j + cpe:/a:netwin:webnews:1.1k + cpe:/a:netwin:webnews:1.1h + cpe:/a:netwin:webnews:1.1i + + CVE-2002-0310 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + webnews-cgi-default-accounts(8255) + + + BUGTRAQ + 20020221 Netwin Webnews 1.1k + + + BID + 4156 + + Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0311 + 2002-05-31T00:00:00.000-04:00 + 2008-09-10T20:00:55.447-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + unixware-webtop-execute-commands(7977) + + + BUGTRAQ + 20020120 Unixware 7.1.1 scoadminreg.cgi local exploit + + + CALDERA + CSSA-2002-SCO.6 + + + BID + 3936 + + Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi. + + + + + + + + + cpe:/a:essen:essentia_web_server:2.1 + + CVE-2002-0312 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:42.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4160 + + + XF + essentia-server-directory-traversal(8248) + + + BUGTRAQ + 20020226 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch) + + + BUGTRAQ + 20020221 SecurityOffice Security Advisory:// Essentia Web Server Directory Traversal Vulnerability + + + NTBUGTRAQ + 20020222 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch) + + Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. + + + + + + + + + cpe:/a:essen:essentia_web_server:2.1 + + CVE-2002-0313 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:42.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4159 + + + XF + essentia-server-long-request-dos(8249) + + + BUGTRAQ + 20020226 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch) + + + BUGTRAQ + 20020221 SecurityOffice Security Advisory:// Essentia Web Server DoS Vulnerability + + + FULLDISC + 20030704 Essentia Web Server 2.12 (Linux) + + Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. + + + + + + + + + + + + + + + + cpe:/a:music_city_networks:morpheus:1.3 + cpe:/a:fasttrack:kazaa:1.3.3 + cpe:/a:grokster:grokster:1.3.3 + cpe:/a:music_city_networks:morpheus:1.3.3 + cpe:/a:grokster:grokster:1.3 + cpe:/a:fasttrack:kazaa:1.4 + cpe:/a:fasttrack:kazaa:1.3 + cpe:/a:fasttrack:kazaa:1.2 + + CVE-2002-0314 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:42.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4122 + + + XF + fasttrack-message-service-dos(8273) + + + BUGTRAQ + 20020222 Morpheus, Kazaa and Grokster Remote DoS. Also Identity faking vulnerability. + + fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. + + + + + + + + + + + + + + + + + cpe:/a:music_city_networks:morpheus:1.3 + cpe:/a:fasttrack:kazaa:1.3.3 + cpe:/a:grokster:grokster:1.3.3 + cpe:/a:music_city_networks:morpheus:1.3.3 + cpe:/a:fasttrack:kazaa:1.5 + cpe:/a:grokster:grokster:1.3 + cpe:/a:fasttrack:kazaa:1.4 + cpe:/a:fasttrack:kazaa:1.3 + cpe:/a:fasttrack:kazaa:1.2 + + CVE-2002-0315 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:42.887-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4121 + + + XF + fasttrack-message-service-spoof(8272) + + + BUGTRAQ + 20020222 Morpheus, Kazaa and Grokster Remote DoS. Also Identity faking vulnerability. + + fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. + + + + + + + + + cpe:/a:xmb_software:xmb_forum:1.6_pre-beta + + CVE-2002-0316 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:43.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4167 + + + XF + xmb-php-css(8262) + + + BUGTRAQ + 20020222 XMB cross-scripting vulnerability + + Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag. + + + + + + + + + cpe:/a:gator:gator:3.0.6.1 + + CVE-2002-0317 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:43.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4161 + + + XF + gator-activex-install(8266) + + + MISC + http://www.gator.com/update/ + + + BUGTRAQ + 20020220 Gator installer Plugin allows any software to be installed + + Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter. + + + + + + + + + cpe:/a:freeradius:freeradius + + CVE-2002-0318 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:43.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020221 DoS Attack against many RADIUS servers + + + XF + freeradius-access-request-dos(9968) + + FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets. + + + + + + + + + + + + cpe:/a:powie:pforum:1.12 + cpe:/a:powie:pforum:1.11 + cpe:/a:powie:pforum:1.14 + cpe:/a:powie:pforum:1.13 + + CVE-2002-0319 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:43.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4165 + + + XF + pforum-username-css(8263) + + + BUGTRAQ + 20020222 pforum: cross-site-scripting bug + + Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-0320 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:56.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#887319 + + + CERT-VN + VU#419419 + + + CERT + CA-2002-16 + + + XF + yahoo-messenger-imvironment-bo(8265) + + + XF + yahoo-messenger-message-bo(8264) + + + BID + 4163 + + + BID + 4162 + + + BUGTRAQ + 20020221 Remote crashes in Yahoo messenger + + Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-0321 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:43.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#952875 + + + CERT + CA-2002-16 + + + XF + yahoo-messenger-username-spoof(8267) + + + BID + 4164 + + + BUGTRAQ + 20020221 Remote crashes in Yahoo messenger + + Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. + + + + + + + + + cpe:/a:yahoo:messenger:4.0 + + CVE-2002-0322 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:56.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4173 + + + BUGTRAQ + 20020223 Re: Re: Remote crashes in Yahoo messenger + + + BUGTRAQ + 20020223 Re: Remote crashes in Yahoo messenger + + Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. + + + + + + + + + cpe:/a:nombas:scriptease_webserver:4.3.0 + + CVE-2002-0323 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:44.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020224 ScriptEase:WebServer Edition vulnerability + + comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL. + + + + + + + + + + + + cpe:/a:noah_gray:graymatter:1.2b + cpe:/a:noah_gray:graymatter:1.1b + cpe:/a:noah_gray:graymatter:1.1 + cpe:/a:noah_gray:graymatter:1.21 + + CVE-2002-0324 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:56.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + greymatter-gmrightclick-account-information(8277) + + + MISC + http://www.dangerousmonkey.com/dangblog/dangarch/00000051.htm + + + BUGTRAQ + 20020224 Greymatter 1.21c and earlier - remote login/pass exposure + + + BID + 4169 + + Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action. + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.5.6_beta + cpe:/a:working_resources_inc.:badblue:1.6_beta + + CVE-2002-0325 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:44.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4179 + + + XF + badblue-dotdotdot-directory-traversal(8295) + + + BUGTRAQ + 20020226 BadBlue Yet Another Directory Traversal + + Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. + + + + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.5.6_beta + cpe:/a:working_resources_inc.:badblue:1.5 + cpe:/a:working_resources_inc.:badblue:1.2.7 + cpe:/a:working_resources_inc.:badblue:1.2.8 + cpe:/a:working_resources_inc.:badblue:1.6.1_beta + + CVE-2002-0326 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:44.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4180 + + + XF + badblue-url-css(8294) + + + BUGTRAQ + 20020226 BadBlue XSS vulnerabilities / Filesharing Server Worm + + Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. + + + + + + + + + cpe:/a:century_software:term:6.27.0869 + + CVE-2002-0327 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:56.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + term-tty-bo(8291) + + + VULN-DEV + 20020222 Censoft TERM Emu bOf + + + BUGTRAQ + 20020227 Century Software Term Exploit + + + BID + 4174 + + Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program. + + + + + + + + + + cpe:/a:ikonboard.com:ikonboard:3.0.1 + cpe:/a:ikonboard.com:ikonboard:2.17 + + CVE-2002-0328 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:56.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020226 Re: Open Bulletin Board javascript bug. + + + BID + 4182 + + Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag. + + + + + + + + + + + + + + cpe:/a:snitz_communications:snitz_forums_2000:3.0 + cpe:/a:snitz_communications:snitz_forums_2000:3.3.01 + cpe:/a:snitz_communications:snitz_forums_2000:3.3 + cpe:/a:snitz_communications:snitz_forums_2000:3.2.03 + cpe:/a:snitz_communications:snitz_forums_2000:3.3.02 + cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4 + + CVE-2002-0329 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:57.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#132011 + + + XF + snitz-img-css(8309) + + + BUGTRAQ + 20020227 RE: Open Bulletin Board javascript bug. + + + CONFIRM + http://forum.snitz.com/forum/link.asp?TOPIC_ID=23660 + + + BID + 4192 + + + BUGTRAQ + 20020227 Snitz 2000 Code Patch (was RE: Open Bulletin Board javascript bug.) + + Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. + + + + + + + + + + + cpe:/a:openbb:openbb:1.0.0_rc1 + cpe:/a:openbb:openbb:1.0.0_beta1 + cpe:/a:openbb:openbb:1.0.0_rc2 + + CVE-2002-0330 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:57.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + openbb-img-css(8278) + + + BUGTRAQ + 20020225 Open Bulletin Board javascript bug. + + + CONFIRM + http://community.iansoft.net/read.php?TID=5159 + + + BID + 4171 + + + OSVDB + 5658 + + Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag. + + + + + + + + + cpe:/a:alcatech_gmbh:bpm_studio_pro:4.2 + + CVE-2002-0331 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:00:57.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + bpm-http-directory-traversal(8300) + + + BUGTRAQ + 20020227 BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY + + + BID + 4198 + + Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request. + + + + + + + + + + cpe:/a:xtell:xtell:2.6.1 + cpe:/a:xtell:xtell:1.91.1 + + CVE-2002-0332 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T15:11:48.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-121 + + + BID + 4193 + + + XF + xtell-bo(8312) + + + BUGTRAQ + 20020227 Remote exploit against xtelld and other fun + + Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request. + + + + + + + + + + cpe:/a:xtell:xtell:2.6.1 + cpe:/a:xtell:xtell:1.91.1 + + CVE-2002-0333 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:45.587-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4194 + + + XF + xtell-tty-directory-traversal(8313) + + + DEBIAN + DSA-121 + + + BUGTRAQ + 20020227 Remote exploit against xtelld and other fun + + Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument. + + + + + + + + + + cpe:/a:xtell:xtell:2.6.1 + cpe:/a:xtell:xtell:1.91.1 + + CVE-2002-0334 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:45.743-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4197 + + + XF + xtell-log-symlink(8314) + + + DEBIAN + DSA-121 + + + BUGTRAQ + 20020227 Remote exploit against xtelld and other fun + + xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file. + + + + + + + + + + cpe:/a:galacticomm_technologies:worldgroup_lite_personal_server:3.20 + cpe:/a:galacticomm_technologies:worldgroup:3.20 + + CVE-2002-0335 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:45.900-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4186 + + + XF + worldgroup-http-get-bo(8298) + + + BUGTRAQ + 20020227 LBYTE&SECURITY.NNOV: Buffer overflows in Worldgroup + + Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request. + + + + + + + + + + cpe:/a:galacticomm_technologies:worldgroup_lite_personal_server:3.20 + cpe:/a:galacticomm_technologies:worldgroup:3.20 + + CVE-2002-0336 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4185 + + + XF + worldgroup-ftp-list-bo(8297) + + + BUGTRAQ + 20020227 LBYTE&SECURITY.NNOV: Buffer overflows in Worldgroup + + Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters. + + + + + + + + + cpe:/a:realnetworks:realplayer:8.0 + + CVE-2002-0337 + 2002-06-25T00:00:00.000-04:00 + 2011-03-07T21:08:06.720-05:00 + + + 5.4 + NETWORK + HIGH + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4200 + + + XF + realplayer-mp3-invalid-dos(8320) + + + BUGTRAQ + 20020227 2K, with RealPlayer Installed 100 % CPU utilization + + RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files. + + + + + + + + + + cpe:/a:ritlabs:the_bat:1.53d + cpe:/a:ritlabs:the_bat:1.54d + + CVE-2002-0338 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4187 + + + XF + thebat-msdos-device-dos(8303) + + + BUGTRAQ + 20020227 SECURITY.NNOV: Special device access in The Bat! + + The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name. + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:11.1cc + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.0st + + CVE-2002-0339 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#310387 + + + BID + 4191 + + + XF + ios-cef-information-leak(8296) + + + CISCO + 20020227 Cisco Security Advisory: Data Leak with Cisco Express Forwarding + + + OSVDB + 806 + + + + + Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length. + + + + + + + + + cpe:/a:microsoft:windows_media_player:8.00.00.4477 + + CVE-2002-0340 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.650-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020222 Windows Media Player executes WMF content in .MP3 files. + + Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content. + + + + + + + + + cpe:/a:novell:groupwise:5.5 + + CVE-2002-0341 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020227 SecurityOffice Security Advisory:// Novell GroupWise Web Access Path Disclosure Vulnerability + + GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter. + + + + + + + + + cpe:/a:kde:k-mail:1.2 + + CVE-2002-0342 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:46.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4177 + + + XF + kmail-message-body-dos(8283) + + + BUGTRAQ + 20020226 BUG: Kmail client DoS + + Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long. + + + + + + + + + cpe:/a:hotline_communications:hotline_connect:1.8.5 + + CVE-2002-0343 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4210 + + + XF + hotline-connect-plaintext-password(8327) + + + BUGTRAQ + 20020228 Hotline Client Plain password vuln. + + Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords. + + + + + + + + + cpe:/a:symantec:liveupdate:1.5 + + CVE-2002-0344 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4170 + + + XF + nav-liveupdate-plaintext-account(8282) + + + BUGTRAQ + 20020225 Symantec LiveUpdate + + + BUGTRAQ + 20020228 Re: "Javier Sanchez" jsanchez157@hotmail.com 02/25/2002 11:14 AM, Symantec + + Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. + + + + + + + + + cpe:/a:symantec:norton_ghost:7.0 + + CVE-2002-0345 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020226 RE: Symantec LiveUpdate + + + BID + 4181 + + + XF + ghost-plaintext-account(8305) + + + BUGTRAQ + 20020301 Re: "Peter Miller" pcmiller61@yahoo.com, 02/26/2002 03:48 AM RE: Symantec + + Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges. + + + + + + + + + + + cpe:/h:sun:cobalt_raq_4 + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2002-0346 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4211 + + + XF + cobalt-raq-css(8321) + + + BUGTRAQ + 20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities + + Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi. + + + + + + + + + + + cpe:/h:sun:cobalt_raq_4 + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2002-0347 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4208 + + + BUGTRAQ + 20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities + + + XF + cobalt-raq-directory-traversal(8322) + + Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request. + + + + + + + + + + + cpe:/h:sun:cobalt_raq_4 + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2002-0348 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:47.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4209 + + + BUGTRAQ + 20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities + + + XF + cobalt-raq-service-dos(8323) + + service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument. + + + + + + + + + cpe:/a:tiny_software:tiny_personal_firewall:2.0.15 + + CVE-2002-0349 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:48.040-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4207 + + + XF + tinyfw-popup-gain-access(8324) + + + BUGTRAQ + 20020228 ... Tiny Personal Firewall ... + + Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions. + + + + + + + + + + cpe:/h:hp:procurve_switch_4000m:c.08.22 + cpe:/h:hp:procurve_switch_4000m:c.09.09 + + CVE-2002-0350 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:01:00.007-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020301 DoS on HP ProCurve 4000M switch (possibly others) + + + BID + 4212 + + + XF + hp-procurve-portscan-dos(8329) + + HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service. + + + + + + + + + + + + + + + cpe:/a:matt_blaze:cfs:1.3.3_m68k + cpe:/a:matt_blaze:cfs:1.3.3 + cpe:/a:matt_blaze:cfs:1.3.3_sparc + cpe:/a:matt_blaze:cfs:1.3.3_ia32 + cpe:/a:matt_blaze:cfs:1.3.3_arm + cpe:/a:matt_blaze:cfs:1.3.3_alpha + cpe:/a:matt_blaze:cfs:1.3.3_ppc + + CVE-2002-0351 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:01:00.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-116 + + + XF + cfs-bo(8330) + + + BID + 4219 + + Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + cpe:/a:phorum:phorum:3.3.2 + + CVE-2002-0352 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T20:01:00.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + phorum-admin-users-information(8344) + + + BUGTRAQ + 20020302 Phorum Discussion Board Security Bug (Email Disclosure) + + + BID + 4226 + + Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication. + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + + CVE-2002-0353 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T15:11:49.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4604 + + + REDHAT + RHSA-2002:088 + + + XF + ethereal-asn1-dos(8952) + + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00003.html + + + DEBIAN + DSA-130 + + + CONECTIVA + CLA-2002:474 + + The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields. + + + + + + + + + + + + + + + cpe:/a:netscape:navigator:6.1 + cpe:/a:mozilla:mozilla:1.0:rc3 + cpe:/a:netscape:navigator:6.2 + cpe:/a:mozilla:mozilla:1.0:rc2 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:1.0:rc1 + cpe:/a:mozilla:mozilla:0.9.7 + + CVE-2002-0354 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:48.777-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + NTBUGTRAQ + 20020430 Reading local files in Netscape 6 and Mozilla (GM#001-NS) + + + BUGTRAQ + 20020430 Reading local files in Netscape 6 and Mozilla (GM#001-NS) + + The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-0355 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:01:00.447-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SGI + 20020503-01-I + + + BID + 4682 + + + XF + irix-netstat-file-existence(9023) + + netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.2f + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.8m + cpe:/o:sgi:irix:6.5.4m + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.6m + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.8f + cpe:/o:sgi:irix:6.5.4f + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.6f + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.10m + cpe:/o:sgi:irix:6.5.9m + cpe:/o:sgi:irix:6.5.5m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.7m + cpe:/o:sgi:irix:6.5.9f + cpe:/o:sgi:irix:6.5.5f + cpe:/o:sgi:irix:6.5.3f + cpe:/o:sgi:irix:6.5.7f + + CVE-2002-0356 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T20:01:00.523-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20020504-01-I + + + BID + 4706 + + + XF + irix-fsrxfs-gain-privileges(9042) + + Vulnerability in XFS filesystem reorganizer (fsr_xfs) in SGI IRIX 6.5.10 and earlier allows local users to gain root privileges by overwriting critical system files. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.2f + cpe:/o:sgi:irix:6.5.8m + cpe:/o:sgi:irix:6.5.4m + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.6m + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.8f + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.4f + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.6f + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.10m + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.9m + cpe:/o:sgi:irix:6.5.5m + cpe:/o:sgi:irix:6.5.7m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.9f + cpe:/o:sgi:irix:6.5.5f + cpe:/o:sgi:irix:6.5.7f + cpe:/o:sgi:irix:6.5.3f + + CVE-2002-0357 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T20:01:00.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#430419 + + + SGI + 20020601-01-P + + + XF + irix-rpcpasswd-gain-privileges(9261) + + + BID + 4939 + + + OSVDB + 834 + + + CIAC + M-087 + + Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges. + + + + + + + + + + cpe:/a:sgi:mediamail:::pro + cpe:/a:sgi:mediamail + + CVE-2002-0358 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:49.587-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SGI + 20020602-01-I + + + BID + 4959 + + + XF + irix-mediamail-core-dump(9292) + + MediaMail and MediaMail Pro in SGI IRIX 6.5.16 and earlier allows local users to force the program to dump core via certain arguments, which could allow the users to read sensitive data or gain privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.2f + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.8m + cpe:/o:sgi:irix:6.5.4m + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.6m + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.8f + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.4f + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.6f + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.5.10m + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.9m + cpe:/o:sgi:irix:6.5.5m + cpe:/o:sgi:irix:6.5.7m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.9f + cpe:/o:sgi:irix:6.5.5f + cpe:/o:sgi:irix:6.5.7f + cpe:/o:sgi:irix:6.5.3f + + CVE-2002-0359 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:11:50.320-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#521147 + + + SGI + 20020606-01-I + + + BUGTRAQ + 20020620 [LSD] IRIX rpc.xfsmd multiple remote root vulnerabilities + + + BID + 5072 + + + XF + irix-xfsmd-bypass-authentication(9401) + + xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges. + + + + + + + + + + + + cpe:/a:sun:solaris_answerbook2:1.4 + cpe:/a:sun:solaris_answerbook2:1.4.2 + cpe:/a:sun:solaris_answerbook2:1.4.3 + cpe:/a:sun:solaris_answerbook2:1.4.1 + + CVE-2002-0360 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:49.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4784 + + + XF + sun-answerbook2-gettransbitmap-bo(9117) + + + MISC + http://www.eSecurityOnline.com/advisories/eSO5063.asp + + + VULNWATCH + 20020520 [VulnWatch] eSecurityOnline advisory 5063 - Sun AnswerBook2 gettransbitmap buffer overflow vulnerability + + + BUGTRAQ + 20020520 eSecurityOnline advisory 5063 - Sun AnswerBook2 gettransbitmap buffer overflow vulnerability + + Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program. + + + + + + + + + cpe:/a:aol:instant_messenger:4.2 + + CVE-2002-0362 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:50.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4677 + + + XF + aim-addexternalapp-bo(9017) + + + BUGTRAQ + 20020506 w00w00 on AOL Instant Messenger remote overflow #2 + + Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711. + + + + + + + + + cpe:/a:aladdin_enterprises:ghostscript:6.53 + + CVE-2002-0363 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:50.277-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.ghostscript.com/pipermail/gs-code-review/2002-January/001801.html + + + MISC + http://www.ghostscript.com/pipermail/gs-code-review/2002-February/001900.html + + + BID + 4937 + + + REDHAT + RHSA-2003:209 + + + REDHAT + RHSA-2002:123 + + + REDHAT + RHSA-2002:083 + + + XF + ghostscript-postscript-command-execution(9254) + + + CALDERA + CSSA-2002-026.0 + + ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0364 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T20:01:01.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#313819 + + + MS + MS02-028 + + + BUGTRAQ + 20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612] + + + BID + 4855 + + + XF + iis-htr-chunked-encoding-bo(9327) + + + BUGTRAQ + 20020613 VNA - .HTR HEAP OVERFLOW + + + NTBUGTRAQ + 20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow + + + VULNWATCH + 20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612] + + + + + + + + Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2002-0366 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:27:50.573-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BID + 4852 + + + MS + MS02-029 + + + MISC + http://www.nextgenss.com/vna/ms-ras.txt + + + BUGTRAQ + 20020620 VPN and Q318138 + + + BUGTRAQ + 20020613 Microsoft RASAPI32.DLL + + + + + + + + Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. + + + + + + + + + + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-0367 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:50.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BUGTRAQ + 20020314 Fwd: DebPloit (exploit) + + + XF + win-debug-duplicate-handles(8462) + + + BID + 4287 + + + BUGTRAQ + 20020327 Local Security Vulnerability in Windows NT and Windows 2000 + + + BUGTRAQ + 20020326 Re: DebPloit (exploit) + + + MS + MS02-024 + + + NTBUGTRAQ + 20020314 DebPloit (exploit) + + + + + + + + smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. + + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000:sp2 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:2000:sp1 + + CVE-2002-0368 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T20:01:01.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-025 + + + BID + 4881 + + + XF + exchange-msg-attribute-dos(9195) + + The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources." + + + + + + + + + cpe:/a:microsoft:.net_framework:1.0 + + CVE-2002-0369 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:51.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS02-026 + + + BID + 4958 + + + XF + ms-aspdotnet-stateserver-bo(9276) + + Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ibm:lotus_notes:5.0.9a + cpe:/o:microsoft:windows_me + cpe:/a:verity:keyview_viewing_sdk:gold + cpe:/a:microsoft:windows_98_plus_pack + cpe:/a:ibm:lotus_notes:5.0.2 + cpe:/a:ibm:lotus_notes:5.0.3 + cpe:/a:ibm:lotus_notes:5.0.10 + cpe:/a:ibm:lotus_notes:5.0.4 + cpe:/a:ibm:lotus_notes:5.0.5 + cpe:/a:ibm:lotus_notes:5.0.11 + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/a:ibm:lotus_notes:r5 + cpe:/a:winzip:winzip:7.0 + cpe:/a:allume_systems_division:stuffit_expander:6.5.2 + cpe:/a:ibm:lotus_notes:r6 + cpe:/a:ibm:lotus_notes:4.5 + cpe:/a:ibm:lotus_notes:5.0 + cpe:/a:ibm:lotus_notes:5.0.1 + + CVE-2002-0370 + 2002-10-10T00:00:00.000-04:00 + 2015-01-09T21:59:14.130-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#383779 + + + BID + 5873 + + + MS + MS02-054 + + + XF + win-zip-decompression-bo(10251) + + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + CONFIRM + http://www.info-zip.org/FAQ.html + + + BUGTRAQ + 20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues + + + VULNWATCH + 20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues + + + SREASON + 587 + + Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0. + + + + + + + + + + + + + + + + + + + + cpe:/a:university_of_minnesota:gopher + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:isa_server:2000 + cpe:/a:microsoft:proxy_server:2.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:proxy_server:2.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:isa_server:2000:sp1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0371 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T20:01:02.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#440275 + + + MS + MS02-027 + + + BUGTRAQ + 20020604 Buffer overflow in MSIE gopher code + + + BID + 4930 + + + MISC + http://www.pivx.com/workaround_fail.html + + + XF + ie-gopher-bo(9247) + + + BUGTRAQ + 20020613 Flawed workaround in MS02-027 -- gopher can run on _any_ port, not just 70 + + + BUGTRAQ + 20020613 Microsoft releases critical fix that breaks their own software! + + + + + Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response. + + + + + + + + + + + cpe:/a:microsoft:windows_media_player:xp + cpe:/a:microsoft:windows_media_player:7.1 + cpe:/a:microsoft:windows_media_player:6.4 + + CVE-2002-0372 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T20:01:02.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-032 + + + BID + 5107 + + + XF + mediaplayer-cache-code-execution(9420) + + + + + Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player". + + + + + + + + + cpe:/a:microsoft:windows_media_player:7.1 + + CVE-2002-0373 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:11:51.507-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS02-032 + + + BID + 5109 + + + XF + mediaplayer-wmdm-privilege-elevation(9421) + + The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service". + + + + + + + + + cpe:/a:padl_software:pam_ldap:144 + + CVE-2002-0374 + 2002-05-29T00:00:00.000-04:00 + 2008-09-10T15:11:51.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + VULNWATCH + 20020506 ldap vulnerabilities + + + BID + 4679 + + + REDHAT + RHSA-2002:180 + + + REDHAT + RHSA-2002:175 + + + REDHAT + RHSA-2002:141 + + + REDHAT + RHSA-2002:084 + + + MANDRAKE + MDKSA-2002:075 + + + XF + pamldap-config-format-string(9018) + + + BUGTRAQ + 20021030 GLSA: pam_ldap + + + CALDERA + CSSA-2002-041.0 + + Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name. + + + + + + + + + + + cpe:/a:ecometry:sgdynamo:6.1 + cpe:/a:ecometry:sgdynamo:5.32 + cpe:/a:ecometry:sgdynamo:7.0 + + CVE-2002-0375 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:52.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + sgdynamo-htname-parameter-xss(9830) + + + OSVDB + 3458 + + + VULN-DEV + 20020417 Smalls holes on 5 products #1 + + + BUGTRAQ + 20020510 Fix available for Sgdynamo + + Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter. + + + + + + + + + cpe:/a:apple:quicktime:5.0.2 + + CVE-2002-0376 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:11:51.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ATSTAKE + A091002-1 + + + XF + quicktime-activex-pluginspage-bo(10077) + + + BID + 5685 + + + BUGTRAQ + 20020925 Fwd: QuickTime for Windows ActiveX security advisory + + Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field. + + + + + + + + + cpe:/a:rob_flynn:gaim:0.57 + + CVE-2002-0377 + 2002-05-29T00:00:00.000-04:00 + 2008-09-05T16:27:52.383-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020512 Gaim abritary Email Reading + + + CONFIRM + http://gaim.sourceforge.net/ChangeLog + + + BID + 4730 + + + XF + gaim-email-access(9061) + + + VULN-DEV + 20020511 Gaim abritary Email Reading + + Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files. + + + + + + + + + + cpe:/o:astart_technologies:lprng:3.7.4 + cpe:/o:astart_technologies:lprng:3.8.9 + + CVE-2002-0378 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:11:52.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:089 + + + BID + 4980 + + + MANDRAKE + MDKSA-2002:042 + + + XF + lprng-remote-jobs-dos(9322) + + + HP + HPSBTL0206-048 + + The default configuration of LPRng print spooler in Red Hat Linux 7.0 through 7.3, Mandrake 8.1 and 8.2, and other operating systems, accepts print jobs from arbitrary remote hosts. + + + + + + + + + + + + cpe:/a:university_of_washington:uw-imap:2000.287 + cpe:/a:university_of_washington:uw-imap:2000.315 + cpe:/a:university_of_washington:uw-imap:2000.283 + cpe:/a:university_of_washington:uw-imap:2000.284 + + CVE-2002-0379 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:52.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#961489 + + + BUGTRAQ + 20020510 wu-imap buffer overflow condition + + + XF + wuimapd-authenticated-user-bo(10803) + + + CONFIRM + http://www.washington.edu/imap/buffer.html + + + BID + 4713 + + + REDHAT + RHSA-2002:092 + + + ENGARDE + ESA-20020607-013 + + + MANDRAKE + MDKSA-2002:034 + + + XF + wuimapd-partial-mailbox-bo(9055) + + + HP + HPSBTL0205-043 + + + CONECTIVA + CLA-2002:487 + + + CALDERA + CSSA-2002-021.0 + + Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request. + + + + + + + + + cpe:/a:lbl:tcpdump:3.6.2 + + CVE-2002-0380 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:53.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + tcpdump-nfs-bo(9216) + + + BID + 4890 + + + REDHAT + RHSA-2003:214 + + + REDHAT + RHSA-2002:121 + + + REDHAT + RHSA-2002:094 + + + DEBIAN + DSA-255 + + + HP + HPSBTL0205-044 + + + FREEBSD + FreeBSD-SA-02:29 + + + BUGTRAQ + 20020606 TSLSA-2002-0055 - tcpdump + + + CONECTIVA + CLA-2002:491 + + + CALDERA + CSSA-2002-025.0 + + Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet. + + + + + + + + + + + cpe:/o:netbsd:netbsd:2.0.4 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:openbsd:openbsd + + CVE-2002-0381 + 2002-06-25T00:00:00.000-04:00 + 2008-09-05T16:27:52.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.FreeBSD.org/cgi/query-pr.cgi?pr=35022 + + + BUGTRAQ + 20020317 TCP Connections to a Broadcast Address on BSD-Based Systems + + + BID + 4309 + + + OSVDB + 5308 + + + CONFIRM + http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet/tcp_input.c.diff?r1=1.109&r2=1.110 + + + XF + bsd-broadcast-address(8485) + + + CONFIRM + http://cvsweb.netbsd.org/bsdweb.cgi/syssrc/sys/netinet/tcp_input.c.diff?r1=1.136&r2=1.137 + + + SGI + 20030604-01-I + + The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address. + + + + + + + + + cpe:/a:xchat:xchat:1.89 + + CVE-2002-0382 + 2002-06-25T00:00:00.000-04:00 + 2008-09-10T15:11:53.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020327 Xchat /dns command execution vulnerability + + + BID + 4376 + + + REDHAT + RHSA-2002:124 + + + REDHAT + RHSA-2002:097 + + + MANDRAKE + MDKSA-2002:051 + + + XF + xchat-dns-execute-commands(8704) + + + CONECTIVA + CLA-2002:526 + + XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metacharacters. + + + + + + + + + + + + + + + cpe:/a:rob_flynn:gaim:0.53 + cpe:/a:rob_flynn:gaim:0.52 + cpe:/a:rob_flynn:gaim:0.51 + cpe:/a:rob_flynn:gaim:0.57 + cpe:/a:rob_flynn:gaim:0.56 + cpe:/a:rob_flynn:gaim:0.55 + cpe:/a:rob_flynn:gaim:0.54 + + CVE-2002-0384 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:11:54.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5406 + + + REDHAT + RHSA-2002:098 + + + XF + gaim-jabber-module-bo(9766) + + + REDHAT + RHSA-2003:156 + + + REDHAT + RHSA-2002:122 + + + REDHAT + RHSA-2002:107 + + + OSVDB + 3729 + + + HP + HPSBTL0208-057 + + + MANDRAKE + MDKSA-2002:054 + + Buffer overflow in Jabber plug-in for Gaim client before 0.58 allows remote attackers to execute arbitrary code. + + + + + + + + + + + cpe:/a:vignette:storyserver:6.0 + cpe:/a:vignette:storyserver:4.1 + cpe:/a:vignette:vignette:5.0 + + CVE-2002-0385 + 2004-06-01T00:00:00.000-04:00 + 2008-09-05T16:27:53.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + storyserver-tcl-information-disclosure(11725) + + + BID + 7296 + + + ATSTAKE + A040703-1 + + Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output. + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + + CVE-2002-0386 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:11:54.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A102802-1 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert43rev1.pdf + + + BID + 5902 + + + XF + oracle-appserver-webcachemanager-dos(10284) + + The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data. + + + + + + + + + + cpe:/a:sun:one_application_server:6.5 + cpe:/a:sun:one_application_server:6.0 + + CVE-2002-0387 + 2003-03-18T00:00:00.000-05:00 + 2008-09-05T16:27:53.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 7082 + + + ATSTAKE + A031303-1 + + + XF + sunone-gxnsapi6-bo(11529) + + + CIAC + N-064 + + + SUNALERT + 52022 + + Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL. + + + + + + + + + cpe:/a:gnu:mailman:2.0.11 + + CVE-2002-0388 + 2002-06-18T00:00:00.000-04:00 + 2009-07-21T17:00:55.733-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://mail.python.org/pipermail/mailman-announce/2002-May/000042.html + + + BID + 4826 + + Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries. + + + + + + + + + cpe:/a:gnu:mailman + + CVE-2002-0389 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:27:54.027-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020417 Mailman/Pipermail private mailing list/local user vulnerability + + + BID + 4538 + + + XF + pipermail-view-archives(8874) + + + MISC + http://sourceforge.net/tracker/?func=detail&atid=100103&aid=474616&group_id=103 + + Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives. + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:sun:solaris:2.6 + cpe:/o:freebsd:freebsd:4.6.1:release_p5 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-0391 + 2002-08-12T00:00:00.000-04:00 + 2011-03-07T21:08:10.597-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + CERT + CA-2002-25 + + + CERT-VN + VU#192995 + + + ISS + 20020731 Remote Buffer Overflow Vulnerability in Sun RPC + + + SGI + 20020801-01-P + + + BID + 5356 + + + REDHAT + RHSA-2003:212 + + + REDHAT + RHSA-2003:168 + + + REDHAT + RHSA-2002:173 + + + REDHAT + RHSA-2002:167 + + + MS + MS02-057 + + + MANDRAKE + MDKSA-2002:057 + + + ENGARDE + ESA-20021003-021 + + + XF + sunrpc-xdr-array-bo(9170) + + + DEBIAN + DSA-333 + + + DEBIAN + DSA-149 + + + DEBIAN + DSA-146 + + + DEBIAN + DSA-143 + + + DEBIAN + DSA-142 + + + REDHAT + RHSA-2002:172 + + + REDHAT + RHSA-2002:166 + + + BUGTRAQ + 20020802 kerberos rpc xdr_array + + + HP + HPSBTL0208-061 + + + BUGTRAQ + 20020909 GLSA: glibc + + + BUGTRAQ + 20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin + + + FREEBSD + FreeBSD-SA-02:34.rpc + + + BUGTRAQ + 20020801 RPC analysis + + + BUGTRAQ + 20020731 Remote Buffer Overflow Vulnerability in Sun RPC + + + CONECTIVA + CLA-2002:535 + + + CONECTIVA + CLA-2002:515 + + + HP + HPSBUX0209-215 + + + BUGTRAQ + 20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers + + + AIXAPAR + IY34194 + + + NETBSD + NetBSD-SA2002-011 + + + CALDERA + CSSA-2002-055.0 + + + + + + + + + + + Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.36 + cpe:/a:apache:http_server:2.0.35 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:1.2.5 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.4 + cpe:/a:apache:http_server:1.3.14::mac_os + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.20::win32 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.11::win32 + cpe:/a:apache:http_server:1.3.12::win32 + cpe:/a:apache:http_server:1.0 + cpe:/a:apache:http_server:1.3.13::win32 + cpe:/a:apache:http_server:1.3.14::win32 + cpe:/a:apache:http_server:1.2 + cpe:/a:apache:http_server:1.3.15::win32 + cpe:/a:apache:http_server:1.1 + cpe:/a:apache:http_server:1.3.16::win32 + cpe:/a:apache:http_server:1.3.17::win32 + cpe:/a:apache:http_server:1.3 + cpe:/a:apache:http_server:1.3.18::win32 + cpe:/a:apache:http_server:1.3.19::win32 + cpe:/a:apache:http_server:2.0.28 + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3.24::win32 + cpe:/a:apache:http_server:1.0.2 + cpe:/a:apache:http_server:1.3.22::win32 + cpe:/a:apache:http_server:1.3.23::win32 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.0.5 + cpe:/a:apache:http_server:1.1.1 + cpe:/a:apache:http_server:1.0.3 + + CVE-2002-0392 + 2002-07-03T00:00:00.000-04:00 + 2011-03-07T21:08:10.783-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-17 + + + CERT-VN + VU#944335 + + + HP + SSRT050968 + + + CONFIRM + http://httpd.apache.org/info/security_bulletin_20020617.txt + + + BID + 5033 + + + BID + 20005 + + + REDHAT + RHSA-2003:106 + + + REDHAT + RHSA-2002:150 + + + REDHAT + RHSA-2002:126 + + + OSVDB + 838 + + + SUSE + SuSE-SA:2002:022 + + + ENGARDE + ESA-20020619-014 + + + XF + apache-chunked-encoding-bo(9249) + + + FRSIRT + ADV-2006-3598 + + + DEBIAN + DSA-133 + + + DEBIAN + DSA-132 + + + DEBIAN + DSA-131 + + + REDHAT + RHSA-2002:118 + + + REDHAT + RHSA-2002:117 + + + REDHAT + RHSA-2002:103 + + + BUGTRAQ + 20020621 [SECURITY] Remote exploit for 32-bit Apache HTTP Server known + + + HP + HPSBUX0207-197 + + + HP + HPSBTL0206-049 + + + MANDRAKE + MDKSA-2002:039 + + + CONECTIVA + CLSA-2002:498 + + + BUGTRAQ + 20020621 [slackware-security] new apache/mod_ssl packages available + + + BUGTRAQ + 20020619 [OpenPKG-SA-2002.004] OpenPKG Security Advisory (apache) + + + SGI + 20020605-01-I + + + SGI + 20020605-01-A + + + CALDERA + CSSA-2002-SCO.31 + + + CALDERA + CSSA-2002-SCO.32 + + + CALDERA + CSSA-2002-029.0 + + Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0393 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:54.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-web-dos(9262) + + + BID + 4942 + + Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration password. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0394 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:54.713-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-insecure-passwords(9263) + + Red-M 1050 (Bluetooth Access Point) uses case insensitive passwords, which makes it easier for attackers to conduct a brute force guessing attack due to the smaller space of possible passwords. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0395 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:54.867-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-tftp-bruteforce(9264) + + The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0396 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:55.010-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-insecure-session(9265) + + + BID + 4940 + + The web management server for Red-M 1050 (Bluetooth Access Point) does not use session-based credentials to authenticate users, which allows attackers to connect to the server from the same IP address as a user who has already established a session. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0397 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:55.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-device-existence(9266) + + Red-M 1050 (Bluetooth Access Point) publicizes its name, IP address, and other information in UDP packets to a broadcast address, which allows any system on the network to obtain potentially sensitive information about the Access Point device by monitoring UDP port 8887. + + + + + + + + + cpe:/h:red-m:1050ap_lan_acess_point + + CVE-2002-0398 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:55.307-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + ATSTAKE + A060502-1 + + + XF + redm-1050ap-ppp-dos(9267) + + + BID + 4943 + + Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name. + + + + + + + + + cpe:/a:gnu:tar:1.13.25 + + CVE-2002-0399 + 2002-10-10T00:00:00.000-04:00 + 2010-05-25T00:12:12.657-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:096 + + + ENGARDE + ESA-20021003-022 + + + XF + archive-extraction-directory-traversal(10224) + + + SUNALERT + 1000928 + + + CONFIRM + https://issues.rpath.com/browse/RPL-1631 + + + BID + 5834 + + + BUGTRAQ + 20070827 FLEA-2007-0049-1 tar + + + BUGTRAQ + 20070825 rPSA-2007-0172-1 tar + + + SUSE + SUSE-SR:2007:019 + + + SUSE + SUSE-SR:2006:005 + + + MANDRAKE + MDKSA-2002:066 + + + SUNALERT + 47800 + + + BUGTRAQ + 20020928 GNU tar (Re: Allot Netenforcer problems, GNU TAR flaw) + + + CONECTIVA + CLA-2002:538 + + Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267. + + + + + + + + + + + + + + cpe:/a:isc:bind:9.0 + cpe:/a:isc:bind:9.1 + cpe:/a:isc:bind:9.2 + cpe:/a:isc:bind:9.1.3 + cpe:/a:isc:bind:9.1.2 + cpe:/a:isc:bind:9.1.1 + + CVE-2002-0400 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:55.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#739123 + + + CERT + CA-2002-15 + + + BID + 4936 + + + REDHAT + RHSA-2003:154 + + + REDHAT + RHSA-2002:119 + + + REDHAT + RHSA-2002:105 + + + SUSE + SuSE-SA:2002:021 + + + XF + bind-findtype-dos(9250) + + + CONFIRM + http://www.isc.org/index.pl?/sw/bind/bind-security.php + + + MANDRAKE + MDKSA-2002:038 + + + CONECTIVA + CLA-2002:494 + + + HP + HPSBUX0207-202 + + + CALDERA + CSSA-2002-SCO.24 + + ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype. + + + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + cpe:/a:ethereal_group:ethereal:0.9.3 + cpe:/a:ethereal_group:ethereal:0.9_.0 + + CVE-2002-0401 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:55.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00004.html + + + DEBIAN + DSA-130 + + + BUGTRAQ + 20020529 Potential security issues in Ethereal + + + BID + 4806 + + + REDHAT + RHSA-2002:088 + + + REDHAT + RHSA-2002:036 + + + XF + ethereal-smb-dissector-dos(9204) + + + CONECTIVA + CLSA-2002:505 + + + CALDERA + CSSA-2002-037.0 + + SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer. + + + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + cpe:/a:ethereal_group:ethereal:0.9.3 + cpe:/a:ethereal_group:ethereal:0.9_.0 + + CVE-2002-0402 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:56.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00004.html + + + DEBIAN + DSA-130 + + + BUGTRAQ + 20020529 Potential security issues in Ethereal + + + BID + 4805 + + + REDHAT + RHSA-2002:170 + + + REDHAT + RHSA-2002:088 + + + REDHAT + RHSA-2002:036 + + + XF + ethereal-x11-dissector-bo(9203) + + + CONECTIVA + CLSA-2002:505 + + + CALDERA + CSSA-2002-037.0 + + Buffer overflow in X11 dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code while Ethereal is parsing keysyms. + + + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + cpe:/a:ethereal_group:ethereal:0.9.3 + cpe:/a:ethereal_group:ethereal:0.9_.0 + + CVE-2002-0403 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:56.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00004.html + + + DEBIAN + DSA-130 + + + BUGTRAQ + 20020529 Potential security issues in Ethereal + + + BID + 4807 + + + REDHAT + RHSA-2002:170 + + + REDHAT + RHSA-2002:088 + + + REDHAT + RHSA-2002:036 + + + XF + ethereal-dns-dissector-dos(9205) + + + CONECTIVA + CLSA-2002:505 + + + CALDERA + CSSA-2002-037.0 + + DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop. + + + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + cpe:/a:ethereal_group:ethereal:0.9.3 + cpe:/a:ethereal_group:ethereal:0.9_.0 + + CVE-2002-0404 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:11:56.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00004.html + + + DEBIAN + DSA-130 + + + BUGTRAQ + 20020529 Potential security issues in Ethereal + + + BID + 4808 + + + REDHAT + RHSA-2002:170 + + + REDHAT + RHSA-2002:088 + + + REDHAT + RHSA-2002:036 + + + XF + ethereal-giop-dissector-dos(9206) + + + CONECTIVA + CLSA-2002:505 + + + CALDERA + CSSA-2002-037.0 + + Vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (memory consumption). + + + + + + + + + cpe:/a:transsoft:broker_ftp_server:5.0 + + CVE-2002-0405 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:11:56.243-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + broker-ftp-dot-bo(6673) + + + BUGTRAQ + 20020527 Problems with various windows FTP servers + + + BID + 4864 + + Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters. + + + + + + + + + + cpe:/a:menasoft:sphereserver:0.99i + cpe:/a:menasoft:sphereserver:0.99f + + CVE-2002-0406 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:56.510-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4258 + + + XF + sphereserver-connections-dos(8338) + + + BUGTRAQ + 20020302 Denial of Service in Sphereserver + + Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in. + + + + + + + + + cpe:/a:lotus:domino:5.0.9a + + CVE-2002-0407 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:11:56.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4406 + + + XF + lotus-domino-reveal-information(8160) + + + BUGTRAQ + 20020402 KPMG-2002006: Lotus Domino Physical Path Revealed + + + BUGTRAQ + 20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service + + htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message. + + + + + + + + + cpe:/a:lotus:domino:5.0.9a + + CVE-2002-0408 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:11:56.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4049 + + + BUGTRAQ + 20020303 Re: KPMG-2002006: Lotus Domino Physical Path Revealed + + + BUGTRAQ + 20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service + + htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message. + + + + + + + + + cpe:/a:microsoft:.net_framework:1.0 + + CVE-2002-0409 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:56.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020303 iBuySpy store hole + + orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. + + + + + + + + + + + + + + cpe:/a:aeromail:aeromail:1.26 + cpe:/a:aeromail:aeromail:1.02 + cpe:/a:aeromail:aeromail:1.20 + cpe:/a:aeromail:aeromail:1.40 + cpe:/a:aeromail:aeromail:1.30 + cpe:/a:aeromail:aeromail:1.10 + + CVE-2002-0410 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:27:57.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4214 + + + XF + aeromail-obtain-files(8345) + + + CONFIRM + http://the.cushman.net/projects/aeromail/download/aeromail-1.45.tar.gz + + + MISC + http://the.cushman.net/projects/aeromail/download/ + + + BUGTRAQ + 20020303 AeroMail multiple vulnerabilities + + send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded. + + + + + + + + + + + + + + cpe:/a:aeromail:aeromail:1.26 + cpe:/a:aeromail:aeromail:1.02 + cpe:/a:aeromail:aeromail:1.20 + cpe:/a:aeromail:aeromail:1.40 + cpe:/a:aeromail:aeromail:1.30 + cpe:/a:aeromail:aeromail:1.10 + + CVE-2002-0411 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:57.260-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4215 + + + XF + aeromail-subject-css(8346) + + + CONFIRM + http://the.cushman.net/projects/aeromail/download/aeromail-1.45.tar.gz + + + BUGTRAQ + 20020303 AeroMail multiple vulnerabilities + + Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line. + + + + + + + + + cpe:/a:luca_deri:ntop:2.0 + + CVE-2002-0412 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:57.417-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4225 + + + XF + ntop-traceevent-format-string(8347) + + + BUGTRAQ + 20020411 ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT + + + CONFIRM + http://snapshot.ntop.org/ + + + BUGTRAQ + 20020304 [H20020304]: Remotely exploitable format string vulnerability in ntop + + + MISC + http://listmanager.unipi.it/pipermail/ntop-dev/2002-February/000489.html + + + OSVDB + 5307 + + + BUGTRAQ + 20020417 segfault in ntop + + + BUGTRAQ + 20020411 re: gobbles ntop alert + + + VULNWATCH + 20020304 [VulnWatch] [H20020304]: Remotely exploitable format string vulnerability in ntop + + Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication. + + + + + + + + + cpe:/a:rebb:rebb:1.0 + + CVE-2002-0413 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:57.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4220 + + + XF + rebb-img-css(8353) + + + BUGTRAQ + 20020304 ReBB javascripts vulnerability + + Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script. + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + + CVE-2002-0414 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:57.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4224 + + + XF + kame-forged-packet-forwarding(8416) + + + BUGTRAQ + 20020304 BSD: IPv4 forwarding doesn't consult inbound SPD in KAME-derived IPsec + + + CONFIRM + http://orange.kame.net/dev/cvsweb.cgi/kame/CHANGELOG + + + OSVDB + 5304 + + + VULNWATCH + 20020304 [VulnWatch] BSD: IPv4 forwarding doesn't consult inbound SPD in KAME-derived IPsec + + KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets. + + + + + + + + + cpe:/a:realnetworks:realplayer:6.0 + + CVE-2002-0415 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:57.900-04:00 + + + 1.7 + LOCAL + LOW + SINGLE_INSTANCE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4221 + + + BUGTRAQ + 20020302 RealPlayer bug + + + XF + realplayer-http-directory-traversal(8336) + + Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275. + + + + + + + + + cpe:/a:sh39:mailserver:1.2.1 + + CVE-2002-0416 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:58.117-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4232 + + + XF + sh39-mailserver-dos(8379) + + + BUGTRAQ + 20020305 Buffer Overflows in sh39.com + + Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:endymion:mailman_webmail:3.0.33 + cpe:/a:endymion:mailman_webmail:3.0.32 + cpe:/a:endymion:mailman_webmail:3.0.35 + cpe:/a:endymion:mailman_webmail:3.0.34 + cpe:/a:endymion:mailman_webmail:3.0.14 + cpe:/a:endymion:mailman_webmail:3.0.15 + cpe:/a:endymion:mailman_webmail:3.0.16 + cpe:/a:endymion:mailman_webmail:3.0 + cpe:/a:endymion:mailman_webmail:3.0.10 + cpe:/a:endymion:mailman_webmail:3.0.11 + cpe:/a:endymion:mailman_webmail:3.0.12 + cpe:/a:endymion:mailman_webmail:3.0.31 + cpe:/a:endymion:mailman_webmail:3.0.13 + cpe:/a:endymion:mailman_webmail:3.0.30 + cpe:/a:endymion:mailman_webmail:3.0.29 + cpe:/a:endymion:mailman_webmail:3.0.20 + cpe:/a:endymion:mailman_webmail:3.0.27 + cpe:/a:endymion:mailman_webmail:3.0.28 + cpe:/a:endymion:mailman_webmail:3.0.26 + cpe:/a:endymion:mailman_webmail:3.0.23 + cpe:/a:endymion:mailman_webmail:3.0.24 + cpe:/a:endymion:mailman_webmail:3.0.21 + cpe:/a:endymion:mailman_webmail:3.0.22 + cpe:/a:endymion:mailman_webmail:3.0.4 + cpe:/a:endymion:mailman_webmail:3.0.1 + cpe:/a:endymion:mailman_webmail:3.0.2 + cpe:/a:endymion:mailman_webmail:3.0.7 + cpe:/a:endymion:mailman_webmail:3.0.8 + cpe:/a:endymion:mailman_webmail:3.0.19 + cpe:/a:endymion:mailman_webmail:3.0.6 + cpe:/a:endymion:mailman_webmail:3.0.18 + + CVE-2002-0417 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:58.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4222 + + + XF + mailman-alternate-templates-traversal(8357) + + + CONFIRM + http://www.endymion.com/products/mailman/history.htm + + + BUGTRAQ + 20020305 Endymion SakeMail and MailMan File Disclosure Vulnerability + + Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:endymion:sake_mail:1.0.29 + cpe:/a:endymion:sake_mail:1.0.28 + cpe:/a:endymion:sake_mail:1.0.30 + cpe:/a:endymion:sake_mail:1.0.22 + cpe:/a:endymion:sake_mail:1.0.31 + cpe:/a:endymion:sake_mail:1.0.23 + cpe:/a:endymion:sake_mail:1.0.20 + cpe:/a:endymion:sake_mail:1.0.33 + cpe:/a:endymion:sake_mail:1.0.34 + cpe:/a:endymion:sake_mail:1.0.21 + cpe:/a:endymion:sake_mail:1.0.35 + cpe:/a:endymion:sake_mail:1.0.26 + cpe:/a:endymion:sake_mail:1.0.36 + cpe:/a:endymion:sake_mail:1.0.27 + cpe:/a:endymion:sake_mail:1.0.24 + + CVE-2002-0418 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:58.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4223 + + + XF + sakemail-paramname-directory-traversal(8358) + + + BUGTRAQ + 20020305 Endymion SakeMail and MailMan File Disclosure Vulnerability + + Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the param_name parameter. + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:internet_information_server:4.0:alpha + + CVE-2002-0419 + 2002-08-12T00:00:00.000-04:00 + 2013-06-06T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4235 + + + XF + iis-authentication-error-messages(8382) + + + BUGTRAQ + 20020305 Considerations for IIS Authentication (#NISR05032002C) + + Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server. + + + + + + + + + cpe:/a:claymore_systems_inc:puretls:0.9b1 + + CVE-2002-0420 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:58.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4237 + + + XF + puretls-injection-attack(8386) + + + BUGTRAQ + 20020305 PureTLS Security Announcement: Upgrade to 0.9b2 + + Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions. + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + + CVE-2002-0421 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:58.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4236 + + + XF + winnt-pw-policy-bypass(8388) + + + BUGTRAQ + 20020306 NT user (who is locked changing his/her password by administrator ) can bypass the security policy and Change the password. + + IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + + CVE-2002-0422 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.167-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + NTBUGTRAQ + 20020305 IIS Internal IP Address Disclosure (#NISR05032002B) + + + BUGTRAQ + 20020305 IIS Internal IP Address Disclosure (#NISR05032002B) + + + OSVDB + 13431 + + + XF + iis-request-ip-disclosure(8385) + + IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header. + + + + + + + + + + cpe:/a:efingerd:efingerd:1.6.1 + cpe:/a:efingerd:efingerd:1.3 + + CVE-2002-0423 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.320-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + efingerd-reverse-lookup-bo(8380) + + + BID + 4239 + + + CONFIRM + http://melkor.dnp.fmph.uniba.sk/~garabik/efingerd/efingerd_1.5.tar.gz + + + BUGTRAQ + 20020306 efingerd remote buffer overflow and a dangerous feature + + Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup. + + + + + + + + + + cpe:/a:efingerd:efingerd:1.6.1 + cpe:/a:efingerd:efingerd:1.3 + + CVE-2002-0424 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + efingerd-file-execution(8381) + + + BID + 4240 + + + CONFIRM + http://melkor.dnp.fmph.uniba.sk/~garabik/efingerd/efingerd_1.6.2.tar.gz + + + BUGTRAQ + 20020306 efingerd remote buffer overflow and a dangerous feature + + efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger. + + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc:6.0 + cpe:/a:khaled_mardam-bey:mirc:6.0_1 + + CVE-2002-0425 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4247 + + + XF + mirc-dcc-reveal-info(8393) + + + BUGTRAQ + 20020306 mIRC DCC Server Security Flaw + + + OSVDB + 5301 + + mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message. + + + + + + + + + cpe:/h:linksys:befvp41:1.40.1 + + CVE-2002-0426 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4250 + + + XF + linksys-etherfast-weak-encryption(8397) + + + BUGTRAQ + 20020308 Linksys BEFVP41 VPN Server does not follow proper VPN standards + + + MISC + ftp://ftp.linksys.com/pub/befsr41/befvp41-1402.zip + + VPN Server module in Linksys EtherFast BEFVP41 Cable/DSL VPN Router before 1.40.1 reduces the key lengths for keys that are supplied via manual key entry, which makes it easier for attackers to crack the keys. + + + + + + + + + + + + cpe:/a:christof_pohl:improved_mod_frontpage:1.5.1 + cpe:/a:christof_pohl:improved_mod_frontpage:1.3.2 + cpe:/a:christof_pohl:improved_mod_frontpage:1.5 + cpe:/a:christof_pohl:improved_mod_frontpage:1.4.1 + + CVE-2002-0427 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:27:59.930-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4251 + + + XF + apache-modfrontpage-bo(8400) + + + MANDRAKE + MDKSA-2002:021 + + + FREEBSD + FreeBSD-SA-02:17 + + Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:checkpoint:next_generation + cpe:/a:checkpoint:firewall-1:4.0:sp2 + cpe:/a:checkpoint:firewall-1:4.1:sp2 + cpe:/a:checkpoint:firewall-1:4.0:sp1 + cpe:/a:checkpoint:firewall-1:4.1:sp1 + cpe:/a:checkpoint:firewall-1:4.0:sp4 + cpe:/a:checkpoint:firewall-1:4.1:sp4 + cpe:/a:checkpoint:firewall-1:4.0:sp3 + cpe:/a:checkpoint:firewall-1:4.0:sp6 + cpe:/a:checkpoint:firewall-1:4.0:sp5 + cpe:/a:checkpoint:firewall-1:4.1:sp5 + cpe:/a:checkpoint:firewall-1:4.0:sp8 + cpe:/a:checkpoint:firewall-1:4.0:sp7 + cpe:/a:checkpoint:check_point_vpn:1_4.1 + cpe:/a:checkpoint:firewall-1:4.1 + cpe:/a:checkpoint:firewall-1:4.0 + cpe:/a:checkpoint:check_point_vpn:1_4.1_sp1 + cpe:/a:checkpoint:firewall-1:4.1:sp3 + cpe:/a:checkpoint:check_point_vpn:1_4.1_sp2 + cpe:/a:checkpoint:check_point_vpn:1_4.1_sp3 + cpe:/a:checkpoint:check_point_vpn:1_4.1_sp4 + + CVE-2002-0428 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:00.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4253 + + + XF + fw1-authentication-bypass-timeouts(8423) + + + BUGTRAQ + 20020308 Checkpoint FW1 SecuRemote/SecureClient "re-authentication" (client side hacks of users.C) + + Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file. + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18::x86 + + CVE-2002-0429 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:01.163-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.openwall.com/linux/ + + + BUGTRAQ + 20020308 linux <=2.4.18 x86 traps.c problem + + + BID + 4259 + + + REDHAT + RHSA-2002:158 + + + XF + linux-ibcs-lcall-process(8420) + + + DEBIAN + DSA-442 + + + DEBIAN + DSA-336 + + + DEBIAN + DSA-332 + + + DEBIAN + DSA-312 + + + DEBIAN + DSA-311 + + The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall). + + + + + + + + + + + cpe:/h:sun:cobalt_raq_4 + cpe:/h:sun:cobalt_raq_2 + cpe:/h:sun:cobalt_raq_3i + + CVE-2002-0430 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:01.227-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4252 + + + BUGTRAQ + 20020308 Remote Cobalt Raq XTR vulns + + MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php. + + + + + + + + + cpe:/a:dave_lawrence:xtux:2001-06-01 + + CVE-2002-0431 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:00.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4260 + + + XF + xtux-server-dos(8422) + + + BUGTRAQ + 20020309 xtux server DoS. + + + MISC + https://sourceforge.net/tracker/index.php?func=detail&aid=529046&group_id=206&atid=100206 + + XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection. + + + + + + + + + cpe:/a:citadel:ux:5.90 + + CVE-2002-0432 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:00.760-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4263 + + + XF + citadel-helo-bo(8426) + + + CONFIRM + http://uncensored.citadel.org/pub/citadel/citadel-ux-5.91.tar.gz + + + BUGTRAQ + 20020309 Citadel/UX Server Remote DoS attack Vulnerability + + Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server. + + + + + + + + + cpe:/a:pi3:pi3web:2.0.0 + + CVE-2002-0433 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:00.917-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4262 + + + XF + pi3web-asterisk-view-files(8429) + + + BUGTRAQ + 20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln + + Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character. + + + + + + + + + cpe:/a:marcus_s._xenakis:directory.php + + CVE-2002-0434 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:01.070-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4278 + + + BUGTRAQ + 20020310 Marcus S. Xenakis "directory.php" allows arbitrary code execution + + + XF + xenakis-directory-execute-commands(8440) + + Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter. + + + + + + + + + + + cpe:/a:gnu:fileutils:4.1 + cpe:/a:gnu:fileutils:4.0 + cpe:/a:gnu:fileutils:4.1.6 + + CVE-2002-0435 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:01.213-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4266 + + + XF + gnu-fileutils-race-condition(8432) + + + CALDERA + CSSA-2002-018.1 + + + BUGTRAQ + 20020310 GNU fileutils - recursive directory removal race condition + + + CONFIRM + http://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.html + + + REDHAT + RHSA-2003:016 + + + REDHAT + RHSA-2003:015 + + + MANDRAKE + MDKSA-2002:031 + + Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system. + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-0436 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:01.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4269 + + + BUGTRAQ + 20020311 SunSolve CD cgi scripts... + + + XF + sunsolve-cd-command-execution(8435) + + sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter. + + + + + + + + + + cpe:/a:stefan_frings:sms_server_tools:1.4.7 + cpe:/a:stefan_frings:sms_server_tools:1.4.6 + + CVE-2002-0437 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:01.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4268 + + + XF + sms-tools-format-string(8433) + + + CONFIRM + http://www.isis.de/members/~s.frings/smstools/history.html + + + BUGTRAQ + 20020311 SMStools vulnerabilities in release before 1.4.8 + + Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources. + + + + + + + + + + + + + + cpe:/h:zyxel:zywall10:3.50_wa1 + cpe:/h:zyxel:zywall10:3.20_wa1 + cpe:/h:zyxel:zywall10:3.24_wa0 + cpe:/h:zyxel:zywall10:3.24_wa1 + cpe:/h:zyxel:zywall10:3.24_wa2 + cpe:/h:zyxel:zywall10:3.20_wa0 + + CVE-2002-0438 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:12:03.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4272 + + + BUGTRAQ + 20020311 ZyXEL ZyWALL10 DoS + + + XF + zyxel-zywall10-arp-dos(8436) + + + VULNWATCH + 20020312 [VulnWatch] ZyXEL ZyWALL10 DoS + + + MISC + ftp://ftp.zyxel.com/public/zywall10/firmware/zywall10_V3.50(WA.2)C0_Standard.zip + + ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface. + + + + + + + + + cpe:/a:caupo.net:cauposhop:1.30a + + CVE-2002-0439 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:01.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4270 + + + XF + cauposhop-user-info-css(8431) + + + BUGTRAQ + 20020311 CaupoShop: cross-site-scripting bug + + Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.6 + cpe:/a:trend_micro:interscan_viruswall:3.51 + + CVE-2002-0440 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:12:04.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4265 + + + XF + interscan-viruswall-http-proxy-bypass(8425) + + + MISC + http://www.inside-security.de/vwall_cl0.html + + + BUGTRAQ + 20020311 VirusWall HTTP proxy content scanning circumvention + + Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients. + + + + + + + + + + + cpe:/a:jerrett_taylor:php_imglist:1.2 + cpe:/a:jerrett_taylor:php_imglist:1.1 + cpe:/a:jerrett_taylor:php_imglist:1.2.1 + + CVE-2002-0441 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4276 + + + XF + phpimglist-dot-directory-traversal(8441) + + + BUGTRAQ + 20020311 Directory traversal vulnerability in phpimglist + + + CONFIRM + http://www.liquidpulse.net/get.lp?id=17 + + Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a .. (dot dot) in the cwd parameter. + + + + + + + + + + cpe:/a:caldera:openserver:5.0.5 + cpe:/a:caldera:openserver:5.0.6 + + CVE-2002-0442 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.290-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4273 + + + XF + openserver-dlvraudit-bo(8442) + + + CALDERA + CSSA-2002-SCO.8 + + Buffer overflow in dlvr_audit for Caldera OpenServer 5.0.5 and 5.0.6 allows local users to gain root privileges. + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2002-0443 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.447-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4256 + + + XF + win2k-password-bypass-policy(8402) + + + BUGTRAQ + 20020307 Windows 2000 password policy bypass possibility + + Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords. + + + + + + + + + + + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000_terminal_services + + CVE-2002-0444 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.633-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4464 + + + BUGTRAQ + 20020408 Vulnerability: Windows2000Server running Terminalservices + + + XF + win2k-terminal-bypass-policies(8813) + + Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies. + + + + + + + + + cpe:/a:php_firstpost:php_firstpost:0.1 + + CVE-2002-0445 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4274 + + + BUGTRAQ + 20020312 [ARL02-A05] PHP FirstPost System Information Path Disclosure Vulnerability + + + XF + phpfirstpost-path-disclosure(8434) + + + OSVDB + 7170 + + article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message. + + + + + + + + + + + cpe:/a:black_tie_project:black_tie_project:0.5b + cpe:/a:black_tie_project:black_tie_project:0.5 + cpe:/a:black_tie_project:black_tie_project:0.4b + + CVE-2002-0446 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:02.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + btp-cid-path-disclosure(8439) + + + BID + 4275 + + categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message. + + + + + + + + + cpe:/a:xerver:xerver:2.10 + + CVE-2002-0447 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:03.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4255 + + + XF + xerver-dot-directory-traversal(8421) + + + BUGTRAQ + 20020312 Xerver Free Web Server 2.10 file Disclosure & DoS PATCH (update version) + + + BUGTRAQ + 20020308 Xerver-2.10-File-Disclousure&DoS-attack + + Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request. + + + + + + + + + cpe:/a:xerver:xerver:2.10 + + CVE-2002-0448 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:03.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4254 + + + XF + xerver-multiple-request-dos(8419) + + + BUGTRAQ + 20020312 Xerver Free Web Server 2.10 file Disclosure & DoS PATCH (update version) + + + BUGTRAQ + 20020308 Xerver-2.10-File-Disclousure&DoS-attack + + Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. + + + + + + + + + + cpe:/a:talentsoft:web%2b_server:5.0 + cpe:/a:talentsoft:web%2b_server:4.6 + + CVE-2002-0449 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:03.353-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#159907 + + + BID + 4233 + + + XF + webplus-webpsvc-bo(8361) + + + CONFIRM + http://www.talentsoft.com/Issues/IssueDetail.wml?ID=WP943 + + + BUGTRAQ + 20020305 Buffer Overrun in Talentsoft's Web+ (#NISR01032002A) + + Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe. + + + + + + + + + + cpe:/a:talentsoft:web%2b_server:5.0 + cpe:/a:talentsoft:web%2b_server:4.6 + + CVE-2002-0450 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:12:16.930-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4282 + + + CONFIRM + http://www.talentsoft.com/Issues/IssueDetail.wml?ID=WP943 + + + XF + webplus-wml-bo(8446) + + + BUGTRAQ + 20020313 2nd Buffer Overflow in Talentsoft's Web+ (#NISR13032002) + + Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe. + + + + + + + + + + cpe:/a:phpprojekt:phpprojekt:3.1a + cpe:/a:phpprojekt:phpprojekt:3.1 + + CVE-2002-0451 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:03.667-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4284 + + + XF + phpprojekt-filemanager-include-files(8448) + + + BUGTRAQ + 20020313 Command execution in phprojekt. + + + CONFIRM + http://www.phprojekt.com/modules.php?op=modload&name=News&file=article&sid=19&mode=&order= + + filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter. + + + + + + + + + + + + + + + cpe:/a:foundrynet:serveriron:7.1.09 + cpe:/a:foundrynet:serveriron:6.0 + cpe:/a:foundrynet:serveriron:xl + cpe:/a:foundrynet:serveriron:xl_g + cpe:/a:foundrynet:serveriron:800 + cpe:/a:foundrynet:serveriron:5.1.10t12 + cpe:/a:foundrynet:serveriron:400 + + CVE-2002-0452 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:03.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + foundry-serveriron-reveal-source(8459) + + + BID + 4286 + + + BUGTRAQ + 20020313 Foundry Networks ServerIron don't decode URIs + + Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible. + + + + + + + + + cpe:/a:oblix:netpoint:5.2 + + CVE-2002-0453 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4288 + + + XF + netpoint-account-lockout-bypass(8461) + + + BUGTRAQ + 20020314 Account Lockout Vulnerability in Oblix NetPoint v5.2 + + The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again. + + + + + + + + + + + + cpe:/a:qualcomm:qpopper:4.0 + cpe:/a:qualcomm:qpopper:4.0.1 + cpe:/a:qualcomm:qpopper:4.0.3 + cpe:/a:qualcomm:qpopper:4.0.2 + + CVE-2002-0454 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4295 + + + BUGTRAQ + 20020315 Bug in QPopper (All Versions?) + + + XF + qpopper-qpopper-dos(8458) + + + CONFIRM + ftp://ftp.qualcomm.com/eudora/servers/unix/popper/qpopper4.0.4.tar.gz + + Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop. + + + + + + + + + + + cpe:/a:incredimail:incredimail:build_618 + cpe:/a:incredimail:incredimail:build_1400185 + cpe:/a:incredimail:incredimail:build_560 + + CVE-2002-0455 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4297 + + + BUGTRAQ + 20020315 MSIE vulnerability exploitable with IncrediMail + + + XF + incredimail-insecure-attachment-directory(8460) + + IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames. + + + + + + + + + cpe:/a:qualcomm:eudora:5.1 + + CVE-2002-0456 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4306 + + + BUGTRAQ + 20020316 MSIE vulnerability exploitable with Eudora (was: IncrediMail) + + + XF + eudora-insecure-attachment-directory(8487) + + + BUGTRAQ + 20020315 RE: MSIE vulnerability exploitable with IncrediMail + + Eudora 5.1 and earlier versions stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames. + + + + + + + + + cpe:/a:bg_guestbook:bg_guestbook:1.0 + + CVE-2002-0457 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.587-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4308 + + + XF + bgguestbook-post-css(8474) + + + BUGTRAQ + 20020316 [ARL02-A08] BG Guestbook Cross Site Scripting Vulnerability + + Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as &lt;, &gt;, and &amp; in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message. + + + + + + + + + cpe:/a:linux-sottises:news-tnk:1.2.2 + + CVE-2002-0458 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.743-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + newstnk-web-css(8477) + + + BUGTRAQ + 20020316 [ARL02-A10] News-TNK Cross Site Scripting Vulnerability + + + BID + 14145 + + + CONFIRM + http://www.linux-sottises.net/software/news-tnk/CHANGES + + + CONFIRM + http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools + + Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. + + + + + + + + + + cpe:/a:linux-sottises:news-tnk:1.2.1 + cpe:/a:linux-sottises:board-tnk:1.3 + + CVE-2002-0459 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:04.900-04:00 + + + 7.6 + NETWORK + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4305 + + + XF + boardtnk-web-css(8475) + + + BUGTRAQ + 20020316 [ARL02-A09] Board-TNK Cross Site Scripting Vulnerability + + + CONFIRM + http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools + + Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. + + + + + + + + + cpe:/a:bitvise:winsshd:1.1 + + CVE-2002-0460 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4300 + + + XF + winsshd-incomplete-connection-dos(8470) + + + BUGTRAQ + 20020318 KPMG-2002005: BitVise WinSSH Denial of Service + + + VULNWATCH + 20020318 [VulnWatch] KPMG-2002005: BitVise WinSSH Denial of Service + + Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0461 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4322 + + + XF + ie-javascript-dos(8488) + + + BUGTRAQ + 20020318 Javascript loop causes IE to crash + + Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop. + + + + + + + + + cpe:/a:big_sam:big_sam:1.1.08 + + CVE-2002-0462 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.353-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4312 + + + XF + bigsam-safemode-path-disclosure(8479) + + + XF + bigsam-displaybegin-dos(8478) + + + BUGTRAQ + 20020318 [ARL02-A11] Big Sam (Built-In Guestbook Stand-Alone Module) Multiple Vulnerabilities + + + CONFIRM + http://www.gezzed.net/bigsam/bigsam.1_1_12.php.txt + + + OSVDB + 5288 + + + OSVDB + 5287 + + bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled. + + + + + + + + + + cpe:/a:arsc_really_simple_chat:arsc_really_simple_chat:1.0 + cpe:/a:arsc_really_simple_chat:arsc_really_simple_chat:1.0.1 + + CVE-2002-0463 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4307 + + + BUGTRAQ + 20020319 Re: [ARL02-A07] ARSC Really Simple Chat System Information Path Disclosure Vulnerability + + + BUGTRAQ + 20020316 [ARL02-A07] ARSC Really Simple Chat System Information Path Disclosure Vulnerability + + + XF + arsc-language-path-disclosure(8472) + + home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message. + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + + CVE-2002-0464 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.650-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4311 + + + BUGTRAQ + 20020318 Hosting Directory Traversal madness... + + + CONFIRM + http://www.hostingcontroller.com/english/patches/ForAll/download/dot-slash.zip + + Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp. + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + + CVE-2002-0465 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + hosting-controller-dot-directory-traversal(7824) + + + BID + 3811 + + + CONFIRM + http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip + + + BUGTRAQ + 20020105 Hosting Controller's - Multiple Security Vulnerabilities + + Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter. + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + + CVE-2002-0466 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:05.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + hosting-controller-directory-browsing(7823) + + + BID + 3808 + + + CONFIRM + http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip + + + BUGTRAQ + 20020105 Hosting Controller's - Multiple Security Vulnerabilities + + Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp. + + + + + + + + + + + + cpe:/a:listar:listar:0.127a + cpe:/a:listar:listar:0.129a + cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-01-21 + cpe:/a:listar:listar:0.126a + + CVE-2002-0467 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:06.103-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4176 + + + XF + ecartis-mystring-bo(8284) + + + BUGTRAQ + 20020310 Ecartis/Listar multiple vulnerabilities + + + CONFIRM + http://www.ecartis.org/ + + + DEBIAN + DSA-123 + + + VULNWATCH + 20020311 [VulnWatch] Ecartis/Listar multiple vulnerabilities + + Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c. + + + + + + + + + + + + + cpe:/a:listar:listar:0.127a + cpe:/a:listar:listar:0.129a + cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-01-21 + cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-01-25 + cpe:/a:listar:listar:0.126a + + CVE-2002-0468 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:06.257-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4271 + + + BUGTRAQ + 20020310 Ecartis/Listar multiple vulnerabilities + + + XF + ecartis-local-bo(8445) + + + CONFIRM + http://www.ecartis.org/ + + + VULN-DEV + 20020227 listar / ecaris remote or local? + + + BUGTRAQ + 20020427 Response to KF about Listar/Ecartis Vulnerability + + + BUGTRAQ + 20020425 ecartis / listar PoC + + + MISC + http://marc.theaimsgroup.com/?l=listar-support&m=101590272221720&w=2 + + Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files. + + + + + + + + + + + + + cpe:/a:listar:listar:0.127a + cpe:/a:listar:listar:0.129a + cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-01-21 + cpe:/a:ecartis:ecartis:1.0.0_snapshot_2002-01-25 + cpe:/a:listar:listar:0.126a + + CVE-2002-0469 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:06.413-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4277 + + + BUGTRAQ + 20020310 Ecartis/Listar multiple vulnerabilities + + + XF + ecartis-root-privileges(8444) + + + VULNWATCH + 20020311 [VulnWatch] Ecartis/Listar multiple vulnerabilities + + Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges. + + + + + + + + + cpe:/a:phpnettoolpack:phpnettoolpack:0.1 + + CVE-2002-0470 + 2002-08-12T00:00:00.000-04:00 + 2008-09-24T00:13:01.843-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4304 + + + XF + phpnettoolpack-traceroute-insecure-path(8484) + + + BUGTRAQ + 20020318 PHP Net Toolpack: input validation error + + PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path. + + + + + + + + + cpe:/a:phpnettoolpack:phpnettoolpack:0.1 + + CVE-2002-0471 + 2002-08-12T00:00:00.000-04:00 + 2008-09-24T00:13:01.967-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4303 + + + XF + phpnettoolpack-traceroute-command-execution(8482) + + + BUGTRAQ + 20020318 PHP Net Toolpack: input validation error + + PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable. + + + + + + + + + cpe:/a:microsoft:msn_messenger:3.6 + + CVE-2002-0472 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:06.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4316 + + + BUGTRAQ + 20020319 Potential vulnerabilities of the Microsoft RVP-based Instant Messaging + + + XF + msn-messenger-message-spoofing(8582) + + + MISC + http://www.encode-sec.com/esp0202.pdf + + MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users. + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0_beta1 + cpe:/a:phpbb_group:phpbb:2.0_rc2 + cpe:/a:phpbb_group:phpbb:2.0_rc3 + cpe:/a:phpbb_group:phpbb:2.0_rc1 + + CVE-2002-0473 + 2002-08-12T00:00:00.000-04:00 + 2013-07-16T10:20:55.113-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4380 + + + OSVDB + 4268 + + + XF + phpbb-db-command-execution(8476) + + + CONFIRM + http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.1.zip + + + MISC + http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9483 + + + VULN-DEV + 20020318 phpBB2 remote execution command + + + BUGTRAQ + 20020318 phpBB2 remote execution command + + + BUGTRAQ + 20020318 Re: phpBB2 remote execution command (fwd) + + db.php in phBB 2.0 (aka phBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter. + + + + + + + + + cpe:/a:zeroforum:zeroforum:1.0 + + CVE-2002-0474 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.210-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4394 + + + BUGTRAQ + 20020329 Re:[Advisory] phpBB 1.4.4 still suffers from Cross Site Scripting Vulnerability + + + XF + zeroforum-img-css(8702) + + Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag. + + + + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:1.2.0 + cpe:/a:phpbb_group:phpbb:1.2.1 + cpe:/a:phpbb_group:phpbb:1.4.4 + cpe:/a:phpbb_group:phpbb:1.4.2 + cpe:/a:phpbb_group:phpbb:1.4.1 + cpe:/a:phpbb_group:phpbb:1.0.0 + cpe:/a:phpbb_group:phpbb:1.4.0 + + CVE-2002-0475 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.353-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4379 + + + MISC + http://www.securiteam.com/unixfocus/6W00Q202UM.html + + + XF + phpbb-cross-site-scripting(7459) + + Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message. + + + + + + + + + cpe:/a:macromedia:flash_player:5.0 + + CVE-2002-0476 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4320 + + + XF + flash-fscommand-save(8584) + + + BUGTRAQ + 20020319 More SWF vulnerabilities? + + + CONFIRM + http://www.macromedia.com/support/flash/ts/documents/fs_save.htm + + Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand. + + + + + + + + + cpe:/a:macromedia:flash_player:5.0 + + CVE-2002-0477 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4321 + + + XF + flash-fscommand-exec(8587) + + + BUGTRAQ + 20020319 More SWF vulnerabilities? + + + CONFIRM + http://www.macromedia.com/support/flash/ts/documents/swf_clear.htm + + + CONFIRM + http://www.macromedia.com/support/flash/ts/documents/standalone_update.htm + + + BUGTRAQ + 20020109 Shockwave Flash player issue + + Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand. + + + + + + + + + cpe:/a:foundrynet:edgeiron:4802f + + CVE-2002-0478 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4330 + + + XF + edgelron-default-snmp-string(8592) + + + BUGTRAQ + 20020320 Default SNMP configuration issue with Foundry Networks EdgeIron 4802F + + The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings. + + + + + + + + + + + cpe:/a:gravity_storm_software:service_pack_manager_2000:6.3 + cpe:/a:gravity_storm_software:service_pack_manager_2000:6.1 + cpe:/a:gravity_storm_software:service_pack_manager_2000:6.0 + + CVE-2002-0479 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:07.977-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sp-manager-insecure-directories(8607) + + + BID + 4347 + + + BUGTRAQ + 20020320 Gravity Storm Service Pack Manager 2000 Share Vulnerability + + Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share. + + + + + + + + + cpe:/a:iss:realsecure_nokia:6.0 + + CVE-2002-0480 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:21.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020322 RE: NMRC Advisory: RealSecure KeyManager Issue - Further Explanation + + + BUGTRAQ + 20020320 NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances + + + BID + 4331 + + + BUGTRAQ + 20020321 RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances + + ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation. + + + + + + + + + cpe:/a:microsoft:outlook:2002 + + CVE-2002-0481 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:08.353-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4340 + + + XF + outlook-iframe-javascript(8604) + + + BUGTRAQ + 20020321 How Outlook 2002 can still execute JavaScript in an HTML email message + + An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function. + + + + + + + + + + cpe:/a:newlog:netsupport_manager:5.5 + cpe:/a:newlog:netsupport_manager:6.10 + + CVE-2002-0482 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:08.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4348 + + + XF + netsupport-manager-directory-traversal(8610) + + + BUGTRAQ + 20020321 Webtraversal in PCI Netsupport Manager (all version up to 7 using web extensions) + + Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request. + + + + + + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.2 + cpe:/a:francisco_burzi:php-nuke:5.1 + cpe:/a:francisco_burzi:php-nuke:5.0 + cpe:/a:francisco_burzi:php-nuke:5.0.1 + cpe:/a:francisco_burzi:php-nuke:5.3.1 + cpe:/a:francisco_burzi:php-nuke:5.4 + cpe:/a:francisco_burzi:php-nuke:5.2a + + CVE-2002-0483 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:08.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4333 + + + XF + phpnuke-index-path-disclosure(8618) + + + BUGTRAQ + 20020320 Fw: PHPNuke 5.4 Path Disclosure Vulnerability? + + index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0.7:rc3 + cpe:/a:php:php:4.0.1:patch1 + cpe:/a:php:php:4.0.7:rc1 + cpe:/a:php:php:4.0.7:rc2 + cpe:/a:php:php:4.0 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.3:patch1 + cpe:/a:php:php:4.0.2 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:3.0 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:3.0.16 + cpe:/a:php:php:3.0.17 + cpe:/a:php:php:3.0.14 + cpe:/a:php:php:3.0.15 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2002-0484 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:08.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020321 Re: move_uploaded_file breaks safe_mode restrictions in PHP + + + BUGTRAQ + 20020317 move_uploaded_file breaks safe_mode restrictions in PHP + + + CONFIRM + http://bugs.php.net/bug.php?id=16128 + + + BID + 4325 + + + XF + php-moveuploadedfile-create-files(8591) + + + BUGTRAQ + 20020322 Re: move_uploaded_file breaks safe_mode restrictions in PHP + + move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system. + + + + + + + + + cpe:/a:symantec:norton_antivirus + + CVE-2002-0485 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULN-DEV + 20020322 One more way to bypass NAV + + + BUGTRAQ + 20020322 One more way to bypass NAV + + Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. + + + + + + + + + + cpe:/a:workforceroi:xpede:7.0 + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0486 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4344 + + + BUGTRAQ + 20020322 Xpede passwords exposed (2 vuln.) + + Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. + + + + + + + + + + cpe:/a:workforceroi:xpede:7.0 + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0487 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.353-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4346 + + + BUGTRAQ + 20020322 Xpede passwords exposed (2 vuln.) + + + XF + xpede-reauth-plaintext-password(8612) + + Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache. + + + + + + + + + cpe:/a:linux_directory_penguin:linux_directory_penguin_traceroute:1.0 + + CVE-2002-0488 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4332 + + + XF + penguin-traceroute-command-execution(8600) + + + BUGTRAQ + 20020321 PHP script: Penguin Traceroute, Remote Command Execution + + + CONFIRM + http://www.linux-directory.com/scripts/traceroute.pl + + Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. + + + + + + + + + cpe:/a:linux_directory_penguin:nslookup:1.0 + + CVE-2002-0489 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.663-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4353 + + + XF + penguin-nslookup-command-execution(8601) + + + BUGTRAQ + 20020322 Re: PHP script: Penguin Traceroute, Remote Command Execution + + Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters. + + + + + + + + + + + + + cpe:/a:instant_web_mail:instant_web_mail:0.56 + cpe:/a:instant_web_mail:instant_web_mail:0.55 + cpe:/a:instant_web_mail:instant_web_mail:0.59 + cpe:/a:instant_web_mail:instant_web_mail:0.57 + cpe:/a:instant_web_mail:instant_web_mail:0.58 + + CVE-2002-0490 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4361 + + + XF + instant-webmail-pop-commands(8650) + + + BUGTRAQ + 20020323 Instant Web Mail additional POP3 commands and mail headers + + + CONFIRM + http://instantwebmail.sourceforge.net/#changeLog + + Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php. + + + + + + + + + cpe:/a:alguest:alguest:1.0 + + CVE-2002-0491 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:09.960-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4355 + + + BUGTRAQ + 20020324 Cookie vulnerability in Alguest guestbook (PHP) + + + XF + alguest-php-admin-access(8623) + + admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value. + + + + + + + + + cpe:/a:dcscripts:dcshop:1.002_beta + + CVE-2002-0492 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020325 dcshop.cgi anybody can delete *.setup for database + + dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. + + + + + + + + + cpe:/a:apache:tomcat + + CVE-2002-0493 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MISC + http://www.apachelabs.org/tomcat-dev/200108.mbox/%3C20010810000819.6350.qmail@icarus.apache.org%3E + + + BUGTRAQ + 20020325 re: Tomcat Security Exposure + + + XF + tomcat-xml-bypass-restrictions(9863) + + Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions. + + + + + + + + + cpe:/a:websight_directory_system:websight_directory_system:0.1 + + CVE-2002-0494 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4357 + + + XF + websight-directory-system-css(8624) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=163389 + + Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name. + + + + + + + + + cpe:/a:cgiscript.net:cssearch:2.3 + + CVE-2002-0495 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.570-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4368 + + + XF + cssearch-url-execute-commands(8636) + + + BUGTRAQ + 20020325 CGIscript.net - csSearch.cgi - Remote Code Execution (up to 17,000 sites vulnerable) + + + MISC + http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=7 + + csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi. + + + + + + + + + cpe:/a:southwest:southwest:1.0.0 + + CVE-2002-0496 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4362 + + + BUGTRAQ + 20020326 SouthWest Telnet talker server. DoS (Denial of Service Attack). + + + XF + southwest-http-port-dos(8626) + + The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002. + + + + + + + + + cpe:/a:mtr:mtr:0.41 + + CVE-2002-0497 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:10.883-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4217 + + + XF + mtr-options-bo(8367) + + + DEBIAN + DSA-124 + + + BUGTRAQ + 20020306 mtr 0.45, 0.46 + + Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable. + + + + + + + + + cpe:/a:etnus:totalview:5.0.0_4 + + CVE-2002-0498 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.023-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4365 + + + XF + totalview-insecure-privileges(8635) + + + BUGTRAQ + 20020326 Etnus TotalView 5. + + Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.9 + cpe:/o:linux:linux_kernel:2.2.20 + cpe:/o:linux:linux_kernel:2.2.8 + cpe:/o:linux:linux_kernel:2.2.7 + cpe:/o:linux:linux_kernel:2.2.6 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.3.0 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.11 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.2.2 + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.2.4 + cpe:/o:linux:linux_kernel:2.2.5 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.1 + cpe:/o:linux:linux_kernel:2.3.99 + + CVE-2002-0499 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.180-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4367 + + + BUGTRAQ + 20020326 d_path() truncating excessive long path name vulnerability + + + XF + linux-dpath-truncate-path(8634) + + + MISC + http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html + + + VULNWATCH + 20020326 [VulnWatch] d_path() truncating excessive long path name vulnerability + + The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0500 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ie-dynsrc-information-disclosure(8658) + + + BID + 4371 + + + BUGTRAQ + 20020326 Retrieving information on local files in IE (GM#003-IE) + + Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. + + + + + + + + + cpe:/a:posadis:posadis:m5pre1 + + CVE-2002-0501 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.603-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4378 + + + XF + posadis-logging-format-string(8653) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=165094 + + + BUGTRAQ + 20020327 Format String Bug in Posadis DNS Server + + + OSVDB + 3516 + + Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages. + + + + + + + + + cpe:/a:citrix:nfuse:1.6 + + CVE-2002-0502 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nfuse-applist-information-disclosure(7984) + + + BID + 3926 + + + BUGTRAQ + 20020123 RE: Citrix NFuse 1.6 + + + BUGTRAQ + 20020122 Citrix NFuse 1.6 + + Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. + + + + + + + + + cpe:/a:citrix:nfuse:1.5 + + CVE-2002-0503 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:11.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nfuse-boilerplate-directory-traversal(8654) + + + BID + 4382 + + + BUGTRAQ + 20020327 Citrix Nfuse directory traversal with boilerplate.asp + + Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter. + + + + + + + + + + cpe:/a:citrix:nfuse:1.6 + cpe:/a:citrix:nfuse:1.51 + + CVE-2002-0504 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4372 + + + XF + nfuse-launch-css(8659) + + + BUGTRAQ + 20020327 NFuse Cross Site Scripting vulnerability + + Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. + + + + + + + + + + cpe:/h:cisco:call_manager:3.0 + cpe:/h:cisco:call_manager:3.1 + + CVE-2002-0505 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4370 + + + XF + cisco-cti-memory-leak(8655) + + + CISCO + 20020327 LDAP Connection Leak in CTI when User Authentication Fails + + Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords. + + + + + + + + + + + + + + + + + + + + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.0::sparc + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:7.2::alpha + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0::alpha + + CVE-2002-0506 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.367-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4393 + + + XF + libnewt-bo(8700) + + + BUGTRAQ + 20020328 A possible buffer overflow in libnewt + + Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt. + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5:sp1 + cpe:/a:microsoft:exchange_server:2000:sp2 + cpe:/a:microsoft:exchange_server:5.5:sp4 + cpe:/a:microsoft:exchange_server:5.5:sp3 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:2000:sp1 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.5:sp2 + cpe:/h:rsa:securid:5.0 + + CVE-2002-0507 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.540-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4390 + + + XF + exchange-owa-securid-bypass(8681) + + + BUGTRAQ + 20020328 Authentication with RSA SecurID and Outlook web access + + An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA. + + + + + + + + + + cpe:/a:wwwisis:wwwisis:3.3 + cpe:/a:wwwisis:wwwisis:3.45 + + CVE-2002-0508 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.710-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4384 + + + BID + 4383 + + + XF + wwwisis-remote-command-execution(8660) + + + CONFIRM + http://www.bireme.br/security.htm + + + BUGTRAQ + 20020402 RE: [VulnWatch] vuln in wwwisis: remote command execution and get files + + + BUGTRAQ + 20020328 vuln in wwwisis: remote command execution and get files + + + VULNWATCH + 20020328 [VulnWatch] vuln in wwwisis: remote command execution and get files + + wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog. + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0 + + CVE-2002-0509 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:12.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4391 + + + XF + oracle-tns-onetcp-dos(8657) + + + BUGTRAQ + 20020328 Oracle9i TSN DoS Attack + + Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + + CVE-2002-0510 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4314 + + + BUGTRAQ + 20020319 Identifying Kernel 2.4.x based Linux machines using UDP + + + XF + linux-udp-fingerprint(8588) + + The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux. + + + + + + + + + cpe:/a:nscd:nscd:2.2.4 + + CVE-2002-0511 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4399 + + + XF + nscd-dns-ptr-validation(8745) + + + CALDERA + CSSA-2002-013.0 + + The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names. + + + + + + + + + + cpe:/a:caldera:openlinux_workstation:3.1.1 + cpe:/a:caldera:openlinux_server:3.1.1 + + CVE-2002-0512 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.337-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4400 + + + CALDERA + CSSA-2002-005.0 + + + XF + kde-startkde-search-directory(8737) + + startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries. + + + + + + + + + + + cpe:/a:symatec:popper_mod:1.2 + cpe:/a:symatec:popper_mod:1.2.1 + cpe:/a:symatec:popper_mod:1.0 + + CVE-2002-0513 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.493-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4412 + + + XF + symatec-popper-admin-access(8746) + + + CONFIRM + http://www.symatec-computer.com/forums/viewtopic.php?t=14 + + + BUGTRAQ + 20020330 popper_mod 1.2.1 and previous accounts compromise + + The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator. + + + + + + + + + cpe:/o:openbsd:openbsd:3.0 + + CVE-2002-0514 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4401 + + + BUGTRAQ + 20020331 packet filter fingerprinting(open but closed, closed but filtered) + + + XF + firewall-rst-fingerprint(8738) + + PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL. + + + + + + + + + cpe:/a:darren_reed:ipfilter:3.4.25 + + CVE-2002-0515 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4403 + + + BUGTRAQ + 20020331 packet filter fingerprinting(open but closed, closed but filtered) + + + XF + firewall-rst-fingerprint(8738) + + IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs. + + + + + + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.0 + cpe:/a:squirrelmail:squirrelmail:1.2.4 + cpe:/a:squirrelmail:squirrelmail:1.2.3 + cpe:/a:squirrelmail:squirrelmail:1.2.2 + cpe:/a:squirrelmail:squirrelmail:1.2.1 + cpe:/a:squirrelmail:squirrelmail:1.2.5 + + CVE-2002-0516 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:13.947-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4385 + + + XF + squirrelmail-theme-command-execution(8671) + + + BUGTRAQ + 20020331 Re: squirrelmail 1.2.5 email user can execute command + + + BUGTRAQ + 20020327 squirrelmail 1.2.5 email user can execute command + + SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0517 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.103-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#169059 + + + BID + 4502 + + + XF + unixware-openunix-dtterm-bo(7282) + + + BUGTRAQ + 20020108 dtterm exploit in Unixware 7.1.1 + + + XF + x11-xrm-bo(8828) + + + BUGTRAQ + 20020108 xterm exploit in Unixware 7.0.1 + + + CALDERA + CSSA-2002-SCO.15 + + Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.5:stable + + CVE-2002-0518 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4524 + + + XF + bsd-syncache-inpcb-dos(8875) + + + FREEBSD + FreeBSD-SA-02:20 + + + OSVDB + 6046 + + + XF + bsd-syncookie-pointer-dos(8873) + + The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (2) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart. + + + + + + + + + cpe:/a:asp-nuke:asp-nuke:rc1 + + CVE-2002-0520 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + aspnuke-image-css(8829) + + + BID + 4475 + + + MISC + http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt + + + CONFIRM + http://www.asp-nuke.com/news.asp?date=20020412&cat=11 + + + VULN-DEV + 20020409 Security holes in ASP-Nuke + + Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag. + + + + + + + + + + cpe:/a:asp-nuke:asp-nuke:rc1 + cpe:/a:asp-nuke:asp-nuke:rc2 + + CVE-2002-0521 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.557-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4481 + + + XF + aspnuke-downloads-post-css(8830) + + + BID + 4477 + + + XF + aspnuke-user-profile-css(8831) + + + MISC + http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt + + + VULN-DEV + 20020409 Security holes in ASP-Nuke + + + CONFIRM + http://www.asp-nuke.com/news.asp?date=20020412&cat=11 + + Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp. + + + + + + + + + + cpe:/a:asp-nuke:asp-nuke:rc1 + cpe:/a:asp-nuke:asp-nuke:rc2 + + CVE-2002-0522 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4484 + + + XF + aspnuke-account-hijacking(8832) + + + MISC + http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt + + + VULN-DEV + 20020409 Security holes in ASP-Nuke + + + CONFIRM + http://www.asp-nuke.com/news.asp?date=20020412&cat=11 + + ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie. + + + + + + + + + + cpe:/a:asp-nuke:asp-nuke:rc1 + cpe:/a:asp-nuke:asp-nuke:rc2 + + CVE-2002-0523 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:14.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4489 + + + XF + aspnuke-cookie-reveal-information(8833) + + + MISC + http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt + + + VULN-DEV + 20020409 Security holes in ASP-Nuke + + + CONFIRM + http://www.asp-nuke.com/news.asp?date=20020412&cat=11 + + ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie. + + + + + + + + + + cpe:/a:asp-nuke:asp-nuke:rc1 + cpe:/a:asp-nuke:asp-nuke:rc2 + + CVE-2002-0524 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4489 + + + XF + aspnuke-cookie-reveal-information(8833) + + + MISC + http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt + + + VULN-DEV + 20020409 Security holes in ASP-Nuke + + + CONFIRM + http://www.asp-nuke.com/news.asp?date=20020412&cat=11 + + ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message. + + + + + + + + + + + + + + cpe:/a:isc:inn:2.2.1 + cpe:/a:isc:inn:2.2 + cpe:/a:isc:inn:2.2.2 + cpe:/a:isc:inn:2.2.3 + cpe:/a:isc:inn:2.0 + cpe:/a:isc:inn:2.1 + + CVE-2002-0525 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4501 + + + XF + inn-rnews-inews-format-string(8834) + + + BUGTRAQ + 20020411 Inn (Inter Net News) security problems + + Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses. + + + + + + + + + cpe:/a:inn:inn:2.2.3 + + CVE-2002-0526 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020411 Inn (Inter Net News) security problems + + + XF + inn-inews-rnews-info-disclosure(42803) + + Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls. + + + + + + + + + + + cpe:/h:watchguard:soho_firewall:5.0.31 + cpe:/h:watchguard:soho_firewall:5.0.28 + cpe:/h:watchguard:soho_firewall:5.0.29 + + CVE-2002-0527 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4447 + + + XF + watchguard-soho-ipoptions-dos(8774) + + + BUGTRAQ + 20020408 KPMG-2002007: Watchguard SOHO Denial of Service + + + VULNWATCH + 20020408 [VulnWatch] KPMG-2002007: Watchguard SOHO Denial of Service + + Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options. + + + + + + + + + cpe:/h:watchguard:soho_firewall:5.0.35 + + CVE-2002-0528 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4491 + + + XF + watchguard-soho-bypass-restrictions(8814) + + + BUGTRAQ + 20020410 KPMG-2002008: Watchguard SOHO IP Restrictions Flaw + + + VULNWATCH + 20020410 [VulnWatch] KPMG-2002008: Watchguard SOHO IP Restrictions Flaw + + Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules. + + + + + + + + + cpe:/a:hp:photosmart_print_driver:1.2.1::mac_os_x + + CVE-2002-0529 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:15.807-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4518 + + + XF + macos-photosmart-weak-permissions(8856) + + + BUGTRAQ + 20020414 Vulnerability in HP Photosmart/Deskjet Drivers for Mac OS X (root compromise) + + HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a Trojan horse. + + + + + + + + + cpe:/a:novell:web_search:2.0.1 + + CVE-2002-0530 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:27.243-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VULNWATCH + 20020410 [VulnWatch] Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues + + + BUGTRAQ + 20020410 Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues + + Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter. + + + + + + + + + + + + + cpe:/a:emumail:emumail_red_hat_linux:5.0 + cpe:/a:emumail:emumail_red_hat_linux:5.1 + cpe:/a:emumail:emumail_unix:5.1 + cpe:/a:emumail:emumail:3.0 + cpe:/a:emumail:emumail_unix:5.0 + + CVE-2002-0531 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:16.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4435 + + + XF + emumail-cgi-view-files(8766) + + + CONFIRM + http://www.emumail.com/downloads/download_unix.html/ + + + BUGTRAQ + 20020403 emumail.cgi + + Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter. + + + + + + + + + + + + + cpe:/a:emumail:emumail_red_hat_linux:5.0 + cpe:/a:emumail:emumail_red_hat_linux:5.1 + cpe:/a:emumail:emumail_unix:5.1 + cpe:/a:emumail:emumail:3.0 + cpe:/a:emumail:emumail_unix:5.0 + + CVE-2002-0532 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:16.257-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4488 + + + XF + emumail-http-host-execute(8836) + + + BUGTRAQ + 20020410 Re: emumail.cgi, one more local vulnerability (not verified) + + + OSVDB + 5270 + + EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters. + + + + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:1.2.0 + cpe:/a:phpbb_group:phpbb:1.2.1 + cpe:/a:phpbb_group:phpbb:1.4.4 + cpe:/a:phpbb_group:phpbb:1.4.2 + cpe:/a:phpbb_group:phpbb:1.4.1 + cpe:/a:phpbb_group:phpbb:1.0.0 + cpe:/a:phpbb_group:phpbb:1.4.0 + + CVE-2002-0533 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:16.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4432 + + + XF + phpbb-bbcode-function-dos(8764) + + + BID + 4434 + + + BUGTRAQ + 20020404 (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability + + + VULNWATCH + 20020404 [VulnWatch] (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability + + + VULN-DEV + 20020404 (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability + + phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags. + + + + + + + + + + cpe:/a:postboard:postboard:2.0.1 + cpe:/a:postboard:postboard:2.0 + + CVE-2002-0534 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:16.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4562 + + + XF + postboard-bbcode-dos(8883) + + + BUGTRAQ + 20020416 Multiple Vulnerabilities in PostBoard + + PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags. + + + + + + + + + + + + + + cpe:/a:postnuke_software_foundation:postnuke:0.71 + cpe:/a:postboard:postboard:2.0.1 + cpe:/a:postboard:postboard:2.0 + cpe:/a:postnuke_software_foundation:postnuke:0.703 + cpe:/a:postnuke_software_foundation:postnuke:0.70 + cpe:/a:postnuke_software_foundation:postnuke:0.64 + + CVE-2002-0535 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:16.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4559 + + + BUGTRAQ + 20020416 Multiple Vulnerabilities in PostBoard + + + XF + postboard-title-css(8884) + + + BID + 4561 + + + XF + postboard-img-css(8881) + + Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title. + + + + + + + + + cpe:/a:phpgroupware:phpgroupware:0.9.13 + + CVE-2002-0536 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:16.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4424 + + + XF + phpgroupware-sql-injection(8755) + + + BUGTRAQ + 20020403 SQL injection in PHPGroupware + + + OSVDB + 5153 + + + BUGTRAQ + 20020411 Re: SQL injection in PHPGroupware + + PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack. + + + + + + + + + cpe:/a:stepweb:sws:2.5 + + CVE-2002-0537 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.040-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4503 + + + BUGTRAQ + 20020411 SWS Vuln (small but important to those using it.) + + + XF + sws-insecure-admin-page(8849) + + The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS. + + + + + + + + + + + + + + + + + + + cpe:/h:symantec:gateway_security:1.0 + cpe:/a:symantec:raptor_firewall:6.5.3::solaris + cpe:/a:symantec:enterprise_firewall:6.5.2::windows_2000_nt + cpe:/a:symantec:velociraptor:1.x + cpe:/a:symantec:enterprise_firewall:7.0::windows_2000_nt + cpe:/a:symantec:raptor_firewall:6.5::windows_nt + cpe:/a:symantec:enterprise_firewall:7.0::solaris + + CVE-2002-0538 + 2002-07-03T00:00:00.000-04:00 + 2011-03-07T21:08:29.750-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4522 + + + XF + raptor-firewall-ftp-bounce(8847) + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.04.17.html + + + BUGTRAQ + 20020415 Raptor Firewall FTP Bounce vulnerability + + + BUGTRAQ + 20020417 Re: Raptor Firewall FTP Bounce vulnerability + + FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability. + + + + + + + + + + cpe:/a:demarc_security:puresecure:1.0.5_for_unix + cpe:/a:demarc_security:puresecure:1.0.5_for_windows + + CVE-2002-0539 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4520 + + + XF + puresecure-sql-injection(8854) + + + BUGTRAQ + 20020417 Demarc Security Update Advisory + + + BUGTRAQ + 20020415 Demarc PureSecure 1.05 may be other (user can bypass login) + + + OSVDB + 5239 + + Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie. + + + + + + + + + + + cpe:/h:nortel:cvx_1800_multi-service_access_switch:3.6.3:patch5 + cpe:/h:nortel:cvx_1800_multi-service_access_switch:3.6.3:patch25 + cpe:/h:nortel:cvx_1800_multi-service_access_switch:3.6.3:patch24 + + CVE-2002-0540 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#403315 + + + BID + 4507 + + + XF + nortel-default-snmp-string(8848) + + + BUGTRAQ + 20020413 Nortel CVX 1800s will dump all local user names and passwords via SNMP + + + BUGTRAQ + 20020419 Re: Nortel CVX 1800s will dump all local user names and passwords via SNMP + + Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration. + + + + + + + + + + cpe:/a:ibm:tivoli_storage_manager:4.2.1 + cpe:/a:ibm:tivoli_storage_manager:4.2 + + CVE-2002-0541 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.tivoli.com/support/storage_mgr/flash_httpport.html + + + BID + 4500 + + + XF + tivoli-storagemanager-client-bo(8817) + + + BUGTRAQ + 20020411 iXsecurity.20020328.tivoli_tsm_dsmsvc.a + + + BID + 4492 + + + XF + tivoli-storagemanager-login-bo(8825) + + + BUGTRAQ + 20020411 iXsecurity.20020327.tivoli_tsm_dsmcad.a + + Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581. + + + + + + + + + + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:openbsd:openbsd:2.9 + + CVE-2002-0542 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.820-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4495 + + + XF + openbsd-mail-root-privileges(8818) + + + BUGTRAQ + 20020411 OpenBSD Local Root Compromise + + + CONFIRM + http://www.openbsd.org/errata30.html#mail + + + BUGTRAQ + 20020411 local root compromise in openbsd 3.0 and below + + + OSVDB + 5269 + + mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron. + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0 + + CVE-2002-0543 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:17.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4466 + + + XF + abyss-unicode-directory-traversal(8805) + + + CONFIRM + http://www.aprelium.com/forum/viewtopic.php?t=24 + + + BUGTRAQ + 20020409 Abyss Webserver 1.0 Administration password file retrieval exploit + + Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request. + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0 + + CVE-2002-0544 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.133-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4467 + + + CONFIRM + http://www.aprelium.com/news/abws103.html + + Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges. + + + + + + + + + + + cpe:/h:cisco:aironet_ap340:11.21 + cpe:/h:cisco:aironet_ap350:11.21 + + CVE-2002-0545 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4461 + + + XF + cisco-aironet-telnet-dos(8788) + + + CISCO + 20020409 Aironet Telnet Vulnerability + + Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords. + + + + + + + + + + cpe:/a:nullsoft:winamp:2.79 + cpe:/a:nullsoft:winamp:2.78 + + CVE-2002-0546 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + winamp-mp3-browser-css(8753) + + + BUGTRAQ + 20020403 Re: Winamp: Mp3 file can control the minibrowser + + + BID + 4414 + + + BUGTRAQ + 20020403 Winamp: Mp3 file can control the minibrowser + + Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file. + + + + + + + + + cpe:/a:nullsoft:winamp:2.79 + + CVE-2002-0547 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4609 + + + XF + winamp-mp3-id3v2-bo(8946) + + + MISC + http://www.winamp.com/download/newfeatures.jhtml + + + BUGTRAQ + 20020426 Mp3 file can execute code in Winamp [Sandblad advisory #5] + + Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag. + + + + + + + + + cpe:/a:anthill:anthill:0.1.6.1 + + CVE-2002-0548 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4443 + + + XF + anthill-postbug-auth-bypass(8771) + + + BUGTRAQ + 20020406 Anthill login and JavaScript vulnerabilities + + Anthill allows remote attackers to bypass authentication and file bug reports by directly accessing the postbug.php program instead of enterbug.php. + + + + + + + + + cpe:/a:anthill:anthill:0.1.6.1 + + CVE-2002-0549 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:18.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4442 + + + XF + anthill-bug-tracking-css(8770) + + + BUGTRAQ + 20020406 Anthill login and JavaScript vulnerabilities + + Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users. + + + + + + + + + cpe:/a:gcf:dynamic_guestbook:3.0 + + CVE-2002-0550 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4423 + + + XF + dynamic-guestbook-command-execution(8762) + + + BUGTRAQ + 20020403 Dynamic Guestbook V3.0 Cross Site Scripting and Arbitrary Command Execution under certain circumstances + + Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter. + + + + + + + + + cpe:/a:gcf:dynamic_guestbook:3.0 + + CVE-2002-0551 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4422 + + + XF + dynamic-guestbook-css(8763) + + + BUGTRAQ + 20020403 Dynamic Guestbook V3.0 Cross Site Scripting and Arbitrary Command Execution under certain circumstances + + Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar. + + + + + + + + + cpe:/a:melange:melange_chat_system:2.0.2_beta_2 + + CVE-2002-0552 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + melange-chat-config-bo(8845) + + + BID + 4510 + + + BID + 4509 + + + BID + 4508 + + + XF + melange-chat-filename-bo(8846) + + + XF + melange-chat-yell-bo(8842) + + + BUGTRAQ + 20020416 Melange Chat POC DOS + + + BUGTRAQ + 20020414 Vulnerabilities in the Melange Chat Server + + Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks. + + + + + + + + + + + + + + cpe:/a:turnkey_solutions:sunshop_shopping_cart:2.5 + cpe:/a:turnkey_solutions:sunshop_shopping_cart:1.5 + cpe:/a:turnkey_solutions:sunshop_shopping_cart:2.0 + cpe:/a:turnkey_solutions:sunshop_shopping_cart:2.4 + cpe:/a:turnkey_solutions:sunshop_shopping_cart:2.2 + cpe:/a:turnkey_solutions:sunshop_shopping_cart:2.1 + + CVE-2002-0553 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sunshop-new-cust-css(8840) + + + BID + 4506 + + + BUGTRAQ + 20020413 SunSop: cross-site-scripting bug + + Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration. + + + + + + + + + + + cpe:/a:ibm:informix_web_datablade:4.12 + cpe:/a:ibm:informix_web_datablade:4.11 + cpe:/a:ibm:informix_web_datablade:4.10 + + CVE-2002-0554 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4496 + + + XF + informix-wdm-sql-injection(8826) + + + BUGTRAQ + 20020411 IBM Informix Web DataBlade: SQL injection + + webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request. + + + + + + + + + + + + cpe:/a:ibm:informix_web_datablade:4.13 + cpe:/a:ibm:informix_web_datablade:4.12 + cpe:/a:ibm:informix_web_datablade:4.11 + cpe:/a:ibm:informix_web_datablade:4.10 + + CVE-2002-0555 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:19.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4498 + + + XF + informix-wbm-sql-decoding(8827) + + + BUGTRAQ + 20020411 IBM Informix Web DataBlade: Auto-decoding HTML entities + + IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it. + + + + + + + + + cpe:/a:deep_forest_software:quik-serv_webserver:1.1b + + CVE-2002-0556 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4425 + + + XF + quikserv-dot-directory-traversal(8754) + + + BUGTRAQ + 20020403 Quik-Serv Web Server v1.1B Arbitrary File Disclosure + + Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. + + + + + + + + + cpe:/o:openbsd:openbsd:3.0 + + CVE-2002-0557 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4338 + + + XF + bsd-yp-execute-shell(8625) + + + OPENBSD + 20020319 016: SECURITY FIX: March 19, 2002 + + Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval(). + + + + + + + + + + + + + cpe:/a:typsoft:typsoft_ftp_server:0.85 + cpe:/a:typsoft:typsoft_ftp_server:0.95 + cpe:/a:typsoft:typsoft_ftp_server:0.97 + cpe:/a:typsoft:typsoft_ftp_server:0.96 + cpe:/a:typsoft:typsoft_ftp_server:0.93 + + CVE-2002-0558 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 2489 + + + XF + typsoft-ftp-directory-traversal(6165) + + + BUGTRAQ + 20020407 Typsoft FTP Server: yet another directory traversal vulnerability + + Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0559 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2002-08 + + + CERT-VN + VU#923395 + + + CERT-VN + VU#878603 + + + CERT-VN + VU#750299 + + + CERT-VN + VU#659043 + + + CERT-VN + VU#313280 + + + XF + oracle-appserver-plsql-adddad-bo(8098) + + + BID + 4032 + + + BUGTRAQ + 20020206 Multiple Buffer Overflows in Oracle 9iAS + + + XF + oracle-appserver-plsql-cache-bo(8097) + + + XF + oracle-appserver-plsql-authclient-bo(8096) + + + XF + oracle-appserver-plsql-bo(8095) + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0560 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-08 + + + CERT-VN + VU#307835 + + + BID + 4294 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7_.1 + + CVE-2002-0561 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:20.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#611776 + + + CERT + CA-2002-08 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + BID + 4292 + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings. + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:application_server:1.0.2 + + CVE-2002-0562 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-08 + + + CERT-VN + VU#698467 + + + BID + 4034 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + BUGTRAQ + 20020206 JSP translation file access under Oracle 9iAS + + The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7_.1 + + CVE-2002-0563 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT + CA-2002-08 + + + CERT-VN + VU#168795 + + + BID + 4293 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + XF + oracle-appserver-apache-services(8455) + + + OSVDB + 705 + + + OSVDB + 13152 + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + MISC + http://www.appsecinc.com/Policy/PolicyCheck7024.html + + + SECTRACK + 1009167 + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0564 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#193523 + + + CERT + CA-2002-08 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials. + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:application_server:1.0.2 + + CVE-2002-0565 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-08 + + + CERT-VN + VU#547459 + + + XF + oracle-appserver-oraclejsp-view-info(8100) + + + BID + 4034 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + BUGTRAQ + 20020206 JSP translation file access under Oracle 9iAS + + Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages. + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7_.1 + + CVE-2002-0566 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT + CA-2002-08 + + + CERT-VN + VU#805915 + + + XF + oracle-appserver-plsql-pls-dos(8099) + + + BID + 4037 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:oracle8i:enterprise_8.0.5.0.0 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:database_server:8.0.3 + cpe:/a:oracle:database_server:8.0.4 + cpe:/a:oracle:database_server:8.0.5 + cpe:/a:oracle:database_server:8.0.6 + cpe:/a:oracle:database_server:8.0.1 + cpe:/a:oracle:database_server:8.0.2 + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:oracle:database_server:8.1.6 + cpe:/a:oracle:database_server:8.0.5.1 + cpe:/a:oracle:oracle8i:enterprise_8.1.6.1.0 + cpe:/a:oracle:oracle8i:8.1.5 + cpe:/a:oracle:database_server:8.1.5 + cpe:/a:oracle:oracle8i:enterprise_8.1.6.0.0 + cpe:/a:oracle:oracle8i:8.1.6 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:oracle8i:enterprise_8.1.7.0.0 + cpe:/a:oracle:oracle8i:enterprise_8.1.5.0.2 + cpe:/a:oracle:oracle8i:enterprise_8.1.7.1.0 + cpe:/a:oracle:oracle8i:enterprise_8.1.5.0.0 + cpe:/a:oracle:oracle8i:enterprise_8.0.6.0.0 + cpe:/a:oracle:oracle8i:enterprise_8.0.6.0.1 + cpe:/a:oracle:database_server:8.1.7.0.0 + cpe:/a:oracle:oracle8i:enterprise_8.1.5.1.0 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0567 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:21.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-08 + + + CERT-VN + VU#180147 + + + BID + 4033 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/plsextproc_alert.pdf + + + BUGTRAQ + 20020206 Remote Compromise in Oracle 9i Database Server + + + XF + oracle-plsql-remote-access(8089) + + Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process. + + + + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0568 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.100-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#476619 + + + CERT + CA-2002-08 + + + BID + 4290 + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2002-0569 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#977251 + + + CERT + CA-2002-08 + + + BID + 4298 + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BUGTRAQ + 20020206 Hackproofing Oracle Application Server paper + + + XF + oracle-appserver-config-file-access(8453) + + Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.9 + cpe:/o:linux:linux_kernel:2.2.20 + cpe:/o:linux:linux_kernel:2.2.8 + cpe:/o:linux:linux_kernel:2.2.7 + cpe:/o:linux:linux_kernel:2.2.6 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.11 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.2.2 + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.2.4 + cpe:/o:linux:linux_kernel:2.2.5 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.1 + + CVE-2002-0570 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.413-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + linux-loop-device-encryption(7769) + + + BID + 3775 + + + BUGTRAQ + 20020102 Vulnerability in encrypted loop device for linux + + The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key. + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0 + + CVE-2002-0571 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4523 + + + XF + oracle-ansi-sql-bypass-acl(8855) + + + CIAC + M-071 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/sql_joins_alert.pdf + + + BUGTRAQ + 20020416 ansi outer join syntax in Oracle allows access to any data + + + OSVDB + 5236 + + Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:freebsd:freebsd:4.4:releng + cpe:/o:sun:solaris:2.6 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.5:stable + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-0572 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.803-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#809347 + + + BID + 4568 + + + BUGTRAQ + 20020422 Pine Internet Advisory: Setuid application execution may give local root in FreeBSD + + + FREEBSD + FreeBSD-SA-02:23 + + + XF + bsd-suid-apps-gain-privileges(8920) + + + BUGTRAQ + 20020423 cheers + + + VULNWATCH + 20020422 Pine Internet Advisory: Setuid application execution may give local root in FreeBSD + + + OSVDB + 6095 + + + CIAC + M-072 + + FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-0573 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:22.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT + CA-2002-10 + + + CERT-VN + VU#638099 + + + XF + solaris-rwall-format-string(8971) + + + BUGTRAQ + 20020430 Adivosry + Exploit for Remote Root Hole in Default Installation of Popular Commercial Operating System + + + BID + 4639 + + + OSVDB + 778 + + + VULNWATCH + 20020430 [VulnWatch] Adivosry + Exploit for Remote Root Hole in Default Installation of Popular Commercial Operating System + + + + + + + + Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.5:stable + + CVE-2002-0574 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:23.147-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4539 + + + FREEBSD + FreeBSD-SA-02:21 + + + OSVDB + 5232 + + + XF + freebsd-icmp-echo-reply-dos(8893) + + Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being removed. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:openbsd:openssh:3.1 + cpe:/a:openbsd:openssh:3.0 + cpe:/a:openbsd:openssh:3.2 + cpe:/a:openbsd:openssh:2.9.9 + cpe:/a:openbsd:openssh:2.9p1 + cpe:/a:openbsd:openssh:2.9p2 + cpe:/a:openbsd:openssh:2.5 + cpe:/a:openbsd:openssh:2.9 + cpe:/a:openbsd:openssh:3.0.1 + cpe:/a:openbsd:openssh:2.5.2 + cpe:/a:openbsd:openssh:3.0.2 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:openbsd:openssh:2.3 + cpe:/a:openbsd:openssh:2.5.1 + + CVE-2002-0575 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:23.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4560 + + + XF + openssh-sshd-kerberos-bo(8896) + + + BUGTRAQ + 20020429 TSLSA-2002-0047 - openssh + + + OSVDB + 781 + + + BUGTRAQ + 20020426 Revised OpenSSH Security Advisory (adv.token) + + + BUGTRAQ + 20020419 OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow + + + VULN-DEV + 20020419 OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow + + + BUGTRAQ + 20020517 OpenSSH 3.2.2 released (fwd) + + + BUGTRAQ + 20020420 OpenSSH Security Advisory (adv.token) + + + CALDERA + CSSA-2002-022.2 + + Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges. + + + + + + + + + + + cpe:/a:allaire:coldfusion_server:4.0 + cpe:/a:allaire:coldfusion_server:5.0 + cpe:/a:allaire:coldfusion_server:4.5 + + CVE-2002-0576 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:23.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4542 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22906 + + + XF + coldfusion-dos-device-path-disclosure(8866) + + + OSVDB + 3337 + + + BUGTRAQ + 20020418 KPMG-2002013: Coldfusion Path Disclosure + + + VULNWATCH + 20020418 [VulnWatch] KPMG-2002013: Coldfusion Path Disclosure + + ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message. + + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:11.0.4 + + CVE-2002-0577 + 2002-06-18T00:00:00.000-04:00 + 2009-03-04T00:12:26.860-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#977779 + + + BID + 4582 + + + XF + hpux-passwd-dos(8939) + + + HP + HPSBUX0204-191 + + + SREASON + 656 + + + + + Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service. + + + + + + + + + cpe:/a:aci:4d_webserver:6.5.7 + + CVE-2002-0578 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:23.803-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020502 iXsecurity.20020404.4d_webserver.a + + + BID + 4665 + + Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user name or (2) password. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0579 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:23.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4552 + + + XF + xpede-insecure-admin-scripts(8900) + + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0580 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.100-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4553 + + + XF + xpede-datasource-reveal-account(8902) + + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0581 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + + BID + 4555 + + + XF + xpede-sprc-sql-injection(8903) + + WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0582 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xpede-expense-directory-permissions(8905) + + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + + BID + 4554 + + WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0583 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.553-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + xpede-expense-directory-permissions(8905) + + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + + BID + 4554 + + WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack. + + + + + + + + + cpe:/a:workforceroi:xpede:4.1 + + CVE-2002-0584 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020419 Xpede many vulnerabilities + + + BID + 4556 + + + XF + xpede-timesheet-disclosure(8907) + + WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet. + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + + CVE-2002-0585 + 2002-06-18T00:00:00.000-04:00 + 2009-03-04T00:12:27.500-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4680 + + + HP + HPSBUX0205-192 + + + XF + hpux-ndd-dos(9020) + + + + + Unknown vulnerability in ndd for HP-UX 11.11 with certain TRANSPORT patches allows attackers to cause a denial of service. + + + + + + + + + + + + + + + + + cpe:/a:aol:aol_server:3.2.1 + cpe:/a:aol:aol_server:3.0 + cpe:/a:aol:aol_server:3.4 + cpe:/a:aol:aol_server:3.3.1 + cpe:/a:aol:aol_server:3.3 + cpe:/a:aol:aol_server:3.4.2 + cpe:/a:aol:aol_server:3.2 + cpe:/a:aol:aol_server:3.4.1 + cpe:/a:aol:aol_server:3.1 + + CVE-2002-0586 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:24.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4535 + + + XF + aolserver-dbproxy-format-string(8860) + + + BUGTRAQ + 20020416 [CERT-intexxia] AOLServer DB Proxy Daemon Format String Vulnerability + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=533141&group_id=3152&atid=303152 + + Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters. + + + + + + + + + + + + + + + + + cpe:/a:aol:aol_server:3.2.1 + cpe:/a:aol:aol_server:3.0 + cpe:/a:aol:aol_server:3.4 + cpe:/a:aol:aol_server:3.3.1 + cpe:/a:aol:aol_server:3.3 + cpe:/a:aol:aol_server:3.4.2 + cpe:/a:aol:aol_server:3.2 + cpe:/a:aol:aol_server:3.4.1 + cpe:/a:aol:aol_server:3.1 + + CVE-2002-0587 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020416 [CERT-intexxia] AOLServer DB Proxy Daemon Format String Vulnerability + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=533141&group_id=3152&atid=303152 + + + CONFIRM + http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/aolserver/aolserver/nspd/log.c.diff?r1=1.4&r2=1.4.6.1 + + Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters. + + + + + + + + + + + + cpe:/a:steve_korbett:pvote:1.0a + cpe:/a:steve_korbett:pvote:1.0b + cpe:/a:steve_korbett:pvote:1.5 + cpe:/a:steve_korbett:pvote:1.0 + + CVE-2002-0588 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4540 + + + XF + pvote-add-delete-polls(8877) + + + CONFIRM + http://orbit-net.net:8001/php/pvote/ + + + BUGTRAQ + 20020418 [[ TH 026 Inc. ]] SA #1 - Multiple vulnerabilities in PVote 1.5 + + PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php. + + + + + + + + + + + + cpe:/a:steve_korbett:pvote:1.0a + cpe:/a:steve_korbett:pvote:1.0b + cpe:/a:steve_korbett:pvote:1.5 + cpe:/a:steve_korbett:pvote:1.0 + + CVE-2002-0589 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4541 + + + XF + pvote-change-admin-password(8878) + + + CONFIRM + http://orbit-net.net:8001/php/pvote/ + + + BUGTRAQ + 20020418 [[ TH 026 Inc. ]] SA #1 - Multiple vulnerabilities in PVote 1.5 + + PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password. + + + + + + + + + cpe:/a:icredibb:icredibb:1.1_beta + + CVE-2002-0590 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020419 [[ TH 026 Inc. ]] SA #2 - IcrediBB 1.1, Cross Site Scripting vulnerability. + + + BID + 4548 + + + XF + incredibb-html-css(8879) + + Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts. + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.3 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:4.8_beta + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:aol:instant_messenger:4.2 + cpe:/a:aol:instant_messenger:4.1 + cpe:/a:aol:instant_messenger:4.7 + + CVE-2002-0591 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + aim-direct-connection-files(8870) + + + BUGTRAQ + 20020416 AIM's 'Direct Connection' feature could lead to arbitrary file creation + + + BID + 4526 + + Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.3 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:2.5.1366 + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.8.2616 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:aol:instant_messenger:4.2 + cpe:/a:aol:instant_messenger:4.1 + cpe:/a:aol:instant_messenger:3.5.1808 + cpe:/a:aol:instant_messenger:2.5.1598 + cpe:/a:aol:instant_messenger:4.2.1193 + cpe:/a:aol:instant_messenger:3.0_n + cpe:/a:aol:instant_messenger:4.1.2010 + cpe:/a:aol:instant_messenger:3.0.1470 + cpe:/a:aol:instant_messenger:2.1.1236 + cpe:/a:aol:instant_messenger:2.0.996 + cpe:/a:aol:instant_messenger:4.8.2646 + cpe:/a:aol:instant_messenger:3.5.1670 + cpe:/a:aol:instant_messenger:2.0_n + cpe:/a:aol:instant_messenger:3.5.1856 + cpe:/a:aol:instant_messenger:3.0.1415 + cpe:/a:aol:instant_messenger:2.0.912 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:3.5.1635 + cpe:/a:aol:instant_messenger:4.7.2480 + cpe:/a:aol:instant_messenger:4.3.2229 + + CVE-2002-0592 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:25.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4574 + + + XF + aim-hijack-connection(8931) + + + BUGTRAQ + 20020421 AIM Remote File Transfer/Direct Connection Vulnerability + + AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. + + + + + + + + + + + + + cpe:/a:netscape:navigator:6.0 + cpe:/a:netscape:communicator:6.1 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:1.0:rc1 + cpe:/a:netscape:navigator:6.01 + + CVE-2002-0593 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:26.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4637 + + + BUGTRAQ + 20020430 RE: Reading local files in Netscape 6 and Mozilla (GM#001-NS) + + + CONECTIVA + CLA-2002:490 + + + XF + mozilla-netscape-irc-bo(8976) + + Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. + + + + + + + + + + + + + + + + + + cpe:/a:netscape:navigator:6.0 + cpe:/a:netscape:navigator:6.1 + cpe:/a:netscape:navigator:6.2 + cpe:/a:galeon:galeon_browser:1.2 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:galeon:galeon_browser:1.2.1 + cpe:/a:mozilla:mozilla:1.0:rc1 + cpe:/a:netscape:navigator:6.2.2 + cpe:/a:netscape:navigator:6.2.1 + cpe:/a:netscape:navigator:6.01 + + CVE-2002-0594 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:26.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4640 + + + BUGTRAQ + 20020430 RE: Reading local files in Netscape 6 and Mozilla (GM#001-NS) + + + REDHAT + RHSA-2003:046 + + + REDHAT + RHSA-2002:192 + + + XF + mozilla-css-files-exist(8977) + + + CONECTIVA + CLA-2002:490 + + Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. + + + + + + + + + cpe:/a:webtrends:reporting_center:4.0d + + CVE-2002-0595 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:26.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + webtrends-long-string-bo(8864) + + + BID + 4531 + + + BUGTRAQ + 20020416 Webtrends Reporting Center Buffer Overflow (#NISR17042002C) + + Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory. + + + + + + + + + cpe:/a:webtrends:reporting_center:4.0d + + CVE-2002-0596 + 2002-06-18T00:00:00.000-04:00 + 2010-01-16T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + webtrends-profile-path-disclosure(8865) + + + OSVDB + 10447 + + + MISC + http://www.ngssoftware.com/advisories/wtr.txt + + + BUGTRAQ + 20020416 Webtrends Reporting Center Buffer Overflow (#NISR17042002C) + + WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message. + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2002-0597 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#693099 + + + BID + 4532 + + + BUGTRAQ + 20020417 KPMG-2002011: Windows 2000 microsoft-ds Denial of Service + + + XF + win2k-lanman-dos(8867) + + + MSKB + Q320751 + + + OSVDB + 5179 + + + VULNWATCH + 20020417 [VulnWatch] KPMG-2002011: Windows 2000 microsoft-ds Denial of Service + + LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445. + + + + + + + + + cpe:/a:foundstone:fscan:1.12 + + CVE-2002-0598 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:26.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4549 + + + XF + fscan-banner-format-string(8895) + + + CONFIRM + http://www.foundstone.com/knowledge/fscan112_advisory.html + + + BUGTRAQ + 20020419 KPMG-2002014: Foundstone Fscan Format String Bug + + Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server banner. + + + + + + + + + cpe:/a:blahz-dns:blahz-dns:0.2 + + CVE-2002-0599 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:27.133-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4618 + + + XF + blahzdns-auth-bypass(8951) + + + BUGTRAQ + 20020428 Blahz-DNS: Authentication bypass vulnerability + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=87004 + + + OSVDB + 5178 + + Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen. + + + + + + + + + + + + + cpe:/a:luke_mewburn:lukemftp:1.5 + cpe:/a:kth:kth_kerberos:4_1.0.2 + cpe:/a:kth:kth_kerberos:4_1.0.3 + cpe:/a:kth:kth_kerberos:4_1.1.1 + cpe:/a:kth:kth_kerberos:4_1.0.4 + + CVE-2002-0600 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4592 + + + XF + kerberos4-ftp-client-overflow(8938) + + + BUGTRAQ + 20020424 A bug in the Kerberos4 ftp client may cause heap overflow which leads to remote code execution + + Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request. + + + + + + + + + + + + + + cpe:/a:information_security_systems:realsecure_network_sensor:5.5.2_xpu_3.4 + cpe:/a:information_security_systems:realsecure_network_sensor:5.5_xpu_3.4 + cpe:/a:information_security_systems:realsecure_network_sensor:6.5 + cpe:/a:information_security_systems:realsecure_network_sensor:6.0_xpu_3.4 + cpe:/a:information_security_systems:realsecure_network_sensor:5.5.1_xpu_3.4 + cpe:/a:information_security_systems:realsecure_network_sensor:5.0_xpu_3.4 + + CVE-2002-0601 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:27.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4649 + + + ISS + 20020430 Remote Denial of Service Vulnerability in RealSecure Network Sensor + + + BUGTRAQ + 20020430 ISS Advisory: Remote Denial of Service Vulnerability in RealSecure Network Sensor + + + OSVDB + 5165 + + + XF + rs-ns-dhcp-dos(8961) + + ISS RealSecure Network Sensor 5.x through 6.5 allows remote attackers to cause a denial of service (crash) via malformed DHCP packets that cause RealSecure to dereference a null pointer. + + + + + + + + + + cpe:/a:snapgear:snapgear_lite%2b_firewall:1.5.3 + cpe:/a:snapgear:snapgear_lite%2b_firewall:1.5.4 + + CVE-2002-0602 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.snapgear.com/releases.html + + + BUGTRAQ + 20020502 KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + + VULNWATCH + 20020502 [VulnWatch] KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + Snapgear Lite+ firewall 1.5.4 and 1.5.3 allows remote attackers to cause a denial of service (crash) via a large number of connections to (1) the HTTP web management port, or (2) the PPTP port. + + + + + + + + + cpe:/a:snapgear:snapgear_lite%2b_firewall:1.5.3 + + CVE-2002-0603 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + snapgear-vpn-ipsec-dos(8987) + + + CONFIRM + http://www.snapgear.com/releases.html + + + BUGTRAQ + 20020502 KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + + VULNWATCH + 20020502 [VulnWatch] KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + + BID + 4659 + + Snapgear Lite+ firewall 1.5.3 allows remote attackers to cause a denial of service (IPSEC crash) via a zero length packet to UDP port 500. + + + + + + + + + + cpe:/a:snapgear:snapgear_lite%2b_firewall:1.5.3 + cpe:/a:snapgear:snapgear_lite%2b_firewall:1.5.4 + + CVE-2002-0604 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + snapgear-vpn-ipoptions-dos(8988) + + + CONFIRM + http://www.snapgear.com/releases.html + + + BUGTRAQ + 20020502 KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + + VULNWATCH + 20020502 [VulnWatch] KPMG-2002017: Snapgear Lite+ Firewall Denial of Service + + + BID + 4660 + + Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options. + + + + + + + + + cpe:/a:macromedia:flash_player:6.0 + + CVE-2002-0605 + 2002-06-18T00:00:00.000-04:00 + 2008-09-10T15:12:34.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.macromedia.com/support/flash/ts/documents/buf_ovflow_623.htm + + + XF + flash-activex-movie-bo(8993) + + + BUGTRAQ + 20020503 Macromedia Flash Activex Buffer overflow + + + BID + 4664 + + + OSVDB + 5177 + + + VULN-DEV + 20020503 Macromedia Flash Activex Buffer overflow + + + VULNWATCH + 20020502 [VulnWatch] Macromedia Flash Activex Buffer overflow + + Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter. + + + + + + + + + cpe:/a:3com:3cdaemon:2.0:revision_10 + + CVE-2002-0606 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:28.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4638 + + + XF + 3cdaemon-ftp-bo(8970) + + + BUGTRAQ + 20020429 3CDaemon DoS exploit + + Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login. + + + + + + + + + + + + + + cpe:/a:snitz_communications:snitz_forums_2000:3.0 + cpe:/a:snitz_communications:snitz_forums_2000:3.3.01 + cpe:/a:snitz_communications:snitz_forums_2000:3.3 + cpe:/a:snitz_communications:snitz_forums_2000:3.3.03 + cpe:/a:snitz_communications:snitz_forums_2000:3.3.02 + cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4 + + CVE-2002-0607 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:28.350-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4558 + + + CONFIRM + http://forum.snitz.com/forum/topic.asp?TOPIC_ID=26770 + + + BUGTRAQ + 20020419 Snitz Forums 2000 remote SQL query manipulation vulnerability + + + XF + snitz-members-sql-injection(8898) + + members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL. + + + + + + + + + cpe:/a:matu:matu_ftp:1.74 + + CVE-2002-0608 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:28.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4572 + + + XF + matu-ftp-long-string-bo(8911) + + + BUGTRAQ + 20020422 Matu FTP remote buffer overflow vulnerability + + Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner. + + + + + + + + + + + cpe:/o:hp:mpe_ix:6.0 + cpe:/o:hp:mpe_ix:7.0 + cpe:/o:hp:mpe_ix:6.5 + + CVE-2002-0609 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:28.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4536 + + + XF + hp-mpeix-ip-dos(8901) + + + HP + HPSBMP0204-013 + + Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets. + + + + + + + + + + + cpe:/o:hp:mpe_ix:6.0 + cpe:/o:hp:mpe_ix:7.0 + cpe:/o:hp:mpe_ix:6.5 + + CVE-2002-0610 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:28.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#551683 + + + BID + 4652 + + + XF + hp-mpeix-ftp-access(8990) + + + CIAC + M-075 + + + HP + HPSBMP0204-014 + + Vulnerability in FTPSRVR in HP MPE/iX 6.0 through 7.0 does not properly validate certain FTP commands, which allows attackers to gain privileges. + + + + + + + + + cpe:/a:craig_patchett:fileseek + + CVE-2002-0611 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:29.037-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + fileseek-cgi-directory-traversal(8858) + + + VULN-DEV + 20020416 FileSeek cgi script advisory + + Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered. + + + + + + + + + cpe:/a:craig_patchett:fileseek + + CVE-2002-0612 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:29.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + fileseek-cgi-command-execution(8857) + + + VULN-DEV + 20020416 FileSeek cgi script advisory + + FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. + + + + + + + + + + cpe:/a:dnstools_software:dnstools:2.0_beta3 + cpe:/a:dnstools_software:dnstools:2.0_beta4 + + CVE-2002-0613 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:29.337-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4617 + + + XF + dnstools-auth-bypass(8948) + + + BUGTRAQ + 20020428 dnstools: authentication bypass vulnerability + + + CONFIRM + http://www.dnstools.com/dnstools_2.0.1.tar.gz + + dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters. + + + + + + + + + + + + + + cpe:/a:php-survey:php-survey:2000-04-21 + cpe:/a:php-survey:php-survey:2000-04-20 + cpe:/a:php-survey:php-survey:2000-06-14b + cpe:/a:php-survey:php-survey:2000-06-14 + cpe:/a:php-survey:php-survey:prebeta2000-03-27 + cpe:/a:php-survey:php-survey:2000-06-15 + + CVE-2002-0614 + 2002-06-18T00:00:00.000-04:00 + 2008-09-05T16:28:29.490-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4612 + + + XF + phpsurvey-global-reveal-info(8950) + + + BUGTRAQ + 20020426 PHP-Survey Database Access Vulnerability + + PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server. + + + + + + + + + + + + + + + cpe:/a:microsoft:excel:2000:sp2 + cpe:/a:microsoft:excel:2000:sr1 + cpe:/a:microsoft:office:xp + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:excel:2002:sp1 + cpe:/a:microsoft:excel:2000 + cpe:/a:microsoft:office:2000 + + CVE-2002-0615 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:35.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-032 + + + XF + mediaplayer-playlist-script-execution(9422) + + + BID + 5110 + + The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation". + + + + + + + + + + + + + + + cpe:/a:microsoft:excel:2000:sp2 + cpe:/a:microsoft:excel:2000:sr1 + cpe:/a:microsoft:office:xp + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:excel:2002:sp1 + cpe:/a:microsoft:excel:2000 + cpe:/a:microsoft:office:2000 + + CVE-2002-0616 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:29.820-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-031 + + + BID + 5063 + + + XF + excel-inline-macro-execution(9397) + + The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability." + + + + + + + + + + + + + + + cpe:/a:microsoft:excel:2000:sp2 + cpe:/a:microsoft:excel:2000:sr1 + cpe:/a:microsoft:office:xp + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:excel:2002:sp1 + cpe:/a:microsoft:excel:2000 + cpe:/a:microsoft:office:2000 + + CVE-2002-0617 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:29.977-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-031 + + + XF + excel-hyperlink-macro-execution(9398) + + + BID + 5064 + + + OSVDB + 5175 + + The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass." + + + + + + + + + + + + + + + cpe:/a:microsoft:excel:2000:sp2 + cpe:/a:microsoft:excel:2000:sr1 + cpe:/a:microsoft:office:xp + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:excel:2002:sp1 + cpe:/a:microsoft:excel:2000 + cpe:/a:microsoft:office:2000 + + CVE-2002-0618 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:35.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-031 + + + MISC + http://www.guninski.com/ex$el2.html + + + NTBUGTRAQ + 20020524 Excel XP xml stylesheet problems + + + BID + 4821 + + + XF + excel-xsl-script-execution(9399) + + The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution". + + + + + + + + + + cpe:/a:microsoft:office:xp + cpe:/a:microsoft:office:2000 + + CVE-2002-0619 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:30.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-031 + + + BUGTRAQ + 20020514 dH team & SECURITY.NNOV: A variant of "Word Mail Merge" vulnerability + + + BID + 5066 + + + XF + word-mail-merge-variant(9077) + + The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788). + + + + + + + + + + + cpe:/a:microsoft:commerce_server:2000 + cpe:/a:microsoft:commerce_server:2000:sp1 + cpe:/a:microsoft:commerce_server:2000:sp2 + + CVE-2002-0620 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:35.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-033 + + + BID + 4853 + + Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API. + + + + + + + + + + + cpe:/a:microsoft:commerce_server:2000 + cpe:/a:microsoft:commerce_server:2000:sp1 + cpe:/a:microsoft:commerce_server:2000:sp2 + + CVE-2002-0621 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:35.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-033 + + + BID + 5108 + + + OSVDB + 5172 + + + XF + mscs-owc-installer-bo(9424) + + Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer. + + + + + + + + + + + cpe:/a:microsoft:commerce_server:2000 + cpe:/a:microsoft:commerce_server:2000:sp1 + cpe:/a:microsoft:commerce_server:2000:sp2 + + CVE-2002-0622 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:35.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-033 + + + BID + 5111 + + + OSVDB + 5170 + + + XF + mscs-owc-installer-permissions(9425) + + The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution". + + + + + + + + + + + + cpe:/a:microsoft:commerce_server:2000 + cpe:/a:microsoft:commerce_server:2002 + cpe:/a:microsoft:commerce_server:2000:sp1 + cpe:/a:microsoft:commerce_server:2000:sp2 + + CVE-2002-0623 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:30.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-033 + + + BID + 5112 + + + OSVDB + 5163 + + + XF + mscs-authfilter-isapi-bo-variant(9426) + + Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun". + + + + + + + + + + cpe:/a:microsoft:msde:2000 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0624 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:36.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT + CA-2002-22 + + + MS + MS02-034 + + + + + Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure." + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:polycom:viewstation_v.35:6.5.1 + cpe:/h:polycom:viewstation_128:7.2 + cpe:/h:polycom:viewstation_dcp:6.5.1 + cpe:/h:polycom:viewstation_fx_vs4000:4.1.5 + cpe:/h:polycom:viewstation_mp:7.2 + cpe:/h:polycom:viewstation_h.323:7.2 + cpe:/h:polycom:viewstation_512:7.2 + cpe:/h:polycom:viewstation_sp_384:7.2 + cpe:/h:polycom:viewstation_mp:6.5.1 + cpe:/h:polycom:viewstation_h.323:6.5.1 + cpe:/h:polycom:viewstation_512:6.5.1 + cpe:/h:polycom:viewstation_v.35:7.2 + cpe:/h:polycom:viewstation_128:6.5.1 + cpe:/h:polycom:viewstation_sp_384:6.5.1 + cpe:/h:polycom:viewstation_dcp:7.2 + + CVE-2002-0626 + 2003-01-07T00:00:00.000-05:00 + 2008-09-05T16:28:31.240-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CIAC + M-123 + + + BID + 5631 + + + CONFIRM + http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf + + + XF + viewstation-default-blank-password(9347) + + + ISS + 20020904 Multiple Remote Vulnerabilities in Polycom Videoconferencing Products + + Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities. + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:polycom:viewstation_v.35:6.5.1 + cpe:/h:polycom:viewstation_128:7.2 + cpe:/h:polycom:viewstation_dcp:6.5.1 + cpe:/h:polycom:viewstation_fx_vs4000:4.1.5 + cpe:/h:polycom:viewstation_mp:7.2 + cpe:/h:polycom:viewstation_h.323:7.2 + cpe:/h:polycom:viewstation_512:7.2 + cpe:/h:polycom:viewstation_sp_384:7.2 + cpe:/h:polycom:viewstation_mp:6.5.1 + cpe:/h:polycom:viewstation_h.323:6.5.1 + cpe:/h:polycom:viewstation_512:6.5.1 + cpe:/h:polycom:viewstation_v.35:7.2 + cpe:/h:polycom:viewstation_128:6.5.1 + cpe:/h:polycom:viewstation_sp_384:6.5.1 + cpe:/h:polycom:viewstation_dcp:7.2 + + CVE-2002-0627 + 2003-01-07T00:00:00.000-05:00 + 2008-09-05T16:28:31.430-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CIAC + M-123 + + + BID + 5632 + + + CONFIRM + http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf + + + XF + viewstation-unicode-retrieve-password(9348) + + + ISS + 20020904 Multiple Remote Vulnerabilities in Polycom Videoconferencing Products + + The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests. + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:polycom:viewstation_v.35:6.5.1 + cpe:/h:polycom:viewstation_128:7.2 + cpe:/h:polycom:viewstation_dcp:6.5.1 + cpe:/h:polycom:viewstation_fx_vs4000:4.1.5 + cpe:/h:polycom:viewstation_mp:7.2 + cpe:/h:polycom:viewstation_h.323:7.2 + cpe:/h:polycom:viewstation_512:7.2 + cpe:/h:polycom:viewstation_sp_384:7.2 + cpe:/h:polycom:viewstation_mp:6.5.1 + cpe:/h:polycom:viewstation_h.323:6.5.1 + cpe:/h:polycom:viewstation_512:6.5.1 + cpe:/h:polycom:viewstation_v.35:7.2 + cpe:/h:polycom:viewstation_128:6.5.1 + cpe:/h:polycom:viewstation_sp_384:6.5.1 + cpe:/h:polycom:viewstation_dcp:7.2 + + CVE-2002-0628 + 2003-01-07T00:00:00.000-05:00 + 2008-09-05T16:28:31.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + M-123 + + + BID + 5635 + + + CONFIRM + http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf + + + XF + viewstation-telnet-login-dos(9349) + + + ISS + 20020904 Multiple Remote Vulnerabilities in Polycom Videoconferencing Products + + + XF + viewstation-telnet-login-info-disclosure(44241) + + The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack. + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:polycom:viewstation_v.35:6.5.1 + cpe:/h:polycom:viewstation_128:7.2 + cpe:/h:polycom:viewstation_dcp:6.5.1 + cpe:/h:polycom:viewstation_fx_vs4000:4.1.5 + cpe:/h:polycom:viewstation_mp:7.2 + cpe:/h:polycom:viewstation_h.323:7.2 + cpe:/h:polycom:viewstation_512:7.2 + cpe:/h:polycom:viewstation_sp_384:7.2 + cpe:/h:polycom:viewstation_mp:6.5.1 + cpe:/h:polycom:viewstation_h.323:6.5.1 + cpe:/h:polycom:viewstation_512:6.5.1 + cpe:/h:polycom:viewstation_v.35:7.2 + cpe:/h:polycom:viewstation_128:6.5.1 + cpe:/h:polycom:viewstation_sp_384:6.5.1 + cpe:/h:polycom:viewstation_dcp:7.2 + + CVE-2002-0629 + 2003-01-07T00:00:00.000-05:00 + 2008-09-05T16:28:31.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + M-123 + + + BID + 5636 + + + CONFIRM + http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf + + + XF + viewstation-telnet-login-dos(9349) + + + ISS + 20020904 Multiple Remote Vulnerabilities in Polycom Videoconferencing Products + + The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server. + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:polycom:viewstation_v.35:6.5.1 + cpe:/h:polycom:viewstation_128:7.2 + cpe:/h:polycom:viewstation_dcp:6.5.1 + cpe:/h:polycom:viewstation_fx_vs4000:4.1.5 + cpe:/h:polycom:viewstation_mp:7.2 + cpe:/h:polycom:viewstation_h.323:7.2 + cpe:/h:polycom:viewstation_512:7.2 + cpe:/h:polycom:viewstation_sp_384:7.2 + cpe:/h:polycom:viewstation_mp:6.5.1 + cpe:/h:polycom:viewstation_h.323:6.5.1 + cpe:/h:polycom:viewstation_512:6.5.1 + cpe:/h:polycom:viewstation_v.35:7.2 + cpe:/h:polycom:viewstation_128:6.5.1 + cpe:/h:polycom:viewstation_sp_384:6.5.1 + cpe:/h:polycom:viewstation_dcp:7.2 + + CVE-2002-0630 + 2003-01-07T00:00:00.000-05:00 + 2008-09-05T16:28:31.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CIAC + M-123 + + + BID + 5637 + + + CONFIRM + http://www.polycom.com/common/pw_item_show_doc/0,,1444,00.pdf + + + XF + viewstation-icmp-dos(9350) + + + ISS + 20020904 Multiple Remote Vulnerabilities in Polycom Videoconferencing Products + + The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + + CVE-2002-0631 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:36.727-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + SGI + 20020607-02-I + + + BID + 5092 + + + XF + irix-nveventd-file-write(9418) + + Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + + CVE-2002-0632 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:36.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5448 + + + XF + irix-bds-unauth-access(9825) + + + SGI + 20020804-01-P + + + OSVDB + 11081 + + Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.52 + + CVE-2002-0637 + 2002-07-11T00:00:00.000-04:00 + 2008-09-05T16:28:32.537-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.securiteam.com/securitynews/5KP000A7QE.html + + + XF + interscan-viruswall-protection-bypass(9464) + + InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2 + cpe:/o:redhat:linux:7.2::alpha + cpe:/o:redhat:linux:6.0::alpha + cpe:/o:redhat:linux:6.1::alpha + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.2 + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:mandrakesoft:mandrake_linux:8.1::ia64 + cpe:/o:mandrakesoft:mandrake_linux:7.0 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:6.1 + cpe:/o:redhat:linux:6.0 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:6.0::sparc + cpe:/o:redhat:linux:6.1::sparc + cpe:/o:redhat:linux:7.0 + cpe:/o:redhat:linux:7.3 + + CVE-2002-0638 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:37.663-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#405955 + + + REDHAT + RHSA-2002:132 + + + BID + 5344 + + + REDHAT + RHSA-2002:137 + + + OSVDB + 5164 + + + MANDRAKE + MDKSA-2002:047 + + + XF + utillinux-chfn-race-condition(9709) + + + HP + HPSBTL0207-054 + + + BUGTRAQ + 20020729 RAZOR advisory: Linux util-linux chfn local root vulnerability + + + CONECTIVA + CLA-2002:523 + + + BUGTRAQ + 20020730 TSLSA-2002-0064 - util-linux + + + VULNWATCH + 20020729 [VulnWatch] RAZOR advisory: Linux util-linux chfn local root vulnerability + + + CALDERA + CSSA-2002-043.0 + + setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:openbsd:openssh:3.2.3p1 + cpe:/a:openbsd:openssh:3.1 + cpe:/a:openbsd:openssh:3.0 + cpe:/a:openbsd:openssh:3.3 + cpe:/a:openbsd:openssh:3.2 + cpe:/a:openbsd:openssh:3.2.2p1 + cpe:/a:openbsd:openssh:1.2.2 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:openbsd:openssh:2.9.9 + cpe:/a:openbsd:openssh:3.1p1 + cpe:/a:openbsd:openssh:3.0.2p1 + cpe:/a:openbsd:openssh:2.9p1 + cpe:/a:openbsd:openssh:2.9p2 + cpe:/a:openbsd:openssh:2.5 + cpe:/a:openbsd:openssh:2.9 + cpe:/a:openbsd:openssh:3.3p1 + cpe:/a:openbsd:openssh:3.0.1 + cpe:/a:openbsd:openssh:2.5.2 + cpe:/a:openbsd:openssh:3.0.2 + cpe:/a:openbsd:openssh:3.0p1 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:openbsd:openssh:3.0.1p1 + cpe:/a:openbsd:openssh:2.3 + cpe:/a:openbsd:openssh:2.5.1 + + CVE-2002-0639 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:37.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#369347 + + + CERT + CA-2002-18 + + + HP + HPSBUX0206-195 + + + BID + 5093 + + + OSVDB + 6245 + + + MANDRAKE + MDKSA-2002:040 + + + ENGARDE + ESA-20020702-016 + + + XF + openssh-challenge-response-bo(9169) + + + DEBIAN + DSA-134 + + + BUGTRAQ + 20020627 How to reproduce OpenSSH Overflow. + + + BUGTRAQ + 20020626 Revised OpenSSH Security Advisory (adv.iss) + + + BUGTRAQ + 20020626 OpenSSH Security Advisory (adv.iss) + + + CONECTIVA + CLA-2002:502 + + + BUGTRAQ + 20020626 [OpenPKG-SA-2002.005] OpenPKG Security Advisory (openssh) + + + CALDERA + CSSA-2002-030.0 + + Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:openbsd:openssh:3.2.3p1 + cpe:/a:openbsd:openssh:3.1 + cpe:/a:openbsd:openssh:3.0 + cpe:/a:openbsd:openssh:3.3 + cpe:/a:openbsd:openssh:3.2 + cpe:/a:openbsd:openssh:3.2.2p1 + cpe:/a:openbsd:openssh:1.2.2 + cpe:/a:openbsd:openssh:1.2.3 + cpe:/a:openbsd:openssh:2.9.9 + cpe:/a:openbsd:openssh:3.1p1 + cpe:/a:openbsd:openssh:3.0.2p1 + cpe:/a:openbsd:openssh:2.9p1 + cpe:/a:openbsd:openssh:2.9p2 + cpe:/a:openbsd:openssh:2.5 + cpe:/a:openbsd:openssh:2.9 + cpe:/a:openbsd:openssh:3.3p1 + cpe:/a:openbsd:openssh:3.0.1 + cpe:/a:openbsd:openssh:2.5.2 + cpe:/a:openbsd:openssh:3.0.2 + cpe:/a:openbsd:openssh:3.0p1 + cpe:/a:openbsd:openssh:2.1 + cpe:/a:openbsd:openssh:2.1.1 + cpe:/a:openbsd:openssh:2.2 + cpe:/a:openbsd:openssh:3.0.1p1 + cpe:/a:openbsd:openssh:2.3 + cpe:/a:openbsd:openssh:2.5.1 + + CVE-2002-0640 + 2002-07-03T00:00:00.000-04:00 + 2008-09-10T15:12:37.867-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#369347 + + + CERT + CA-2002-18 + + + HP + HPSBUX0206-195 + + + BID + 5093 + + + REDHAT + RHSA-2002:131 + + + REDHAT + RHSA-2002:127 + + + OSVDB + 839 + + + SUSE + SuSE-SA:2002:024 + + + MANDRAKE + MDKSA-2002:040 + + + ENGARDE + ESA-20020702-016 + + + DEBIAN + DSA-134 + + + BUGTRAQ + 20020628 Sun statement on the OpenSSH Remote Challenge Vulnerability + + + BUGTRAQ + 20020627 How to reproduce OpenSSH Overflow. + + + BUGTRAQ + 20020626 Revised OpenSSH Security Advisory (adv.iss) + + + BUGTRAQ + 20020626 OpenSSH Security Advisory (adv.iss) + + + CONECTIVA + CLA-2002:502 + + + CALDERA + CSSA-2002-030.0 + + Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt). + + + + + + + + + + cpe:/a:microsoft:msde:2000 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0641 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:37.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#682620 + + + MS + MS02-034 + + + BUGTRAQ + 20020711 Microsoft SQL Server 2000 'BULK INSERT' Buffer Overflow (#NISR11072002) + + + BID + 4847 + + + MISC + http://www.ngssoftware.com/advisories/ms-sqlbi.txt + + + + + Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query. + + + + + + + + + + cpe:/a:microsoft:msde:2000 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0642 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:33.490-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#796313 + + + CERT + CA-2002-22 + + + MS + MS02-034 + + + BID + 5205 + + + XF + mssql-registry-insecure-permissions(9523) + + + + + The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key." + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2002-0643 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:38.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#338195 + + + MS + MS02-035 + + + BUGTRAQ + 20020711 SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file + + + BID + 5203 + + + VULN-DEV + 20020711 SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file + + The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System." + + + + + + + + + + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0644 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:33.803-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-038 + + Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code. + + + + + + + + + + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0645 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:33.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-038 + + SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands. + + + CVE-2002-0646 + 2005-05-02T00:00:00.000-04:00 + 2008-09-10T15:12:39.023-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0371. Reason: This candidate is a reservation duplicate of CVE-2002-0371. Notes: CVE-2002-0371 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0647 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:39.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-047 + + + BID + 5558 + + + XF + ms-legacytext-activex-bo(9935) + + Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control". + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0648 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:39.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + + + MS + MS02-047 + + + BUGTRAQ + 20020823 Accessing remote/local content in IE (GM#009-IE) + + + BID + 5560 + + + XF + ie-xml-redirect-read-files(9936) + + + + + + + + + + + + + + + + + The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0649 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:39.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + CERT-VN + VU#484891 + + + CERT-VN + VU#399260 + + + CERT + CA-2003-04 + + + CERT + CA-2002-22 + + + MS + MS02-039 + + + BID + 5310 + + + BUGTRAQ + 20030201 The Spread of the Sapphire/Slammer SQL Worm + + + BUGTRAQ + 20030130 RE: MSDE contained in... + + + BUGTRAQ + 20030129 Re: MSDE contained in... + + + BUGTRAQ + 20030128 Re: MSDE contained in... + + + BUGTRAQ + 20030128 RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + BUGTRAQ + 20030126 Tool: Sapphire SQL Worm Scanner + + + BUGTRAQ + 20030125 Sapphire SQL Worm Analysis Complete + + + BUGTRAQ + 20030126 RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + BUGTRAQ + 20030125 RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + BUGTRAQ + 20030125 SQL Sapphire Worm Analysis + + + BUGTRAQ + 20030125 Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + BUGTRAQ + 20030125 Fw: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + BUGTRAQ + 20030125 MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! + + + NTBUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + + BUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + + + + Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm. + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0650 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:39.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-039 + + + BUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + + BID + 5312 + + + OSVDB + 878 + + + XF + mssql-resolution-keepalive-dos(9662) + + + NTBUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop. + + + + + + + + + cpe:/a:isc:bind:9.4.0 + + CVE-2002-0651 + 2002-07-03T00:00:00.000-04:00 + 2011-03-07T21:08:38.407-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT + CA-2002-19 + + + CERT-VN + VU#803539 + + + MISC + http://www.pine.nl/advisories/pine-cert-20020601.txt + + + XF + dns-resolver-lib-bo(9432) + + + BUGTRAQ + 20020626 Remote buffer overflow in resolver code of libc + + + AIXAPAR + IY32746 + + + BID + 5100 + + + REDHAT + RHSA-2003:154 + + + REDHAT + RHSA-2002:167 + + + REDHAT + RHSA-2002:133 + + + REDHAT + RHSA-2002:119 + + + MANDRAKE + MDKSA-2002:043 + + + REDHAT + RHSA-2002:139 + + + BUGTRAQ + 20020704 [OpenPKG-SA-2002.006] OpenPKG Security Advisory (bind) + + + FREEBSD + FreeBSD-SA-02:28 + + + MANDRAKE + MDKSA-2002:038 + + + CONECTIVA + CLSA-2002:507 + + + NTBUGTRAQ + 20020703 Buffer overflow and DoS i BIND + + + ENGARDE + ESA-20020724-018 + + + SGI + 20020701-01-I + + + NETBSD + NetBSD-SA2002-006 + + + CALDERA + CSSA-2002-SCO.37 + + + CALDERA + CSSA-2002-SCO.39 + + + + + Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + + CVE-2002-0652 + 2002-07-03T00:00:00.000-04:00 + 2008-09-05T16:28:35.007-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SGI + 20020606-01-I + + + BUGTRAQ + 20020620 [LSD] IRIX rpc.xfsmd multiple remote root vulnerabilities + + + SGI + 20020605-01-I + + xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs(). + + + + + + + + + cpe:/a:mod_ssl:mod_ssl:2.8.9 + + CVE-2002-0653 + 2002-07-11T00:00:00.000-04:00 + 2008-09-10T15:12:39.853-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5084 + + + REDHAT + RHSA-2003:106 + + + REDHAT + RHSA-2002:146 + + + REDHAT + RHSA-2002:136 + + + REDHAT + RHSA-2002:135 + + + REDHAT + RHSA-2002:134 + + + SUSE + SuSE-SA:2002:028 + + + MANDRAKE + MDKSA-2002:048 + + + XF + apache-modssl-htaccess-bo(9415) + + + DEBIAN + DSA-135 + + + REDHAT + RHSA-2002:164 + + + VULN-DEV + 20020622 Another flaw in Apache? + + + ENGARDE + ESA-20020702-017 + + + BUGTRAQ + 20020624 Apache mod_ssl off-by-one vulnerability + + + CONECTIVA + CLA-2002:504 + + + HP + HPSBTL0207-052 + + + BUGTRAQ + 20020628 TSL-2002-0058 - apache/mod_ssl + + + CALDERA + CSSA-2002-031.0 + + Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries. + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.38 + cpe:/a:apache:http_server:2.0.37 + cpe:/a:apache:http_server:2.0.28:beta:win32 + cpe:/a:apache:http_server:2.0.36 + cpe:/a:apache:http_server:2.0.35 + cpe:/a:apache:http_server:2.0.32:beta:win32 + cpe:/a:apache:http_server:2.0.34:beta:win32 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:2.0.28:beta + cpe:/a:apache:http_server:2.0.39 + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:2.0.28 + + CVE-2002-0654 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:39.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020816 Apache 2.0.39 directory traversal and path disclosure bug + + + BID + 5486 + + + BID + 5485 + + + XF + apache-cgi-path-disclosure(9876) + + + XF + apache-var-path-disclosure(9875) + + + CONFIRM + http://www.apache.org/dist/httpd/CHANGES_2.0 + + Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:http_server:9.2.0 + cpe:/a:openssl:openssl:0.9.2b + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.2 + cpe:/a:oracle:application_server + cpe:/o:apple:mac_os_x:10.1 + cpe:/a:openssl:openssl:0.9.6d + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/a:openssl:openssl:0.9.6c + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/a:openssl:openssl:0.9.3 + cpe:/a:openssl:openssl:0.9.4 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/a:openssl:openssl:0.9.6b + cpe:/a:openssl:openssl:0.9.5 + cpe:/o:apple:mac_os_x:10.0.2 + cpe:/a:openssl:openssl:0.9.6a + cpe:/a:openssl:openssl:0.9.6 + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:corporate_time_outlook_connector:3.3 + cpe:/a:openssl:openssl:0.9.1c + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:openssl:openssl:0.9.7:beta2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:openssl:openssl:0.9.5a + cpe:/a:openssl:openssl:0.9.7:beta1 + cpe:/a:oracle:http_server:9.0.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1 + + CVE-2002-0655 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:39.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#308891 + + + CERT + CA-2002-23 + + + BID + 5364 + + + MANDRAKE + MDKSA-2002:046 + + + CONECTIVA + CLA-2002:513 + + + FREEBSD + FreeBSD-SA-02:33 + + + CALDERA + CSSA-2002-033.1 + + + CALDERA + CSSA-2002-033.0 + + OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:http_server:9.2.0 + cpe:/a:openssl:openssl:0.9.2b + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.2 + cpe:/a:oracle:application_server + cpe:/o:apple:mac_os_x:10.1 + cpe:/a:openssl:openssl:0.9.6d + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/a:openssl:openssl:0.9.6c + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/a:openssl:openssl:0.9.3 + cpe:/a:openssl:openssl:0.9.4 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/a:openssl:openssl:0.9.6b + cpe:/a:openssl:openssl:0.9.5 + cpe:/o:apple:mac_os_x:10.0.2 + cpe:/a:openssl:openssl:0.9.6a + cpe:/a:openssl:openssl:0.9.6 + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:corporate_time_outlook_connector:3.3 + cpe:/a:openssl:openssl:0.9.1c + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:openssl:openssl:0.9.7:beta2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:openssl:openssl:0.9.5a + cpe:/a:openssl:openssl:0.9.7:beta1 + cpe:/a:oracle:http_server:9.0.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1 + + CVE-2002-0656 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:40.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#258555 + + + CERT-VN + VU#102795 + + + CERT + CA-2002-23 + + + BID + 5363 + + + BID + 5362 + + + MANDRAKE + MDKSA-2002:046 + + + XF + openssl-ssl2-masterkey-bo(9714) + + + CONECTIVA + CLA-2002:513 + + + FREEBSD + FreeBSD-SA-02:33 + + + CALDERA + CSSA-2002-033.1 + + + CALDERA + CSSA-2002-033.0 + + + XF + openssl-ssl3-sessionid-bo(9716) + + Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3. + + + + + + + + + + cpe:/a:openssl:openssl:0.9.7:beta2 + cpe:/a:openssl:openssl:0.9.7:beta1 + + CVE-2002-0657 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:40.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT + CA-2002-23 + + + CERT-VN + VU#561275 + + + BID + 5361 + + + MANDRAKE + MDKSA-2002:046 + + + XF + openssl-ssl3-masterkey-bo(9715) + + + CONECTIVA + CLA-2002:513 + + + FREEBSD + FreeBSD-SA-02:33 + + + CALDERA + CSSA-2002-033.1 + + + CALDERA + CSSA-2002-033.0 + + Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ossp:mm:1.0.6 + cpe:/a:ossp:mm:1.0.7 + cpe:/a:ossp:mm:1.0.8 + cpe:/a:ossp:mm:1.0.9 + cpe:/a:ossp:mm:1.0.2 + cpe:/a:ossp:mm:1.0.3 + cpe:/a:ossp:mm:1.0.4 + cpe:/a:ossp:mm:1.0.5 + cpe:/a:ossp:mm:1.0.0 + cpe:/a:ossp:mm:1.0.10 + cpe:/a:ossp:mm:1.0.1 + cpe:/a:ossp:mm:1.0.12 + cpe:/a:ossp:mm:1.0.11 + cpe:/a:ossp:mm:1.1.0 + cpe:/a:ossp:mm:1.1.1 + cpe:/a:ossp:mm:1.1.2 + cpe:/a:ossp:mm:1.1.3 + + CVE-2002-0658 + 2002-08-12T00:00:00.000-04:00 + 2013-09-04T00:18:30.637-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MANDRAKE + MDKSA-2002:045 + + + FREEBSD + FreeBSD-SN-02:05 + + + BID + 5352 + + + REDHAT + RHSA-2003:158 + + + REDHAT + RHSA-2002:163 + + + SUSE + SuSE-SA:2002:028 + + + XF + mm-tmpfile-symlink(9719) + + + DEBIAN + DSA-137 + + + REDHAT + RHSA-2002:164 + + + REDHAT + RHSA-2002:156 + + + REDHAT + RHSA-2002:154 + + + REDHAT + RHSA-2002:153 + + + HP + HPSBTL0208-056 + + + CALDERA + CSSA-2002-032.0 + + OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:http_server:9.2.0 + cpe:/a:openssl:openssl:0.9.2b + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1.2 + cpe:/a:oracle:application_server + cpe:/o:apple:mac_os_x:10.1 + cpe:/a:openssl:openssl:0.9.6d + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/a:openssl:openssl:0.9.6c + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/a:openssl:openssl:0.9.3 + cpe:/a:openssl:openssl:0.9.4 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/a:openssl:openssl:0.9.6b + cpe:/a:openssl:openssl:0.9.5 + cpe:/o:apple:mac_os_x:10.0.2 + cpe:/a:openssl:openssl:0.9.6a + cpe:/a:openssl:openssl:0.9.6 + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:corporate_time_outlook_connector:3.3 + cpe:/a:openssl:openssl:0.9.1c + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:openssl:openssl:0.9.7:beta2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:openssl:openssl:0.9.5a + cpe:/a:openssl:openssl:0.9.7:beta1 + cpe:/a:oracle:http_server:9.0.1 + cpe:/a:oracle:corporate_time_outlook_connector:3.1 + + CVE-2002-0659 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:40.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#748355 + + + CERT + CA-2002-23 + + + BID + 5366 + + + XF + openssl-asn1-parser-dos(9718) + + + REDHAT + RHSA-2002:164 + + + REDHAT + RHSA-2002:161 + + + REDHAT + RHSA-2002:160 + + + CONECTIVA + CLA-2002:516 + + + FREEBSD + FreeBSD-SA-02:33 + + + CALDERA + CSSA-2002-033.1 + + + CALDERA + CSSA-2002-033.0 + + The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. + + + + + + + + + + cpe:/a:greg_roelofs:libpng:1.0.12 + cpe:/a:greg_roelofs:libpng3:1.2.1 + + CVE-2002-0660 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:36.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-140 + + + REDHAT + RHSA-2002:152 + + + REDHAT + RHSA-2002:151 + + Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728. + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.38 + cpe:/a:apache:http_server:2.0.37 + cpe:/a:apache:http_server:2.0.28:beta:win32 + cpe:/a:apache:http_server:2.0.36 + cpe:/a:apache:http_server:2.0.35 + cpe:/a:apache:http_server:2.0.32:beta:win32 + cpe:/a:apache:http_server:2.0.34:beta:win32 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:2.0.28:beta + cpe:/a:apache:http_server:2.0.39 + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:2.0.28 + + CVE-2002-0661 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:40.413-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://httpd.apache.org/info/security_bulletin_20020908a.txt + + + BID + 5434 + + + XF + apache-access-data(9808) + + + BUGTRAQ + 20020816 Apache 2.0.39 directory traversal and path disclosure bug + + + BUGTRAQ + 20020809 Apache 2.0 vulnerability affects non-Unix platforms + + Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters. + + + + + + + + + + + + + + + + + + + cpe:/a:dan_mueth:scrollkeeper:0.3.8 + cpe:/a:dan_mueth:scrollkeeper:0.3 + cpe:/a:dan_mueth:scrollkeeper:0.3.7 + cpe:/a:dan_mueth:scrollkeeper:0.3.9 + cpe:/a:dan_mueth:scrollkeeper:0.3.4 + cpe:/a:dan_mueth:scrollkeeper:0.3.3 + cpe:/a:dan_mueth:scrollkeeper:0.3.6 + cpe:/a:dan_mueth:scrollkeeper:0.3.10 + cpe:/a:dan_mueth:scrollkeeper:0.3.5 + cpe:/a:dan_mueth:scrollkeeper:0.3.11 + cpe:/a:dan_mueth:scrollkeeper:0.3.1 + + CVE-2002-0662 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:12:40.493-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:186 + + + DEBIAN + DSA-160 + + + BUGTRAQ + 20020904 GLSA: scrollkeeper + + + BID + 5602 + + + XF + scrollkeeper-tmp-file-symlink(10002) + + + BUGTRAQ + 20020902 The ScrollKeeper Root Trap + + scrollkeeper-get-cl in ScrollKeeper 0.3 to 0.3.11 allows local users to create and overwrite files via a symlink attack on the scrollkeeper-tempfile.x temporary files. + + + + + + + + + + cpe:/a:symantec:norton_internet_security:2001 + cpe:/a:symantec:norton_personal_firewall:2001_3.0.4.91 + + CVE-2002-0663 + 2002-07-26T00:00:00.000-04:00 + 2008-09-10T15:12:40.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ATSTAKE + A071502-1 + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.07.15.html + + + BID + 5237 + + + OSVDB + 4366 + + + XF + norton-fw-http-bo(9579) + + Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request. + + + + + + + + + + cpe:/a:granite_software:zmerge:4.0 + cpe:/a:granite_software:zmerge:5.0 + + CVE-2002-0664 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:12:40.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5101 + + + XF + zmerge-admindb-script-access(10057) + + + BUGTRAQ + 20020906 Rapid 7 Advisory R7-0005: ZMerge Insecure Default ACLs + + The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts. + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-0665 + 2002-07-11T00:00:00.000-04:00 + 2008-09-10T15:12:40.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23164 + + + BID + 5118 + + + XF + jrun-forwardslash-auth-bypass(9450) + + + BUGTRAQ + 20020628 wp-02-0009: Macromedia JRun Admin Server Authentication Bypass + + + VULNWATCH + 20020628 [VulnWatch] wp-02-0009: Macromedia JRun Admin Server Authentication Bypass + + Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.6:stable + cpe:/h:nec:ix2010 + cpe:/h:nec:ix1011 + cpe:/a:frees_wan:frees_wan:1.9 + cpe:/o:netbsd:netbsd:1.5::x86 + cpe:/h:nec:ix1010 + cpe:/o:freebsd:freebsd:4.6 + cpe:/o:apple:mac_os_x_server:10.2 + cpe:/h:nec:ix1050 + cpe:/o:apple:mac_os_x:10.2 + cpe:/h:nec:ix1020 + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:freebsd:freebsd:4.6:release + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/a:frees_wan:frees_wan:1.9.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/a:frees_wan:frees_wan:1.9.4 + cpe:/h:global_technology_associates:gnat_box_firmware:3.2 + cpe:/a:frees_wan:frees_wan:1.9.5 + cpe:/o:netbsd:netbsd:1.6:beta + cpe:/h:global_technology_associates:gnat_box_firmware:3.3 + cpe:/h:nec:bluefire_ix1035_router + cpe:/a:frees_wan:frees_wan:1.9.2 + cpe:/a:frees_wan:frees_wan:1.9.3 + cpe:/h:global_technology_associates:gnat_box_firmware:3.1 + cpe:/a:frees_wan:frees_wan:1.9.6 + cpe:/o:netbsd:netbsd:1.5::sh3 + + CVE-2002-0666 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:12:40.867-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#459371 + + + BID + 6011 + + + XF + ipsec-packet-integer-overflow(10411) + + + DEBIAN + DSA-201 + + + BINDVIEW + 20021018 Denial of Service in IPSEC implementations + + + NETBSD + NetBSD-SA2002-016 + + IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0667 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:40.977-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5214 + + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + XF + pingtel-xpressa-default-password(9562) + + + ATSTAKE + A071202-1 + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0668 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:37.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + pingtel-xpressa-call-hijacking(9563) + + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + OSVDB + 5144 + + + ATSTAKE + A071202-1 + + The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0669 + 2003-02-19T00:00:00.000-05:00 + 2008-09-05T16:28:38.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + ATSTAKE + A071202-1 + + + XF + pingtel-xpressa-web-dos(9564) + + The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify the user when an authentication failure occurs. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0670 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:38.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + XF + pingtel-xpressa-plaintext-passwords(9565) + + + ATSTAKE + A071202-1 + + The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0671 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:41.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + BID + 5224 + + + XF + pingtel-xpressa-dns-spoofing(9566) + + + ATSTAKE + A071202-1 + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0672 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:38.523-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + XF + pingtel-xpressa-factory-defaults(9567) + + + ATSTAKE + A071202-1 + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0673 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:38.677-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + XF + pingtel-xpressa-phone-reregister(9568) + + + ATSTAKE + A071202-1 + + The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perform unauthorized actions. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0674 + 2002-07-23T00:00:00.000-04:00 + 2011-03-07T21:08:40.097-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + pingtel-xpressa-admin-timeout(9569) + + + CONFIRM + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + BID + 5221 + + + ATSTAKE + A071202-1 + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication. + + + + + + + + + + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.7.4 + + CVE-2002-0675 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:41.540-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5223 + + + MISC + http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp + + + XF + pingtel-xpressa-firmware-upgrade(9570) + + + ATSTAKE + A071202-1 + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone. + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.1 + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + + CVE-2002-0676 + 2002-07-11T00:00:00.000-04:00 + 2008-09-05T16:28:39.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5176 + + + OSVDB + 5137 + + + XF + macos-softwareupdate-no-auth(9502) + + + MISC + http://www.cunap.com/~hardingr/projects/osx/exploit.html + + SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:caldera:openunix:8.0 + cpe:/o:compaq:tru64:5.1a + cpe:/a:xi_graphics:dextop:2.1 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sun:solaris:8.0 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.11 + cpe:/a:caldera:unixware:7 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sun:solaris:7.0 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:compaq:tru64:5.0a + cpe:/a:caldera:unixware:7.1_.0 + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:sun:solaris:2.5.1 + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:ibm:aix:5.1 + + CVE-2002-0677 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:41.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + CERT-VN + VU#975403 + + + CERT + CA-2002-20 + + + BUGTRAQ + 20020710 [CORE-20020528] Multiple vulnerabilities in ToolTalk Database server + + + CALDERA + CSSA-2002-SCO.28 + + + SGI + 20021102-02-P + + + + + + + + + + + CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:caldera:openunix:8.0 + cpe:/o:compaq:tru64:5.1a + cpe:/a:xi_graphics:dextop:2.1 + cpe:/a:caldera:unixware:7.0 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.0.1 + cpe:/o:sgi:irix:5.3 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:5.2 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.0 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sun:solaris:8.0 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.4 + cpe:/o:sgi:irix:6.3 + cpe:/o:sgi:irix:6.2 + cpe:/o:sgi:irix:6.1 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sun:solaris:7.0 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:sun:solaris:2.5.1 + cpe:/a:caldera:unixware:7.1.0 + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:ibm:aix:5.1 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-0678 + 2002-07-23T00:00:00.000-04:00 + 2011-03-07T21:08:40.423-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + + CERT-VN + VU#299816 + + + CERT + CA-2002-20 + + + BUGTRAQ + 20020710 [CORE-20020528] Multiple vulnerabilities in ToolTalk Database server + + + AIXAPAR + IY32368 + + + HP + HPSBUX0207-199 + + + BID + 5083 + + + XF + tooltalk-ttdbserverd-tttransaction-symlink(9527) + + + SGI + 20021101-01-P + + + CALDERA + CSSA-2002-SCO.28 + + + + + + + + + + + CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sun:solaris:7.0 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:ibm:aix:4.3.3 + cpe:/o:compaq:tru64:5.0a + cpe:/o:caldera:openunix:8.0 + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:compaq:tru64:5.1a + cpe:/o:sun:solaris:2.5.1 + cpe:/a:caldera:unixware:7.0 + cpe:/a:caldera:unixware:7.1.0 + cpe:/a:xi_graphics:dextop:2.1 + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:ibm:aix:5.1 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-0679 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:41.930-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT-VN + VU#387387 + + + CERT + CA-2002-26 + + + BUGTRAQ + 20020812 ENTERCEPT RICOCHET ADVISORY: Multi-Vendor CDE ToolTalk Database + + + HP + HPSBUX0207-199 + + + BID + 5444 + + + XF + tooltalk-ttdbserverd-ttcreatefile-bo(9822) + + + AIXAPAR + IY32793 + + + AIXAPAR + IY32792 + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F46366&zone_32=category%3Asecurity + + + + + + + + Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure. + + + + + + + + + + + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:2.1.2 + cpe:/a:goahead_software:goahead_webserver:2.1.1 + cpe:/o:montavista_software:hard_hat_linux:1.0 + cpe:/a:orange_software:orange_web_server:2.1 + cpe:/a:goahead_software:goahead_webserver:2.1.3 + cpe:/a:goahead_software:goahead_webserver:2.1.4 + cpe:/a:goahead_software:goahead_webserver:2.1.5 + + CVE-2002-0680 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:42.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULNWATCH + 20020710 [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting + + + BUGTRAQ + 20020719 Re: [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting + + + BUGTRAQ + 20020710 wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting + + Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. + + + + + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:2.1.2 + cpe:/a:goahead_software:goahead_webserver:2.1.1 + cpe:/a:goahead_software:goahead_webserver:2.1.3 + cpe:/a:goahead_software:goahead_webserver:2.1.4 + cpe:/a:goahead_software:goahead_webserver:2.1.5 + + CVE-2002-0681 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:40.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5198 + + + XF + goahead-error-msg-xss(9518) + + + BUGTRAQ + 20020710 wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting + + + VULNWATCH + 20020710 [VulnWatch] wp-02-0001: GoAhead Web Server Directory Traversal + Cross Site Scripting + + Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script. + + + + + + + + + cpe:/a:apache:tomcat:4.0.3 + + CVE-2002-0682 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:40.427-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VULNWATCH + 20020710 [VulnWatch] wp-02-0008: Apache Tomcat Cross Site Scripting + + + XF + tomcat-servlet-xss(9520) + + + BID + 5193 + + + OSVDB + 4973 + + + BUGTRAQ + 20020710 wp-02-0008: Apache Tomcat Cross Site Scripting + + Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet. + + + + + + + + + cpe:/a:pacific_software:carello:1.3 + + CVE-2002-0683 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:40.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5192 + + + OSVDB + 6592 + + + XF + carello-local-file-execution(9521) + + + BUGTRAQ + 20020710 wp-02-0012: Carello 1.3 Remote File Execution + + + VULNWATCH + 20020710 wp-02-0012: Carello 1.3 Remote File Execution + + Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter. + + + + + + + + + + cpe:/a:gnu:glibc:2.2.5 + cpe:/a:isc:bind:4.9.8 + + CVE-2002-0684 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:40.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#542971 + + + REDHAT + RHSA-2002:139 + + + MANDRAKE + MDKSA-2002:050 + + + BUGTRAQ + 20020704 Re: Remote buffer overflow in resolver code of libc + + + CONECTIVA + CLSA-2002:507 + + Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr. + + + + + + + + + + + cpe:/a:pgp:personal_security:7.0.3 + cpe:/a:pgp:freeware:7.0.3 + cpe:/a:pgp:desktop_security:7.0.4 + + CVE-2002-0685 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:40.880-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#821139 + + + CONFIRM + http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.04/hotfix/ReadMe.txt + + + NTBUGTRAQ + 20020710 EEYE: Remote PGP Outlook Encryption Plug-in Vulnerability + + + BID + 5202 + + + OSVDB + 4364 + + + XF + pgp-outlook-heap-overflow(9525) + + + BUGTRAQ + 20020710 EEYE: Remote PGP Outlook Encryption Plug-in Vulnerability + + Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via a large, malformed mail message. + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:6.0 + cpe:/a:iplanet:iplanet_web_server:4.1 + + CVE-2002-0686 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:41.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#612843 + + + BID + 4851 + + + MISC + http://www.nextgenss.com/vna/sun-iws.txt + + + XF + iplanet-search-bo(9506) + + + BUGTRAQ + 20020709 Sun iPlanet Web Server Buffer Overflow (#NISR09072002) + + Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter. + + + + + + + + + cpe:/a:zope:zope:2.5.1b1 + + CVE-2002-0687 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:41.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_2002-04-15/security_alert + + + BID + 5813 + + + REDHAT + RHSA-2002:060 + + + OSVDB + 5166 + + + XF + zope-inject-headers-dos(9621) + + The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers. + + + + + + + + + + cpe:/a:zope:zope:2.5.1 + cpe:/a:zope:zope:2.4.0 + + CVE-2002-0688 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:28:41.333-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.zope.org/Products/Zope/Hotfix_2002-06-14/security_alert + + + BID + 5812 + + + REDHAT + RHSA-2002:060 + + + XF + zope-zcatalog-index-bypass(9610) + + + DEBIAN + DSA-490 + + ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes. + + + + + + + + + cpe:/a:mcafee:epolicy_orchestrator:2.5.1 + + CVE-2002-0690 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:28:41.490-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 7111 + + + ATSTAKE + A031703-1 + + + XF + epolicy-get-format-string(11559) + + + BUGTRAQ + 20030317 McAfee ePolicy Orchestrator Format String Vulnerability (a031703-1) + + + OSVDB + 4375 + + Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings. + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0691 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:43.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-047 + + + BID + 5561 + + + XF + ie-local-resource-xss(9938) + + Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-0189. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/a:microsoft:frontpage_server_extensions:2002 + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/a:microsoft:frontpage_server_extensions:2000 + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-0692 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:43.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#723537 + + + MS + MS02-053 + + + XF + fpse-smarthtml-interpreter-bo(10195) + + + BID + 5804 + + + XF + fpse-smarthtml-interpreter-dos(10194) + + Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_nt:4.0::workstation + + CVE-2002-0693 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:43.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + MS + MS02-055 + + + BID + 5874 + + + XF + win-html-help-bo(10253) + + + BUGTRAQ + 20021010 prover of concept code of windows help overflow + + + BUGTRAQ + 20021009 Thor Larholm security advisory TL#004 + + + BUGTRAQ + 20021003 Buffer Overflow in IE/Outlook HTML Help + + + + + Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_nt:4.0::workstation + + CVE-2002-0694 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:44.023-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-055 + + + XF + win-chm-code-execution(10254) + + + + + The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File." + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:data_access_components:2.5:gold + cpe:/a:microsoft:data_access_components:2.5 + cpe:/a:microsoft:data_access_components:2.6:gold + cpe:/a:microsoft:data_access_components:2.7:gold + cpe:/a:microsoft:data_access_components:2.6 + cpe:/a:microsoft:data_access_components:2.7 + cpe:/a:microsoft:data_access_components:2.12.4202.3 + cpe:/a:microsoft:data_access_components:2.1.1.3711.11:ga + cpe:/a:microsoft:microsoft_data_access_components:2.12.4292.3_ga_clean + cpe:/a:microsoft:data_access_components:1.5 + cpe:/a:microsoft:data_access_components:2.5:sp2 + cpe:/a:microsoft:data_access_components:2.1 + cpe:/a:microsoft:data_access_components:2.6:sp1 + cpe:/a:microsoft:data_access_components:2.6:sp2 + cpe:/a:microsoft:data_access_components:2.0 + cpe:/a:microsoft:data_access_components:2.5:sp1 + + CVE-2002-0695 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:44.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-040 + + + MISC + http://www.nextgenss.com/advisories/mssql-ors.txt + + + BID + 5372 + + + XF + mssql-mdac-openrowset-bo(9734) + + Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command. + + + + + + + + + cpe:/a:microsoft:visual_foxpro:6.0 + + CVE-2002-0696 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:28:42.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5633 + + + MS + MS02-049 + + + XF + ms-foxpro-app-execution(10035) + + + CIAC + M-120 + + Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames. + + + + + + + + + cpe:/a:microsoft:metadirectory_services:2.2 + + CVE-2002-0697 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:44.227-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS02-036 + + + BID + 5308 + + + XF + mms-data-repository-access(9657) + + Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. + + + + + + + + + + + + + cpe:/a:microsoft:exchange_server:5.5:sp1 + cpe:/a:microsoft:exchange_server:5.5:sp4 + cpe:/a:microsoft:exchange_server:5.5:sp3 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.5:sp2 + + CVE-2002-0698 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:44.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-037 + + + MSKB + Q326322 + + + BID + 5306 + + + XF + exchange-imc-ehlo-bo(9658) + + + ISS + 20020724 Remote Buffer Overflow Vulnerability in Microsoft Exchange Server + + Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-0699 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:12:44.367-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS02-048 + + + + + Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML. + + + + + + + + + + cpe:/a:microsoft:content_management_server:2001 + cpe:/a:microsoft:content_management_server:2001:sp1 + + CVE-2002-0700 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:44.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-041 + + + BID + 5420 + + + OSVDB + 4862 + + + XF + mcms-authentication-bo(9783) + + Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise." + + + + + + + + + + cpe:/o:freebsd:freebsd:6.2:stable + cpe:/o:openbsd:openbsd + + CVE-2002-0701 + 2002-07-23T00:00:00.000-04:00 + 2008-09-10T15:12:44.507-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-02:30 + + + BID + 5133 + + + OPENBSD + 20020627 009: SECURITY FIX: June 27, 2002 + + + XF + openbsd-ktrace-gain-privileges(9474) + + ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra privileges. + + + + + + + + + + + + + + + + + cpe:/a:isc:dhcpd:3.0.1:rc3 + cpe:/a:isc:dhcpd:3.0.1:rc4 + cpe:/a:isc:dhcpd:3.0 + cpe:/a:isc:dhcpd:3.0.1:rc5 + cpe:/a:isc:dhcpd:3.0.1:rc6 + cpe:/a:isc:dhcpd:3.0.1:rc1 + cpe:/a:isc:dhcpd:3.0.1:rc2 + cpe:/a:isc:dhcpd:3.0.1:rc7 + cpe:/a:isc:dhcpd:3.0.1:rc8 + + CVE-2002-0702 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:43.693-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2002-12 + + + CERT-VN + VU#854315 + + + BID + 4701 + + + MANDRAKE + MDKSA-2002:037 + + + XF + dhcpd-nsupdate-format-string(9039) + + + SUSE + SuSE-SA:2002:019 + + + VULNWATCH + 20020508 [VulnWatch] [NGSEC-2002-2] ISC DHCPDv3, remote root compromise + + + CALDERA + CSSA-2002-028.0 + + + BUGTRAQ + 20020508 [NGSEC-2002-2] ISC DHCPDv3, remote root compromise + + + CONECTIVA + CLA-2002:483 + + Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response. + + + + + + + + + + + + cpe:/a:gisle_aas:digest-md5:2.16 + cpe:/a:gisle_aas:digest-md5:2.17 + cpe:/a:gisle_aas:digest-md5:2.18 + cpe:/a:gisle_aas:digest-md5:2.19 + + CVE-2002-0703 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:43.850-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4716 + + + MANDRAKE + MDKSA-2002:035 + + + XF + linux-utf8-incorrect-md5(9051) + + + REDHAT + RHSA-2002:081 + + An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + + CVE-2002-0704 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:44.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4699 + + + REDHAT + RHSA-2002:086 + + + XF + linux-netfilter-information-leak(9043) + + + MANDRAKE + MDKSA-2002:030 + + + HP + HPSBTL0205-039 + + + BUGTRAQ + 20020508 [CARTSA-20020402] Linux Netfilter NAT/ICMP code information leak + + The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages. + + + + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter:3.0.3 + cpe:/a:surfcontrol:web_filter:4.1 + cpe:/a:surfcontrol:web_filter:4.0 + cpe:/a:surfcontrol:superscout_web_filter:3.0 + + CVE-2002-0705 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:44.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021002 wp--02-0005: Multiple Vulnerabilities in SuperScout Web Reports Server + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0005.txt + + + BID + 5856 + + + OSVDB + 3489 + + + XF + superscout-webfilter-information-retrieval(10248) + + The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords. + + + + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter:3.0.3 + cpe:/a:surfcontrol:web_filter:4.1 + cpe:/a:surfcontrol:web_filter:4.0 + cpe:/a:surfcontrol:superscout_web_filter:3.0 + + CVE-2002-0706 + 2002-10-10T00:00:00.000-04:00 + 2008-09-05T16:28:44.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021002 wp--02-0005: Multiple Vulnerabilities in SuperScout Web Reports Server + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0005.txt + + + OSVDB + 3491 + + + XF + superscout-webfilter-weak-encryption(10247) + + UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function. + + + + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter:3.0.3 + cpe:/a:surfcontrol:web_filter:4.1 + cpe:/a:surfcontrol:web_filter:4.0 + cpe:/a:surfcontrol:superscout_web_filter:3.0 + + CVE-2002-0707 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:45.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021002 wp--02-0005: Multiple Vulnerabilities in SuperScout Web Reports Server + + + BID + 5854 + + + XF + superscout-webfilter-get-dos(10242) + + The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. + + + + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter:3.0.3 + cpe:/a:surfcontrol:web_filter:4.1 + cpe:/a:surfcontrol:web_filter:4.0 + cpe:/a:surfcontrol:superscout_web_filter:3.0 + + CVE-2002-0708 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:45.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021002 wp--02-0005: Multiple Vulnerabilities in SuperScout Web Reports Server + + + BID + 5857 + + + XF + superscout-webfilter-directory-traversal(10244) + + Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences. + + + + + + + + + + + + cpe:/a:surfcontrol:superscout_web_filter:3.0.3 + cpe:/a:surfcontrol:web_filter:4.1 + cpe:/a:surfcontrol:web_filter:4.0 + cpe:/a:surfcontrol:superscout_web_filter:3.0 + + CVE-2002-0709 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:12:45.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5859 + + + XF + superscout-webfilter-sql-injection(10245) + + + BUGTRAQ + 20021002 wp--02-0005: Multiple Vulnerabilities in SuperScout Web Reports Server + + SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs. + + + + + + + + + + + + + cpe:/a:rod_clark:sendform.cgi:1.4.1 + cpe:/a:rod_clark:sendform.cgi:1.4.2 + cpe:/a:rod_clark:sendform.cgi:1.4 + cpe:/a:rod_clark:sendform.cgi:1.4.3 + cpe:/a:rod_clark:sendform.cgi:1.4.4 + + CVE-2002-0710 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:45.617-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020730 Directory traversal vulnerability in sendform.cgi + + + CONFIRM + http://www.scn.org/~bb615/scripts/sendform.html + + + BID + 5286 + + + OSVDB + 3568 + + + XF + sendform-blurbfile-directory-traversal(9725) + + Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter. + + + + + + + + + + + cpe:/h:hp:trucluster_server:5.1a + cpe:/h:hp:trucluster_server:5.0a + cpe:/h:hp:trucluster_server:5.1 + + CVE-2002-0711 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:12:45.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021105 RE: [security bulletin] SSRT2265 HP TruCluster Server Interconnect + + + BID + 6102 + + + COMPAQ + SSRT2265 + + + XF + hp-trucluster-interconnect-dos(10551) + + Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service. + + + + + + + + + + cpe:/a:entrust:entrust_authority_security_manager:5.0 + cpe:/a:entrust:entrust_authority_security_manager:6.0 + + CVE-2002-0712 + 2004-02-03T00:00:00.000-05:00 + 2008-09-05T16:28:45.320-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#720017 + + + CONFIRM + http://www.kb.cert.org/vuls/id/AAMN-5KKVXC + + + XF + easm-multiple-authorization-bypass(11724) + + + BID + 7284 + + Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations. + + + + + + + + + cpe:/a:squid:squid:2.4.stable6 + + CVE-2002-0713 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:45.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + CONFIRM + http://www.squid-cache.org/Advisories/SQUID-2002_3.txt + + + MANDRAKE + MDKSA-2002:044 + + + REDHAT + RHSA-2002:130 + + + BUGTRAQ + 20020715 TSLSA-2002-0062 - squid + + + BID + 5157 + + + BID + 5156 + + + BID + 5155 + + + XF + squid-msnt-helper-bo(9482) + + + XF + squid-ftp-dir-bo(9481) + + + XF + squid-gopher-bo(9480) + + + REDHAT + RHSA-2002:051 + + + CALDERA + CSSA-2002-046.0 + + Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated. + + + + + + + + + cpe:/a:squid:squid:2.4.stable6 + + CVE-2002-0714 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:45.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + CONFIRM + http://www.squid-cache.org/Advisories/SQUID-2002_3.txt + + + MANDRAKE + MDKSA-2002:044 + + + REDHAT + RHSA-2002:130 + + + BUGTRAQ + 20020715 TSLSA-2002-0062 - squid + + + BID + 5158 + + + OSVDB + 5924 + + + XF + squid-ftp-data-injection(9479) + + + REDHAT + RHSA-2002:051 + + + CONECTIVA + CLA-2002:506 + + + CALDERA + CSSA-2002-046.0 + + FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses. + + + + + + + + + cpe:/a:squid:squid:2.4.stable6 + + CVE-2002-0715 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:45.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/bugs/ + + + CONFIRM + http://www.squid-cache.org/Advisories/SQUID-2002_3.txt + + + MANDRAKE + MDKSA-2002:044 + + + REDHAT + RHSA-2002:130 + + + BUGTRAQ + 20020715 TSLSA-2002-0062 - squid + + + BID + 5154 + + + XF + squid-auth-header-forwarding(9478) + + + REDHAT + RHSA-2002:051 + + + CALDERA + CSSA-2002-046.0 + + Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password. + + + + + + + + + + cpe:/o:sco:openserver:5.0.5 + cpe:/o:sco:openserver:5.0.6 + + CVE-2002-0716 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:45.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020604 SRT Security Advisory (SRT2002-06-04-1711): SCO crontab + + + BID + 4938 + + + XF + openserver-crontab-format-string(9271) + + + VULN-DEV + 20020604 SRT Security Advisory (SRT2002-06-04-1711): SCO crontab + + Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument. + + + + + + + + + + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + + CVE-2002-0717 + 2002-07-26T00:00:00.000-04:00 + 2008-09-05T16:28:46.067-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#929115 + + + CERT + CA-2002-21 + + + BUGTRAQ + 20020722 Advisory 02/2002: PHP remote vulnerability + + + BUGTRAQ + 20020722 PHP Security Advisory: Vulnerability in PHP versions 4.2.0 and 4.2.1 + + + XF + php-multipart-handler-bo(9635) + + PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed. + + + + + + + + + + cpe:/a:microsoft:content_management_server:2001 + cpe:/a:microsoft:content_management_server:2001:sp1 + + CVE-2002-0718 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:46.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-041 + + + BID + 5421 + + + XF + mcms-authoring-file-execution(9784) + + Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." + + + + + + + + + + cpe:/a:microsoft:content_management_server:2001 + cpe:/a:microsoft:content_management_server:2001:sp1 + + CVE-2002-0719 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:46.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-041 + + + BID + 5422 + + + XF + mcms-resource-sql-injection(9785) + + SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-0720 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:46.307-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + MS + MS02-042 + + + BID + 5480 + + + XF + win2k-ncm-gain-privileges(9856) + + + + + A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp4 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2002-0721 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:46.383-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#939675 + + + CERT-VN + VU#818939 + + + CERT-VN + VU#399531 + + + MS + MS02-043 + + + MISC + http://www.ngssoftware.com/advisories/mssql-esppu.txt + + + NTBUGTRAQ + 20020816 Microsoft SQL Server Extended Stored Procdure privilege upgrade vulnerabilities (#NISR15002002A) + + + BUGTRAQ + 20020816 Microsoft SQL Server Extended Stored Procdure privilege upgrade vulnerabilities (#NISR15002002A) + + + NTBUGTRAQ + 20020815 Alert: Microsoft Security Bulletin - MS02-043 + + Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-0722 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:46.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-047 + + + BUGTRAQ + 20020828 Origin of downloaded files can be spoofed in MSIE + + + BID + 5559 + + + OSVDB + 5129 + + + XF + ie-file-origin-spoofing(9937) + + Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing." + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0723 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:46.507-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-047 + + + BID + 5196 + + + XF + ie-object-scripting(9537) + + Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag." + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2002-0724 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:46.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + CERT-VN + VU#250635 + + + CERT-VN + VU#342243 + + + CERT-VN + VU#311619 + + + MS + MS02-045 + + + BUGTRAQ + 20020822 CORE-20020618: Vulnerabilities in Windows SMB (DoS) + + + + + Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service". + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services + + CVE-2002-0725 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:12:46.647-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5484 + + + XF + win-ntfs-bypass-auditing(9869) + + + ATSTAKE + A081602-1 + + NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. + + + + + + + + + cpe:/a:microsoft:tsac_activex_control + + CVE-2002-0726 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:46.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-046 + + + ATSTAKE + A082802-1 + + + BID + 5554 + + + XF + ms-tsac-activex-bo(9934) + + Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field. + + + + + + + + + + + cpe:/a:microsoft:project:2002 + cpe:/a:microsoft:office_web_components:2002 + cpe:/a:microsoft:office_web_components:2000 + + CVE-2002-0727 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:46.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-044 + + + XF + owc-spreadsheet-host-script-execution (8777) + + + BID + 4449 + + + OSVDB + 3006 + + + BUGTRAQ + 20020408 Scripting for the scriptless with OWC in IE (GM#005-IE) + + The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method. + + + + + + + + + + cpe:/a:greg_roelofs:libpng:1.0.14 + cpe:/a:greg_roelofs:libpng:1.2.4 + + CVE-2002-0728 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:47.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MANDRAKE + MDKSA-2002:049 + + + DEBIAN + DSA-140 + + + REDHAT + RHSA-2002:152 + + + CONECTIVA + CLA-2002:512 + + + CONFIRM + ftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200207 + + Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk. + + + + + + + + + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-0729 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.037-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + + NTBUGTRAQ + 20020725 Microsoft SQL Server 2000 Unauthenticated System Compromise (#NISR25072002) + + Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator. + + + + + + + + + cpe:/a:philip_chinery:philip_chinerys_guestbook:1.1 + + CVE-2002-0730 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4566 + + + XF + guestbook-pl-css(8916) + + + BUGTRAQ + 20020421 Philip Chinery's Guestbook 1.1 fails to filter out js/html + + Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage. + + + + + + + + + + + + cpe:/a:vqsoft:vqserver:1.9 + cpe:/a:vqsoft:vqserver:1.9.47 + cpe:/a:vqsoft:vqserver:1.9.55 + cpe:/a:vqsoft:vqserver:1.9.30 + + CVE-2002-0731 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4573 + + + XF + vqserver-samples-css(8935) + + + BUGTRAQ + 20020421 vqServer Demo Files Cross-Site Scripting + + Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl. + + + + + + + + + cpe:/a:levcgi.com:myguestbook:1.0 + + CVE-2002-0732 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4651 + + + XF + myguestbook-cgi-css(8968) + + + BUGTRAQ + 20020430 Levcgi.coms MyGuestbook JavaScript Injection Vulnerability + + + CONFIRM + http://www.levcgi.com/programs.cgi?program=myguestbook&action=history + + Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments. + + + + + + + + + cpe:/a:acme_labs:thttpd:2.20b + + CVE-2002-0733 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4601 + + + XF + thttpd-error-page-css(9029) + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes1.txt + + + CONFIRM + http://www.acme.com/software/thttpd/#releasenotes + + + VULNWATCH + 20020417 Smalls holes on 5 products #1 + + + OSVDB + 5125 + + Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. + + + + + + + + + cpe:/a:michel_valdrighi:b2:0.6_pre + + CVE-2002-0734 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.770-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4673 + + + XF + b2-b2inc-command-execution(9013) + + + BUGTRAQ + 20020506 b2 php remote command execution + + + CONFIRM + http://cafelog.com/ + + b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:c-note:squid_auth_ldap:1.0.1 + cpe:/a:c-note:squid_auth_ldap:2.0 + cpe:/a:padl_software:pam_ldap:build_143 + cpe:/a:c-note:squid_auth_ldap:1.2_b2 + cpe:/a:padl_software:nss_ldap:build_181 + cpe:/a:padl_software:nss_ldap:build_180 + cpe:/a:padl_software:nss_ldap:build_189 + cpe:/a:padl_software:nss_ldap:build_185.2 + cpe:/a:padl_software:nss_ldap:build_185.3 + cpe:/a:padl_software:nss_ldap:build_187 + cpe:/a:padl_software:nss_ldap:build_188 + cpe:/a:c-note:squid_auth_ldap:1.0.2_beta + cpe:/a:padl_software:nss_ldap:build_185.1 + cpe:/a:padl_software:nss_ldap:build_185 + cpe:/a:padl_software:nss_ldap:build_186 + cpe:/a:padl_software:nss_ldap:build_183 + cpe:/a:padl_software:nss_ldap:build_184 + + CVE-2002-0735 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:48.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4679 + + + XF + squidauthldap-logging-format-string(9019) + + + BUGTRAQ + 20020506 ldap vulnerabilities + + + VULN-DEV + 20020506 ldap vulnerabilities + + + VULNWATCH + 20020506 [VulnWatch] ldap vulnerabilities + + Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. + + + + + + + + + + cpe:/a:microsoft:backoffice:4.0 + cpe:/a:microsoft:backoffice:4.5 + + CVE-2002-0736 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.163-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4528 + + + XF + backoffice-bypass-authentication(8862) + + + MSKB + Q316838 + + + BUGTRAQ + 20020416 Back Office Web Administrator Authentication Bypass (#NISR17042002A) + + Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. + + + + + + + + + cpe:/a:sambar:sambar_server:5.1 + + CVE-2002-0737 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.303-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4533 + + + XF + sambar-script-source-disclosure(8876) + + + CONFIRM + http://www.sambar.com/security.htm + + + OSVDB + 5123 + + + BUGTRAQ + 20020417 KPMG-2002012: Sambar Webserver Serverside Fileparse Bypass + + + VULNWATCH + 20020417 [VulnWatch] KPMG-2002012: Sambar Webserver Serverside Fileparse Bypass + + Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character. + + + + + + + + + + + cpe:/a:mhonarc:mhonarc:2.5.1 + cpe:/a:mhonarc:mhonarc:2.5 + cpe:/a:mhonarc:mhonarc:2.5.2 + + CVE-2002-0738 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.443-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4546 + + + XF + mhonarc-script-filtering-bypass(8894) + + + CONFIRM + http://www.mhonarc.org/MHonArc/CHANGES + + + DEBIAN + DSA-163 + + + BUGTRAQ + 20020418 MHonArc v2.5.2 Script Filtering Bypass Vulnerability + + MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax. + + + + + + + + + cpe:/a:postnuke_software_foundation:postcalendar:3.0 + + CVE-2002-0739 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4563 + + + XF + postcalendar-calendar-event-css(8899) + + + BUGTRAQ + 20020420 Vulnerability in PostCalendar + + Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page. + + + + + + + + + + + cpe:/a:slrn_development_team:slrn:0.9.6.2 + cpe:/a:slrn_development_team:slrn:0.9.6.4 + cpe:/a:slrn_development_team:slrn:0.9.6.3 + + CVE-2002-0740 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4569 + + + XF + slrnpull-d-spooldir-bo(8910) + + + BUGTRAQ + 20020430 Re: Slrnpull Buffer Overflow (-d parameter) + + + BUGTRAQ + 20020425 slrnpull -d PoC + + + BUGTRAQ + 20020422 Slrnpull Buffer Overflow (-d parameter) + + Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument. + + + + + + + + + cpe:/a:psychoid:psybnc:2.3 + + CVE-2002-0741 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:49.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4570 + + + XF + psybnc-long-password-dos(8912) + + + BUGTRAQ + 20020423 PsyBNC Remote Dos POC + + + BUGTRAQ + 20020422 Re: psyBNC 2.3 DoS / Bug + + psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, which is not properly terminated by psyBNC. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0742 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.037-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY28880 + + Buffer overflow in pioout on AIX 4.3.3. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0743 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.193-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29516 + + mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0744 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.333-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29517 + + namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0745 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.473-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29518 + + Buffer overflow in uucp in AIX 4.3.3. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0746 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.630-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29583 + + Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-0747 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.770-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29589 + + Buffer overflow in lsmcode in AIX 4.3.3. + + + + + + + + + + + cpe:/a:national_instruments:labview:6.1 + cpe:/a:national_instruments:labview:5.1.1 + cpe:/a:national_instruments:labview:6.0 + + CVE-2002-0748 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:50.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4577 + + + XF + labview-http-get-dos(8919) + + + CONFIRM + http://digital.ni.com/public.nsf/websearch/4C3F86E655E5389886256BA00064B22F?OpenDocument + + + BUGTRAQ + 20020423 LabVIEW Web Server DoS Vulnerability + + + OSVDB + 5119 + + LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations. + + + + + + + + + cpe:/a:cgiscript.net:csmailto + + CVE-2002-0749 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.067-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4579 + + + XF + cgiscript-csmailto-command-execution(8930) + + + BUGTRAQ + 20020423 CGIscript.net - csMailto.cgi - Remote Command Execution + + CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field. + + + + + + + + + cpe:/a:cgiscript.net:csmailto + + CVE-2002-0750 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=5 + + + BUGTRAQ + 20020423 CGIscript.net - csMailto.cgi - Remote Command Execution + + CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field. + + + + + + + + + cpe:/a:cgiscript.net:csmailto + + CVE-2002-0751 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.350-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4579 + + + MISC + http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=5 + + + BUGTRAQ + 20020423 CGIscript.net - csMailto.cgi - Remote Command Execution + + CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters. + + + + + + + + + cpe:/a:cgiscript.net:csmailto + + CVE-2002-0752 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020423 CGIscript.net - csMailto.cgi - Remote Command Execution + + CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file. + + + + + + + + + + cpe:/a:talentsoft:web%2b_server:5.0 + cpe:/a:talentsoft:web%2b_server:4.6 + + CVE-2002-0753 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.647-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4530 + + + XF + webplus-long-cookie-bop(8861) + + + BUGTRAQ + 20020416 Buffer Overrun in Talentsoft's Web+ (3) (#NISR17042002B) + + Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/a:freebsd:heimdal:0.4e + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:4.3:release + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:4.2:stable + cpe:/o:freebsd:freebsd:4.3:stable + cpe:/o:freebsd:freebsd:4.1.1:release + cpe:/a:kth:heimdal:0.4e + + CVE-2002-0754 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.817-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3919 + + + XF + kerberos5-k5su-elevate-privileges(7956) + + + FREEBSD + FreeBSD-SA-02:07 + + Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.4:release + + CVE-2002-0755 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:51.990-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4777 + + + XF + freebsd-k5su-gain-privileges(9125) + + + FREEBSD + FreeBSD-SA-02:24 + + + OSVDB + 4893 + + Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute commands as root. + + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.92.1 + cpe:/a:usermin:usermin:0.7 + cpe:/a:webmin:webmin:0.92 + cpe:/a:webmin:webmin:0.91 + cpe:/a:webmin:webmin:0.96 + cpe:/a:usermin:usermin:0.8 + cpe:/a:webmin:webmin:0.95 + cpe:/a:usermin:usermin:0.9 + cpe:/a:webmin:webmin:0.94 + cpe:/a:webmin:webmin:0.93 + + CVE-2002-0756 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:52.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4694 + + + XF + webmin-usermin-authpage-css(9036) + + + BUGTRAQ + 20020508 [SNS Advisory No.52] Webmin/Usermin Cross-site Scripting Vulnerability + + Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies. + + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.92.1 + cpe:/a:usermin:usermin:0.7 + cpe:/a:webmin:webmin:0.92 + cpe:/a:webmin:webmin:0.91 + cpe:/a:webmin:webmin:0.96 + cpe:/a:usermin:usermin:0.8 + cpe:/a:webmin:webmin:0.95 + cpe:/a:usermin:usermin:0.9 + cpe:/a:webmin:webmin:0.94 + cpe:/a:webmin:webmin:0.93 + + CVE-2002-0757 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:52.287-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4700 + + + MANDRAKE + MDKSA-2002:033 + + + XF + webmin-usermin-sessionid-spoof(9037) + + + BUGTRAQ + 20020508 [SNS Advisory No.53] Webmin/Usermin Session ID Spoofing Vulnerability + + (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations. + + + + + + + + + cpe:/o:suse:suse_linux:8.0::i386 + + CVE-2002-0758 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:50.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4695 + + + XF + suse-sysconfig-command-execution(9040) + + + SUSE + SuSE-SA:2002:016 + + ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are stored and executed in a file. + + + + + + + + + + + + + + + + + + cpe:/a:bzip:bzip2:1.0 + cpe:/a:bzip:bzip2:0.9.0c + cpe:/a:bzip:bzip2:1.0.1 + cpe:/a:bzip:bzip2:0.9.5d + cpe:/a:bzip:bzip2:0.9.0 + cpe:/a:bzip:bzip2:0.9.5b + cpe:/a:bzip:bzip2:0.9.0a + cpe:/a:bzip:bzip2:0.9.5c + cpe:/a:bzip:bzip2:0.9.0b + cpe:/a:bzip:bzip2:0.9.5a + + CVE-2002-0759 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:52.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4774 + + + XF + bzip2-decompression-file-overwrite(9126) + + + FREEBSD + FreeBSD-SA-02:25 + + + CALDERA + CSSA-2002-039.0 + + bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow attackers to overwrite files via a bzip2 archive. + + + + + + + + + + + + + + + + + + cpe:/a:bzip:bzip2:1.0 + cpe:/a:bzip:bzip2:0.9.0c + cpe:/a:bzip:bzip2:1.0.1 + cpe:/a:bzip:bzip2:0.9.5d + cpe:/a:bzip:bzip2:0.9.0 + cpe:/a:bzip:bzip2:0.9.5b + cpe:/a:bzip:bzip2:0.9.0a + cpe:/a:bzip:bzip2:0.9.5c + cpe:/a:bzip:bzip2:0.9.0b + cpe:/a:bzip:bzip2:0.9.5a + + CVE-2002-0760 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:52.757-04:00 + + + 1.2 + LOCAL + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4775 + + + XF + bzip2-decompression-race-condition(9127) + + + FREEBSD + FreeBSD-SA-02:25 + + + CALDERA + CSSA-2002-039.0 + + Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive, which could allow local users to read the files as they are being decompressed. + + + + + + + + + + + + + + + + + + cpe:/a:bzip:bzip2:1.0 + cpe:/a:bzip:bzip2:0.9.0c + cpe:/a:bzip:bzip2:1.0.1 + cpe:/a:bzip:bzip2:0.9.5d + cpe:/a:bzip:bzip2:0.9.0 + cpe:/a:bzip:bzip2:0.9.5b + cpe:/a:bzip:bzip2:0.9.0a + cpe:/a:bzip:bzip2:0.9.5c + cpe:/a:bzip:bzip2:0.9.0b + cpe:/a:bzip:bzip2:0.9.5a + + CVE-2002-0761 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:52.927-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4776 + + + XF + bzip2-compression-symlink(9128) + + + FREEBSD + FreeBSD-SA-02:25 + + + CALDERA + CSSA-2002-039.0 + + bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended. + + + + + + + + + cpe:/o:suse:suse_linux:8.0 + + CVE-2002-0762 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:50.960-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4757 + + + XF + suse-shadow-filesize-limits(9102) + + + SUSE + SuSE-SA:2002:017 + + shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that modify the files. + + + + + + + + + cpe:/a:hp:virtualvault:4.5 + + CVE-2002-0763 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:53.240-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4690 + + + XF + hp-virtualvault-admin-access(9038) + + + HP + HPSBUX0205-193 + + Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server. + + + + + + + + + cpe:/a:phorum:phorum:3.3.2a + + CVE-2002-0764 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:53.380-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4763 + + + XF + phorum-php-command-execution(9107) + + + CONFIRM + http://www.phorum.org/ + + + BUGTRAQ + 20020518 Phorum 3.3.2a has another bug for remote command execution + + + BUGTRAQ + 20020517 Phorum 3.3.2a remote command execution + + Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands. + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/a:openbsd:openssh:3.2.2 + + CVE-2002-0765 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:51.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4803 + + + XF + bsd-sshd-authentication-error(9215) + + + OSVDB + 5113 + + + OPENBSD + 20020522 004: SECURITY FIX: May 22, 2002 + + + BUGTRAQ + 20020527 OpenSSH 3.2.3 released (fwd) + + sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password. + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:openbsd:openbsd:2.9 + + CVE-2002-0766 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:51.320-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#314963 + + + XF + openbsd-file-descriptor-dos(9048) + + + BID + 4708 + + + OSVDB + 5715 + + + OSVDB + 5114 + + + OPENBSD + 20020508 003: SECURITY FIX: May 8, 2002 + + + BUGTRAQ + 20020509 OpenBSD local DoS and root exploit + + OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor. + + + + + + + + + cpe:/a:richard_gooch:simpleinit:2.0.2 + + CVE-2002-0767 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:53.833-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5001 + + + XF + simpleinit-file-descriptor-open(9357) + + + BUGTRAQ + 20020613 simpleinit root exploit - file descriptor left open + + simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges. + + + + + + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:8.0 + cpe:/a:luke_mewburn:lukemftp:1.5 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:7.3 + cpe:/o:suse:suse_linux:6.4 + + CVE-2002-0768 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:53.990-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + lukemftp-pasv-bo(9130) + + + SUSE + SuSE-SA:2002:018 + + Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command. + + + + + + + + + cpe:/h:cisco:ata-186 + + CVE-2002-0769 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.147-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4711 + + + XF + cisco-ata-bypass-auth(9057) + + + XF + cisco-ata-reveal-info(9056) + + + BID + 4712 + + + CISCO + 20020523 ATA-186 Password Disclosure Vulnerability + + + BUGTRAQ + 20020509 Cisco ATA-186 admin password can be trivially circumvented + + The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the attackers to (1) obtain the password from the login screen, or (2) reconfigure the adaptor by modifying certain request parameters. + + + + + + + + + + cpe:/a:id_software:quake_2i_server:3.20 + cpe:/a:id_software:quake_2i_server:3.21 + + CVE-2002-0770 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#970915 + + + BID + 4744 + + + MISC + http://www.quakesrc.org/forum/topicDisplay.php?topicID=160 + + + XF + quake2-unexpanded-var-disclosure(9095) + + + BUGTRAQ + 20020514 Remote quake 2 3.2x server cvar leak + + + OSVDB + 11187 + + Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password." + + + + + + + + + + + + cpe:/a:viewcvs:viewcvs:0.9.2 + cpe:/a:viewcvs:viewcvs:0.9.1 + cpe:/a:viewcvs:viewcvs:0.8 + cpe:/a:viewcvs:viewcvs:0.9 + + CVE-2002-0771 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.443-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4818 + + + XF + viewcvs-css(9112) + + + BUGTRAQ + 20020518 cross-site scripting bug of ViewCVS + + + BUGTRAQ + 20020518 cross-site scripting bug of ViewCVS + + Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters. + + + + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4b + cpe:/a:hosting_controller:hosting_controller:1.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + cpe:/a:hosting_controller:hosting_controller:1.3 + + CVE-2002-0772 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.583-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4759 + + + BUGTRAQ + 20020517 Hosting Controller still have dangerous bugs! + + + XF + hosting-controller-dsnmanager-traversal(9104) + + Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter. + + + + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4b + cpe:/a:hosting_controller:hosting_controller:1.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + cpe:/a:hosting_controller:hosting_controller:1.3 + + CVE-2002-0773 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.740-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020517 Hosting Controller still have dangerous bugs! + + + BID + 4761 + + + XF + hosting-controller-improotdir-commands(9105) + + imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath. + + + + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4b + cpe:/a:hosting_controller:hosting_controller:1.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + cpe:/a:hosting_controller:hosting_controller:1.3 + + CVE-2002-0774 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:54.897-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4779 + + + XF + hosting-controller-default-account(9131) + + + BUGTRAQ + 20020519 Another vulnerability in hosting controller + + Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed. + + + + + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:1.4.1 + cpe:/a:hosting_controller:hosting_controller:1.4b + cpe:/a:hosting_controller:hosting_controller:1.1 + cpe:/a:hosting_controller:hosting_controller:1.4 + cpe:/a:hosting_controller:hosting_controller:1.3 + + CVE-2002-0775 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.053-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://hostingcontroller.com/english/logs/sp2log.html + + + CONFIRM + http://www.hostingcontroller.com/english/patches/ForAll/download/drivebrowse.zip + + + BUGTRAQ + 20020519 Another vulnerability in hosting controller + + browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. + + + + + + + + + cpe:/a:hosting_controller:hosting_controller:2002 + + CVE-2002-0776 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020713 Hosting Controller Vulnerability + + + CONFIRM + http://hostingcontroller.com/english/logs/sp2log.html + + + BID + 5229 + + + XF + hosting-controller-password-modification(9554) + + getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:7.0.1 + cpe:/a:ipswitch:imail:7.1 + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:7.0.7 + cpe:/a:ipswitch:imail:6.4 + cpe:/a:ipswitch:imail:7.0.6 + cpe:/a:ipswitch:imail:6.3 + cpe:/a:ipswitch:imail:7.0.5 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:7.0.3 + cpe:/a:ipswitch:imail:6.0 + cpe:/a:ipswitch:imail:7.0.2 + cpe:/a:ipswitch:imail:6.0.3 + cpe:/a:ipswitch:imail:6.0.4 + cpe:/a:ipswitch:imail:6.0.5 + cpe:/a:ipswitch:imail:6.0.6 + cpe:/a:ipswitch:imail:5.0.8 + cpe:/a:ipswitch:imail:5.0 + cpe:/a:ipswitch:imail:5.0.5 + cpe:/a:ipswitch:imail:5.0.6 + cpe:/a:ipswitch:imail:6.0.1 + cpe:/a:ipswitch:imail:5.0.7 + cpe:/a:ipswitch:imail:6.0.2 + + CVE-2002-0777 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.350-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4780 + + + XF + imail-ldap-bo(9116) + + + BUGTRAQ + 20020520 Foundstone Advisory - Buffer Overflow in Ipswitch Imail 7.1 and prior (fwd) + + Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:cisco:cache_engine_550:3.0 + cpe:/a:cisco:content_engine:590_4.0 + cpe:/a:cisco:content_engine:590_4.1 + cpe:/a:cisco:content_engine:507_2.2.0 + cpe:/h:cisco:cache_engine_550:2.4.0 + cpe:/a:cisco:content_distribution_manager_4650:4.1 + cpe:/h:cisco:content_router_4430 + cpe:/a:cisco:content_distribution_manager_4650:4.0 + cpe:/a:cisco:content_engine:7320 + cpe:/o:cisco:content_router_4430:4.1 + cpe:/o:cisco:content_router_4430:4.0 + cpe:/a:cisco:content_engine:7320_4.0 + cpe:/a:cisco:content_engine:7320_3.1 + cpe:/a:cisco:content_engine:7320_4.1 + cpe:/h:cisco:cache_engine_550:2.2.0 + cpe:/a:cisco:content_engine:590 + cpe:/a:cisco:content_distribution_manager_4630:4.0 + cpe:/a:cisco:content_engine:507_4.1 + cpe:/a:cisco:content_engine:507_4.0 + cpe:/a:cisco:content_engine:507 + cpe:/a:cisco:content_distribution_manager_4630:4.1 + cpe:/h:cisco:cache_engine_570:2.2.0 + cpe:/h:cisco:cache_engine_505:3.0 + cpe:/a:cisco:content_engine:507_3.1 + cpe:/h:cisco:cache_engine_550 + cpe:/a:cisco:content_engine:560 + cpe:/a:cisco:content_distribution_manager_4630 + cpe:/a:cisco:content_engine:590_3.1 + cpe:/a:cisco:content_distribution_manager_4650 + cpe:/a:cisco:content_engine:560_4.0 + cpe:/a:cisco:content_engine:560_4.1 + cpe:/a:cisco:content_engine:560_3.1 + cpe:/h:cisco:cache_engine_570:570 + cpe:/a:cisco:content_engine:560_2.2.0 + cpe:/a:cisco:content_engine:590_2.2.0 + cpe:/h:cisco:cache_engine_505:2.4.0 + cpe:/h:cisco:cache_engine_570:2.4.0 + cpe:/h:cisco:cache_engine_570:3.0 + cpe:/a:cisco:content_engine:7320_2.2.0 + + CVE-2002-0778 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.553-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4751 + + + XF + cisco-cache-content-tcp-forward(9082) + + + CISCO + 20020528 Transparent Cache Engine and Content Engine TCP Relay Vulnerability + + The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP. + + + + + + + + + cpe:/a:novell:bordermanager:3.6:sp1a + + CVE-2002-0779 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULNWATCH + 20020508 [VulnWatch] cqure.net.20020412.bordermanager_36_mv1.a + + + BID + 4696 + + + XF + novell-bordermanager-ftp-dos(9031) + + + BUGTRAQ + 20020508 cqure.net.20020412.bordermanager_36_mv1.a + + FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data. + + + + + + + + + cpe:/a:novell:bordermanager:3.6:sp1a + + CVE-2002-0780 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:55.927-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + novell-bordermanager-ipipx-dos(9032) + + + VULNWATCH + 20020508 [VulnWatch] cqure.net.20020412.bordermanager_36_mv1.a + + + BID + 4697 + + + BUGTRAQ + 20020508 cqure.net.20020412.bordermanager_36_mv1.a + + IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND. + + + + + + + + + cpe:/a:novell:bordermanager:3.6:sp1a + + CVE-2002-0781 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + novell-bordermanager-rtsp-dos(9033) + + + VULNWATCH + 20020508 [VulnWatch] cqure.net.20020412.bordermanager_36_mv1.a + + + BID + 4698 + + + BUGTRAQ + 20020508 cqure.net.20020412.bordermanager_36_mv1.a + + RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND. + + + + + + + + + cpe:/a:novell:bordermanager:3.5 + + CVE-2002-0782 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4726 + + + XF + novell-bordermanager-conntable-dos(9062) + + + BUGTRAQ + 20020510 Re: cqure.net.20020412.bordermanager_36_mv1.a + + Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface. + + + + + + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0.1::win32 + cpe:/a:opera_software:opera_web_browser:6.0.1 + cpe:/a:opera_software:opera_web_browser:6.0::win32 + cpe:/a:opera_software:opera_web_browser:6.0 + cpe:/a:opera_software:opera_web_browser:5.12::win32 + cpe:/a:opera_software:opera_web_browser:5.12 + + CVE-2002-0783 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.367-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4745 + + + XF + opera-sameoriginpolicy-bypass(9096) + + + BUGTRAQ + 20020515 Opera javascript protocoll vulnerability [Sandblad advisory #6] + + Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL. + + + + + + + + + cpe:/a:lysias:lidik_webserver:0.7b + + CVE-2002-0784 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4691 + + + CONFIRM + http://www.lysias.de/send/news/index.php?page=3 + + + XF + lidek-webserver-directory-traversal(9028) + + + BUGTRAQ + 20020507 Lysias Lidik Webserver suffers from a Directory Traversal Vulnerability + + Directory traversal vulnerability in Lysias Lidik web server 0.7b allows remote attackers to list directories via an HTTP request with a ... (modified dot dot). + + + + + + + + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.3 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.8.2616 + cpe:/a:aol:instant_messenger:4.0 + cpe:/a:aol:instant_messenger:4.2 + cpe:/a:aol:instant_messenger:4.8.2646 + cpe:/a:aol:instant_messenger:4.1 + cpe:/a:aol:instant_messenger:4.2.1193 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:4.1.2010 + cpe:/a:aol:instant_messenger:4.7.2480 + cpe:/a:aol:instant_messenger:4.3.2229 + + CVE-2002-0785 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#259435 + + + BID + 4709 + + + XF + aim-addbuddy-bo(9058) + + + BUGTRAQ + 20020508 Hole in AOL Instant Messenger + + + OSVDB + 5109 + + AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow. + + + + + + + + + cpe:/a:critical_path:injoin_directory_server:4.0 + + CVE-2002-0786 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.850-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4718 + + + XF + injoin-admin-interface-view-files(9054) + + + VULNWATCH + 20020510 [VulnWatch] Two (2) Critical Path inJoin V4.0 Directory Server Issues + + iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter. + + + + + + + + + cpe:/a:critical_path:injoin_directory_server:4.0 + + CVE-2002-0787 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:56.990-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4717 + + + XF + injoin-admin-interface-css(9053) + + + VULNWATCH + 20020510 [VulnWatch] Two (2) Critical Path inJoin V4.0 Directory Server Issues + + Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters. + + + + + + + + + + + cpe:/a:pgp:personal_security:7.0.3 + cpe:/a:pgp:corporate_desktop:7.1 + cpe:/a:pgp:freeware:7.0.3 + + CVE-2002-0788 + 2002-08-12T00:00:00.000-04:00 + 2013-08-03T00:27:27.127-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4702 + + + XF + pgp-ntfs-reveal-data(9044) + + + BUGTRAQ + 20020508 NTFS and PGP interact to expose EFS encrypted data + + + CONFIRM + http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txt + + + OSVDB + 4363 + + An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information. + + + + + + + + + cpe:/a:mnogosearch:mnogosearch:3.1.19 + + CVE-2002-0789 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:57.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4724 + + + XF + mnogosearch-search-cgi-bo(9060) + + + MISC + http://www.mnogosearch.org/history.html#log31 + + + CONFIRM + http://www.mnogosearch.org/Download/mnogosearch-3.1.20.tar.gz + + + BUGTRAQ + 20020511 Bug in mnogosearch-3.1.19 + + Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-0790 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:54.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY24556 + + clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges. + + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + cpe:/o:novell:netware:5.1:sp4 + + CVE-2002-0791 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:57.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4693 + + + XF + netware-ftp-dos(9034) + + + VULNWATCH + 20020508 [VulnWatch] cqure.net.20020408.netware_nwftpd.a + + + MISC + http://support.novell.com/cgi-bin/search/searchtid.cgi?/2962252.htm + + + BUGTRAQ + 20020508 Re: cqure.net.20020408.netware_nwftpd.a + + Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length. + + + + + + + + + + + + + + + + + + cpe:/a:cisco:webns:5.0_1.012s + cpe:/a:cisco:webns:5.0_0.038s + cpe:/a:cisco:webns:5.0_2.005s + cpe:/a:cisco:webns:5.1_0.0.10 + cpe:/h:cisco:content_services_switch_11000 + cpe:/a:cisco:webns:4.0_1.053s + + CVE-2002-0792 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:57.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#686939 + + + CERT-VN + VU#330275 + + + BID + 4748 + + + BID + 4747 + + + XF + cisco-css-http-dos(9083) + + + CISCO + 20020515 Content Service Switch Web Management HTTP Processing Vulnerabilities + + The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data. + + + + + + + + + cpe:/a:qnx:rtos:4.25 + + CVE-2002-0793 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:57.913-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4902 + + + XF + qnx-rtos-monitor-f(9231) + + + XF + qnx-rtos-dumper-symlink(9234) + + + XF + qnx-rtos-watcom-sample(9233) + + + XF + qnx-rtos-crttrap-c(9232) + + + BID + 4904 + + + BID + 4903 + + + BID + 4901 + + + BUGTRAQ + 20020531 Multiple vulnerabilities in QNX + + Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility. + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + + CVE-2002-0794 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:58.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4879 + + + XF + freebsd-accept-filter-dos(9209) + + + FREEBSD + FreeBSD-SA-02:26 + + + OSVDB + 5081 + + The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cause a denial of service (network service availability) via a large number of connection attempts, which fills the queue. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.5:stable + + CVE-2002-0795 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:58.223-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4880 + + + XF + freebsd-rc-delete-directories(9217) + + + FREEBSD + FreeBSD-SA-02:27 + + + OSVDB + 5083 + + The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files. + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.8 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:sunos:5.7 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:sunos:5.6 + + CVE-2002-0796 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:55.117-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BID + 4932 + + + XF + solaris-snmpdx-format-string(9241) + + + SUN + 00219 + + + BUGTRAQ + 20020604 Entercept Ricochet Security Advisory: Solaris snmpdx Vulnerabilities + + + + + + + + Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges. + + + + + + + + + + + + + + + + + cpe:/o:sun:sunos:5.8 + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:sunos:5.7 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:sunos:5.6 + + CVE-2002-0797 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:55.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + SUN + 00219 + + + BID + 4933 + + + XF + solaris-mibiisa-bo(9242) + + + BUGTRAQ + 20020604 Entercept Ricochet Security Advisory: Solaris snmpdx Vulnerabilities + + + + + + + + Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges. + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + + CVE-2002-0798 + 2002-08-12T00:00:00.000-04:00 + 2009-03-04T00:12:53.297-05:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 4886 + + + XF + hpux-sd-view-files(9207) + + + HP + HPSBUX0205-194 + + + + + Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service. + + + + + + + + + cpe:/a:youngzsoft:cmailserver:3.30 + + CVE-2002-0799 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:58.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cmailserver-user-bo(9132) + + + BID + 4789 + + + BUGTRAQ + 20020521 YoungZSoft CMailServer overflow, PATCH + WAREZ!@#! + + Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.0 + + CVE-2002-0800 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:59.007-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4912 + + + XF + badblue-directory-contents-disclosure(9239) + + + BUGTRAQ + 20020601 BadBlue Web Server v1.7.0 Directory Contents Disclosure + + BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end. + + + + + + + + + + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-0801 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:59.160-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#703835 + + + CERT + CA-2002-14 + + + BID + 4873 + + + XF + jrun-isapi-host-bo(9194) + + + OSVDB + 5082 + + + BUGTRAQ + 20020529 Addendum to advisory #NISR29052002 (JRun buffer overflow) + + + BUGTRAQ + 20020529 Macromedia JRUN Buffer overflow vulnerability (#NISR29052002) + + + VULNWATCH + 20020529 [VulnWatch] FW: Macromedia JRUN Buffer overflow vulnerability (#NISR29052002) + + Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file. + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.0 + + CVE-2002-0802 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:59.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://marc.theaimsgroup.com/?l=postgresql-general&m=102032794322362 + + + REDHAT + RHSA-2002:149 + + + XF + postgresql-sqlascii-sql-injection(10328) + + The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0803 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:55.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To 2.14.2, 2.16 Prior To 2.16rc2 + + + XF + bugzilla-queryhelp-obtain-information(9300) + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=126801 + + + FREEBSD + FreeBSD-SN-02:05 + + + BID + 4964 + + + MISC + ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A05.asc + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0804 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:59.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To 2.14.2, 2.16 Prior To 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=129466 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + OSVDB + 6394 + + + XF + bugzilla-reversedns-hostname-spoof(9301) + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0805 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:28:59.867-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=134575 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + OSVDB + 6395 + + + XF + bugzilla-world-writable-dir(9302) + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0806 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:00.020-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=141557 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + OSVDB + 5080 + + + XF + bugzilla-edituser-user-delete(9303) + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0807 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:55.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + XF + bugzilla-real-name-xss(9304) + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=146447 + + + BID + 4964 + + Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0808 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:00.333-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=107718 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + XF + bugzilla-masschange-change-groupset(9305) + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0809 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:00.490-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=148674 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + XF + bugzilla-group-permissions-removal(10141) + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0810 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:00.660-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=92263 + + + BID + 4964 + + + REDHAT + RHSA-2002:109 + + + OSVDB + 6399 + + + XF + bugzilla-shadow-database-information(9306) + + + FREEBSD + FreeBSD-SN-02:05 + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails. + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-0811 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:56.210-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=130821 + + + BUGTRAQ + 20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2 + + + BID + 4964 + + Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi. + + + CVE-2002-0812 + 2002-08-12T00:00:00.000-04:00 + 2005-10-20T00:00:00.000-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5436 + + + XF + orinoco-rg-default-snmp(9810) + + + VULNWATCH + 20020813 Foundstone Labs Advisory - Information Leakage in Orinoco and Compaq Access Points [updated] + + + VULNWATCH + 20020809 Foundstone Labs Advisory - Information Leakage in Orinoco and Compaq Access Points + + Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string. + + + + + + + + + + + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:11.3 + cpe:/o:cisco:ios:11.2 + + CVE-2002-0813 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CISCO + 20020730 TFTP Long Filename Vulnerability + + + BID + 5328 + + + OSVDB + 854 + + + XF + cisco-tftp-filename-bo(9700) + + + BUGTRAQ + 20020727 Phenoelit Advisory, 0815 ++ * - Cisco_tftp + + + BUGTRAQ + 20020822 Cisco IOS exploit PoC + + + + + Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename. + + + + + + + + + cpe:/a:vmware:gsx_server:2.0.0_build_2050 + + CVE-2002-0814 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:01.223-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020726 Re: VMware GSX Server Remote Buffer Overflow + + + CONFIRM + http://www.vmware.com/download/gsx_security.html + + + BUGTRAQ + 20020724 VMware GSX Server Remote Buffer Overflow + + + BID + 5294 + + + XF + vmware-gsx-auth-bo(9663) + + + NTBUGTRAQ + 20020805 VMware GSX Server 2.0.1 Release and Security Alert + + Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument. + + + + + + + + + + + cpe:/a:microsoft:ie:6.0.2900 + cpe:/a:mozilla:mozilla + cpe:/a:netscape:navigator + + CVE-2002-0815 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:01.363-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020729 XWT Foundation Advisory: Firewall circumvention possible with all browsers + + + BUGTRAQ + 20020729 RE: XWT Foundation Advisory + + The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain. + + + + + + + + + + + + + + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:5.0 + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:5.1a + cpe:/o:compaq:tru64:4.0f + + CVE-2002-0816 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:57.163-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#229867 + + + BUGTRAQ + 20020719 tru64 proof of concept /bin/su non-exec bypass + + + BID + 5272 + + + XF + tru64-su-bo(9640) + + + COMPAQ + SSRT2257 + + Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument. + + + + + + + + + + + + cpe:/a:william_deich:super:3.18 + cpe:/a:william_deich:super:3.16 + cpe:/a:william_deich:super:3.17 + cpe:/a:william_deich:super:3.12 + + CVE-2002-0817 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:57.243-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-139 + + + BUGTRAQ + 20020731 The SUPER Bug + + + BID + 5367 + + + XF + super-syslog-format-string(9741) + + + VULNWATCH + 20020730 The SUPER Bug + + Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument. + + + + + + + + + cpe:/a:wwwoffle:wwwoffle + + CVE-2002-0818 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:01.850-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-144 + + + SUSE + SuSE-SA:2002:029 + + + BID + 5260 + + + XF + wwwoffle-neg-length-bo(9619) + + + BUGTRAQ + 20020718 wwwoffle-2.7b and prior segfaults with negative Content-Length value + + + CALDERA + CSSA-2002-048.0 + + wwwoffled in World Wide Web Offline Explorer (WWWOFFLE) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative Content-Length value. + + + + + + + + + cpe:/a:artsd:artsd + + CVE-2002-0819 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.007-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULN-DEV + 20020613 Re: LOCAL ROOT EXPLOIT - SUPPORT FULL-DISCLOSURE - LOCAL ROOT EXPLOIT + + + CONFIRM + http://marc.theaimsgroup.com/?l=kde-multimedia&m=102607939232023&w=2 + + + BUGTRAQ + 20020706 LOCAL ROOT EXPLOIT - SUPPORT FULL-DISCLOSURE - LOCAL ROOT EXPLOIT + + Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function. + + + + + + + + + cpe:/o:freebsd:freebsd:4.6 + + CVE-2002-0820 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.147-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20020731 [VulnWatch] FreeBSD <=4.6 kernel problems, yet Linux and *BSD much better than Windows + + + FREEBSD + FreeBSD-SA-02:23 + + + BUGTRAQ + 20020819 Freebsd FD exploit + + + MISC + http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&frame=right&th=d429cd2ef1d3a2b7&seekm=ai6c0q%242289%241%40FreeBSD.csie.NCTU.edu.tw#link16 + + FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges. + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.4 + + CVE-2002-0821 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00005.html + + + CONECTIVA + CLSA-2002:505 + + Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector. + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.4 + + CVE-2002-0822 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.457-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00005.html + + + BID + 5167 + + Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump. + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/a:microsoft:windows_help + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2002-0823 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.613-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MSKB + Q293338 + + + BUGTRAQ + 20020801 Winhelp32 Remote Buffer Overrun + + + BID + 4857 + + + OSVDB + 2991 + + + XF + htmlhelp-item-bo(9746) + + Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:1.1 + cpe:/a:samba:ppp + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.6.1:release_p1 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:2.2.1 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.7 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:freebsd:freebsd:1.1.5.1 + cpe:/o:freebsd:freebsd:1.1.5 + cpe:/o:freebsd:freebsd:2.1.5 + cpe:/o:freebsd:freebsd:2.1.6 + cpe:/o:freebsd:freebsd:2.1.7 + cpe:/o:freebsd:freebsd:2.0.5 + cpe:/o:freebsd:freebsd:1.0 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:2.1.0 + + CVE-2002-0824 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:02.787-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-02:32.pppd + + + BID + 5355 + + + OPENBSD + 20020729 011: SECURITY FIX: July 29, 2002 + + + XF + pppd-race-condition(9738) + + + NETBSD + NetBSD-SA2002-010 + + BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device. + + + + + + + + + cpe:/a:padl_software:nss_ldap:198 + + CVE-2002-0825 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:03.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.padl.com/Articles/PotentialBufferOverflowin.html + + Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + cpe:/a:ipswitch:ws_ftp_server:3.1.1 + + CVE-2002-0826 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:58.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html + + + ATSTAKE + A080802-1 + + + BID + 5427 + + + XF + wsftp-site-cpwd-bo(9794) + + Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0827 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:03.317-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5051 + + + XF + ppptalk-local-elevated-privileges(9380) + + + CALDERA + CSSA-2002-SCO.27.txt + + Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824. + + + CVE-2002-0828 + 2002-08-12T00:00:00.000-04:00 + 2008-09-10T15:12:58.820-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0862. Reason: This is a duplicate of CVE-2002-0862. Notes: All CVE users should reference CVE-2002-0862 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/o:freebsd:freebsd:4.6.1:release_p4 + + CVE-2002-0829 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:03.567-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-02:35.ffs + + + BID + 5399 + + + OSVDB + 5073 + + + XF + freebsd-ffs-integer-overflow(9771) + + Integer overflow in the Berkeley Fast File System (FFS) in FreeBSD 4.6.1 RELEASE-p4 and earlier allows local users to access arbitrary file contents within FFS to gain privileges by creating a file that is larger than allowed by the virtual memory system. + + + + + + + + + cpe:/o:freebsd:freebsd:4.6.1:release_p7 + + CVE-2002-0830 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:03.707-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-02:36.nfs + + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + XF + bsd-nfs-rpc-dos(9772) + + + BID + 5402 + + + OSVDB + 5072 + + + NETBSD + NetBSD-SA2002-013 + + Network File System (NFS) in FreeBSD 4.6.1 RELEASE-p7 and earlier, NetBSD 1.5.3 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service (hang) via an RPC message with a zero length payload, which causes NFS to reference a previous payload and enter an infinite loop. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.6:release + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.4:release + cpe:/o:freebsd:freebsd:4.3:release + cpe:/o:freebsd:freebsd:4.6:stable + + CVE-2002-0831 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:03.863-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + FREEBSD + FreeBSD-SA-02:37.kqueue + + + BID + 5405 + + + OSVDB + 5069 + + + XF + freebsd-kqueue-dos(9774) + + The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allows local users to cause a denial of service (kernel panic) via a pipe call in which one end is terminated and an EVFILT_WRITE filter is registered for the other end. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0832 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:04.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020804 Bypassing cookie restrictions in IE 5+6 + + Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature. + + + + + + + + + + cpe:/a:qualcomm:eudora:5.0j + cpe:/a:qualcomm:eudora:5.1.1 + + CVE-2002-0833 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:04.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020805 [SNS Advisory No.55] Eudora 5.x for Windows Buffer Overflow Vulnerability + + + BID + 5397 + + + XF + eudora-boundary-bo(9765) + + + BUGTRAQ + 20020808 [SNS Advisory No.55 rev.2] Eudora 5.x for Windows Buffer Overflow Vulnerability + + Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string. + + + + + + + + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.2 + cpe:/a:ethereal_group:ethereal:0.9.1 + cpe:/a:ethereal_group:ethereal:0.8 + cpe:/a:ethereal_group:ethereal:0.9.5 + cpe:/a:ethereal_group:ethereal:0.9.4 + cpe:/a:ethereal_group:ethereal:0.9.3 + cpe:/a:ethereal_group:ethereal:0.8.18 + cpe:/a:ethereal_group:ethereal:0.9_.0 + + CVE-2002-0834 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:12:59.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00006.html + + Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. + + + + + + + + + + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + cpe:/a:caldera:openlinux_workstation:3.1 + cpe:/a:caldera:openlinux_server:3.1 + cpe:/a:caldera:openlinux_workstation:3.1.1 + cpe:/a:redhat:pre-execution_environment:0.1 + cpe:/a:caldera:openlinux_server:3.1.1 + + CVE-2002-0835 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:04.520-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:165 + + + REDHAT + RHSA-2002:162 + + + BID + 5596 + + + XF + pxe-dhcp-dos(10003) + + + HP + HPSBTL0209-066 + + + CALDERA + CSSA-2002-044.0 + + Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/o:mandrakesoft:mandrake_linux:8.2::ppc + cpe:/o:redhat:linux:8.0::i386 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:7.3::i386 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.2 + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:redhat:linux:8.0 + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:mandrakesoft:mandrake_linux:9.0 + cpe:/o:mandrakesoft:mandrake_linux:8.1::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2 + cpe:/o:mandrakesoft:mandrake_linux:7.2 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + cpe:/o:redhat:linux:7.3 + + CVE-2002-0836 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:29:04.693-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#169841 + + + BID + 5978 + + + REDHAT + RHSA-2002:194 + + + DEBIAN + DSA-207 + + + BUGTRAQ + 20021018 GLSA: tetex + + + XF + dvips-system-execute-commands(10365) + + + HP + HPSBTL0210-073 + + + REDHAT + RHSA-2002:195 + + + MANDRAKE + MDKSA-2002:070 + + + BUGTRAQ + 20021216 [OpenPKG-SA-2002.015] OpenPKG Security Advisory (tetex) + + + CONECTIVA + CLA-2002:537 + + dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts. + + + + + + + + + + cpe:/a:wordtrans:wordtrans-web:1.0_beta2.2.4 + cpe:/a:wordtrans:wordtrans-web:1.1_pre8 + + CVE-2002-0837 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:04.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5674 + + + BID + 5671 + + + REDHAT + RHSA-2002:188 + + + XF + wordtrans-web-code-execution(10063) + + + XF + wordtrans-web-php-xss(10059) + + + MISC + http://www.guardent.com/comp_news_wordtrans-web.html# + + + BUGTRAQ + 20020908 Guardent Client Advisory: Multiple wordtrans-web Vulnerabilities + + wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:gv:gv:3.0.4 + cpe:/a:gv:gv:3.4.3 + cpe:/a:gv:gv:3.5.8 + cpe:/a:gv:gv:3.2.4 + cpe:/a:ghostview:ghostview:1.5 + cpe:/a:gv:gv:3.4.2 + cpe:/a:gv:gv:3.0.0 + cpe:/a:gv:gv:2.7b5 + cpe:/a:ghostview:ghostview:1.4.1 + cpe:/a:gv:gv:2.9.4 + cpe:/a:gv:gv:3.5.3 + cpe:/a:ghostview:ghostview:1.4 + cpe:/a:gv:gv:2.7b2 + cpe:/a:gv:gv:3.5.2 + cpe:/a:ghostview:ghostview:1.3 + cpe:/a:gv:gv:2.7b1 + cpe:/a:ggv:ggv:1.0.2 + cpe:/a:gv:gv:2.7b4 + cpe:/a:gv:gv:2.7b3 + cpe:/a:gv:gv:3.1.6 + cpe:/a:gv:gv:2.7.6 + cpe:/a:gv:gv:3.1.4 + cpe:/a:gv:gv:3.4.12 + + CVE-2002-0838 + 2002-10-10T00:00:00.000-04:00 + 2008-09-10T15:13:00.273-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#600777 + + + BID + 5808 + + + REDHAT + RHSA-2002:212 + + + BUGTRAQ + 20020926 iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv + + + REDHAT + RHSA-2002:220 + + + REDHAT + RHSA-2002:207 + + + CONFIRM + http://www.kde.org/info/security/advisory-20021008-1.txt + + + XF + gv-sscanf-function-bo(10201) + + + DEBIAN + DSA-182 + + + DEBIAN + DSA-179 + + + DEBIAN + DSA-176 + + + CALDERA + CSSA-2002-053.0 + + + MANDRAKE + MDKSA-2002:071 + + + MANDRAKE + MDKSA-2002:069 + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/47780&zone_32=category:security + + + BUGTRAQ + 20021017 GLSA: ggv + + + BUGTRAQ + 20020926 Errata: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv + + + CONECTIVA + CLA-2002:542 + + Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf. + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.20 + + CVE-2002-0839 + 2002-10-11T00:00:00.000-04:00 + 2011-09-06T21:12:24.087-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20021003 iDEFENSE Security Advisory 10.03.2002: Apache 1.3.x shared memory scoreboard vulnerabilities + + + BID + 5884 + + + ENGARDE + ESA-20021007-024 + + + MANDRAKE + MDKSA-2002:068 + + + XF + apache-scorecard-memory-overwrite(10280) + + + DEBIAN + DSA-195 + + + DEBIAN + DSA-188 + + + DEBIAN + DSA-187 + + + CONFIRM + http://www.apacheweek.com/issues/02-10-04 + + + HP + HPSBUX0210-224 + + + HP + HPSBOV02683 + + + BUGTRAQ + 20021017 TSLSA-2002-0069-apache + + + BUGTRAQ + 20021015 GLSA: apache + + + SGI + 20021105-01-I + + + BUGTRAQ + 20021003 [OpenPKG-SA-2002.009] OpenPKG Security Advisory (apache) + + + CONFIRM + http://marc.theaimsgroup.com/?l=apache-httpd-announce&m=103367938230488&w=2 + + + CONECTIVA + CLA-2002:530 + + The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.38 + cpe:/a:apache:http_server:2.0.37 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:apache:http_server:2.0.36 + cpe:/a:oracle:oracle9i:9.0.2 + cpe:/a:apache:http_server:2.0.35 + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.6 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.4 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:oracle:oracle9i:9.0.1.3 + cpe:/a:oracle:oracle8i:8.1.7_.1.0_enterprise + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:oracle:oracle9i:9.0.1.2 + cpe:/a:apache:http_server:1.3 + cpe:/a:oracle:oracle8i:8.1.7_.0.0_enterprise + cpe:/a:oracle:application_server:9.0.2.1 + cpe:/a:apache:http_server:2.0.28 + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:apache:http_server:1.3.23 + cpe:/a:oracle:database_server:9.2.2 + cpe:/a:apache:http_server:2.0.42 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:oracle:database_server:9.2.1 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:http_server:2.0.41 + cpe:/a:apache:http_server:2.0.40 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:application_server:9.0.2:r2 + cpe:/a:apache:http_server:2.0.39 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0840 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:00.413-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#240329 + + + BUGTRAQ + 20021002 Apache 2 Cross-Site Scripting + + + XF + apache-http-host-xss(10241) + + + CONFIRM + http://www.apacheweek.com/issues/02-10-04 + + + BID + 5847 + + + REDHAT + RHSA-2003:106 + + + REDHAT + RHSA-2002:251 + + + REDHAT + RHSA-2002:248 + + + REDHAT + RHSA-2002:244 + + + REDHAT + RHSA-2002:243 + + + REDHAT + RHSA-2002:222 + + + OSVDB + 862 + + + ENGARDE + ESA-20021007-024 + + + MANDRAKE + MDKSA-2002:068 + + + DEBIAN + DSA-195 + + + DEBIAN + DSA-188 + + + DEBIAN + DSA-187 + + + HP + HPSBUX0210-224 + + + BUGTRAQ + 20021003 [OpenPKG-SA-2002.009] OpenPKG Security Advisory (apache) + + + CONFIRM + http://marc.theaimsgroup.com/?l=apache-httpd-announce&m=103367938230488&w=2 + + + CONECTIVA + CLA-2002:530 + + + VULNWATCH + 20021002 Apache 2 Cross-Site Scripting + + + BUGTRAQ + 20021017 TSLSA-2002-0069-apache + + + SGI + 20021105-02-I + + Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157. + + + CVE-2002-0841 + 2003-03-03T00:00:00.000-05:00 + 2008-09-10T15:13:00.757-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0842. Reason: This candidate is a duplicate of CVE-2002-0842. The duplicate assignment was made before public disclosure. Notes: none. + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + + CVE-2002-0842 + 2003-03-03T00:00:00.000-05:00 + 2011-03-07T21:08:53.563-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#849993 + + + CERT + CA-2003-05 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2003alert52.pdf + + + MISC + http://www.nextgenss.com/advisories/ora-appservfmtst.txt + + + XF + oracle-appserver-davpublic-dos(11330) + + + NTBUGTRAQ + 20030217 Oracle9i Application Server Format String Vulnerability (#NISR16022003d) + + + BID + 6846 + + + CIAC + N-046 + + + BUGTRAQ + 20030218 Re: CSSA-2003-007.0 Advisory withdrawn. + + + BUGTRAQ + 20030218 CSSA-2003-007.0 Advisory withdrawn. Re: Security Update: [CSSA-2003-007.0] Linux: Apache mod_dav mo + + + VULNWATCH + 20030217 Oracle9i Application Server Format String Vulnerability (#NISR16022003d) + + Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror(). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.6 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:oracle:oracle8i:8.1.7.1.0_enterprise + cpe:/a:apache:http_server:1.3.4 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:oracle:database_server:8.1.7 + cpe:/a:apache:http_server:1.3 + cpe:/a:oracle:application_server:9.0.2.1 + cpe:/a:apache:http_server:1.3.23 + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:database_server:9.2.2 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:oracle8i:8.1.7.0.0_enterprise + cpe:/a:apache:http_server:1.3.9 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:application_server:9.0.2:r2 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:oracle:oracle8i:8.1.7.1 + + CVE-2002-0843 + 2002-10-11T00:00:00.000-04:00 + 2011-03-07T21:08:53.657-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VUPEN + ADV-2006-3263 + + + ENGARDE + ESA-20021007-024 + + + MANDRAKE + MDKSA-2002:068 + + + DEBIAN + DSA-195 + + + DEBIAN + DSA-188 + + + DEBIAN + DSA-187 + + + CONFIRM + http://www.apacheweek.com/issues/02-10-04 + + + HP + HPSBUX0210-224 + + + BUGTRAQ + 20021003 [OpenPKG-SA-2002.009] OpenPKG Security Advisory (apache) + + + CONECTIVA + CLSA-2002:530 + + + BUGTRAQ + 20021017 TSLSA-2002-0069-apache + + + SGI + 20021105-01-I + + + CONFIRM + http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2871 + + + BID + 5996 + + + BID + 5995 + + + BID + 5887 + + + XF + apache-apachebench-response-bo(10281) + + + AIXAPAR + IY87070 + + + CONFIRM + http://marc.theaimsgroup.com/?l=apache-httpd-announce&m=103367938230488&w=2 + + + CONECTIVA + CLA-2002:530 + + + BUGTRAQ + 20021016 Apache 1.3.26 + + Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response. + + + + + + + + + cpe:/a:derek_price:cvsd:1.11.2 + + CVE-2002-0844 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.160-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4829 + + + VULNWATCH + 20020525 [DER ADV#8] - Local off by one in CVSD + + + CALDERA + CSSA-2002-035.0 + + + XF + cvs-rcs-offbyone-bo(9175) + + + REDHAT + RHSA-2004:004 + + + BUGTRAQ + 20020525 [DER ADV#8] - Local off by one in CVSD + + + SGI + 20040103-01-U + + + + + Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code. + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:6.0 + cpe:/a:iplanet:iplanet_web_server:4.1 + + CVE-2002-0845 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.sun.com/service/support/software/iplanet/alerts/transferencodingalert-23july2002.html + + + BID + 5433 + + + XF + iplanet-chunked-encoding-bo(9799) + + + BUGTRAQ + 20020808 EEYE: Sun(TM) ONE / iPlanet Web Server 4.1 and 6.0 Remote Buffer Overflow + + Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding. + + + + + + + + + cpe:/a:macromedia:shockwave_flash + + CVE-2002-0846 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.457-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23293 + + + BID + 5430 + + + REDHAT + RHSA-2003:027 + + + REDHAT + RHSA-2003:026 + + + XF + flash-swf-header-bo(9798) + + + BUGTRAQ + 20020830 RE: Macromedia Shockwave Flash Malformed Header Overflow + + The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length. + + + + + + + + + + + cpe:/a:tinyproxy:tinyproxy:1.3.2 + cpe:/a:tinyproxy:tinyproxy:1.3.3 + cpe:/a:tinyproxy:tinyproxy:1.4.3 + + CVE-2002-0847 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.613-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4731 + + + XF + tinyproxy-memory-corruption(9079) + + + DEBIAN + DSA-145 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=88790 + + tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free). + + + + + + + + + + cpe:/o:cisco:vpn_500_concentrator:5.2.23.0003 + cpe:/o:cisco:vpn_500_concentrator:6.0.21.0002 + + CVE-2002-0848 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.770-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20020807 Cisco VPN 5000 Series Concentrator RADIUS PAP Authentication Vulnerability + + + BID + 5417 + + + XF + cisco-vpn5000-plaintext-password(9781) + + Cisco VPN 5000 series concentrator hardware 6.0.21.0002 and earlier, and 5.2.23.0003 and earlier, when using RADIUS with a challenge type of Password Authentication Protocol (PAP) or Challenge, sends the user password in cleartext in a validation retry request, which could allow remote attackers to steal passwords via sniffing. + + + + + + + + + cpe:/a:cisco:iscsi_driver:::linux + + CVE-2002-0849 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:29:06.927-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5423 + + + XF + linux-iscsi-conf-insecure(9792) + + + BUGTRAQ + 20020808 Re: [VulnWatch] iDEFENSE Security Advisory: iSCSI Default Configuration File Settings + + + BUGTRAQ + 20020808 iDEFENSE Security Advisory: iSCSI Default Configuration File Settings + + Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain privileges by reading the cleartext CHAP password. + + + + + + + + + cpe:/a:pgp:corporate_desktop:7.1.1 + + CVE-2002-0850 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:07.083-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5656 + + + XF + pgp-long-filename-bo(10043) + + + BUGTRAQ + 20020906 Foundstone Labs Advisory - Remotely Exploitable Buffer Overflow in PGP + + + CONFIRM + http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1.1/pgphotfix_outlookplugin711/ReadMe.txt + + + VULNWATCH + 20020905 Foundstone Labs Advisory - Remotely Exploitable Buffer Overflow in PGP + + Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long filename when it is decrypted. + + + + + + + + + cpe:/a:isdn4linux:isdn4linux:3.1_pre1 + + CVE-2002-0851 + 2002-09-05T00:00:00.000-04:00 + 2008-09-05T16:29:07.223-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5437 + + + XF + isdn4linux-ipppd-format-string(9811) + + + VULNWATCH + 20020809 Local Root Exploit + + Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog. + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_client:3.5.1::mac_os_x + cpe:/a:cisco:vpn_client:3.5.2::mac_os_x + cpe:/a:cisco:vpn_client:3.5.2::linux + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.5.2::windows + cpe:/a:cisco:vpn_client:3.5.1::linux + cpe:/a:cisco:vpn_client:3.5.2::solaris + cpe:/a:cisco:vpn_client:3.5.1::solaris + + CVE-2002-0852 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:01.757-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20020812 Cisco VPN Client Multiple Vulnerabilities + + Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads. + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_client:3.5.1::mac_os_x + cpe:/a:cisco:vpn_client:3.5.2::mac_os_x + cpe:/a:cisco:vpn_client:3.5.2::linux + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.5.2::windows + cpe:/a:cisco:vpn_client:3.5.1::linux + cpe:/a:cisco:vpn_client:3.5.2::solaris + cpe:/a:cisco:vpn_client:3.5.1::solaris + + CVE-2002-0853 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:01.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#287771 + + + CISCO + 20020812 Cisco VPN Client Multiple Vulnerabilities + + + BID + 5440 + + + XF + cisco-vpn-zerolength-dos(9821) + + Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload. + + + + + + + + + + cpe:/o:suse:suse_linux:8.0 + cpe:/o:suse:suse_linux:7.3 + + CVE-2002-0854 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:01.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may allow local users to gain privileges. + + + + + + + + + cpe:/a:gnu:mailman:2.0.12 + + CVE-2002-0855 + 2002-09-05T00:00:00.000-04:00 + 2008-09-05T16:29:07.863-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5298 + + + CONFIRM + http://mail.python.org/pipermail/mailman-announce/2002-July/000043.html + + + REDHAT + RHSA-2002:181 + + + REDHAT + RHSA-2002:178 + + + REDHAT + RHSA-2002:177 + + + REDHAT + RHSA-2002:176 + + + XF + mailman-subscription-option-xss(9985) + + + DEBIAN + DSA-147 + + + BUGTRAQ + 20020724 cross-site scripting bug of Mailman + + + CONECTIVA + CLA-2002:522 + + Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature. + + + + + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1.3 + cpe:/a:oracle:oracle9i:9.0.1.2 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:database_server:9.2.1 + cpe:/a:oracle:oracle9i:9.0.2 + cpe:/a:oracle:oracle9i:9.0 + + CVE-2002-0856 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:02.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + oracle-listener-debug-dos(9237) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert38rev1.pdf + + + BID + 5457 + + + ISS + 20020813 Remote Denial of Service Vulnerability in Oracle9i SQL*NET + + + VULNWATCH + 20020813 ISS Security Brief: Remote Denial of Service Vulnerability in Oracle9i SQL*NET + + SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature. + + + + + + + + + + + + cpe:/a:oracle:database_server:9.2 + cpe:/a:oracle:database_server:9.0 + cpe:/a:oracle:database_server:7.3.4 + cpe:/a:oracle:oracle8i:8.1 + + CVE-2002-0857 + 2002-09-05T00:00:00.000-04:00 + 2008-09-05T16:29:08.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#301059 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf + + + BID + 5460 + + + MISC + http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt + + + SECTRACK + 1005037 + + + BUGTRAQ + 20020814 Oracle Listener Control Format String Vulnerabilities (#NISR14082002) + + Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file. + + + + + + + + + + cpe:/a:oracle:oracle9i + cpe:/a:oracle:oracle8i + + CVE-2002-0858 + 2002-09-05T00:00:00.000-04:00 + 2008-09-05T16:29:08.333-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + OSVDB + 9476 + + + XF + oracle-catsnmp-default-account(9932) + + + BUGTRAQ + 20020812 Vulnerability in Oracle + + catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges. + + + + + + + + + + + + + + + + + cpe:/a:microsoft:jet:4.0 + cpe:/a:microsoft:jet:4.0:sp2 + cpe:/a:microsoft:jet:4.0:sp5 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:jet:4.0:sp3 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:jet:4.0:sp1 + cpe:/a:microsoft:jet:4.0:sp4 + + CVE-2002-0859 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:02.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020619 Microsoft SQL Server 2000 OpenDataSource Buffer Overflow (#NISR19062002) + + + MISC + http://www.nextgenss.com/advisories/mssql-ods.txt + + + MSKB + Q282010 + + + BID + 5057 + + + XF + mssql-jet-ods-bo(9375) + + Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code. + + + + + + + + + + + + cpe:/a:microsoft:project:2002 + cpe:/a:microsoft:project:2000 + cpe:/a:microsoft:office_web_components:2002 + cpe:/a:microsoft:office_web_components:2000 + + CVE-2002-0860 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:02.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-044 + + + XF + owc-spreadsheet-loadtext-read-files (8778) + + + BID + 4453 + + + OSVDB + 3007 + + + BUGTRAQ + 20020408 Reading local files with OWC in IE (GM#006-IE) + + The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file. + + + + + + + + + + + + cpe:/a:microsoft:project:2002 + cpe:/a:microsoft:project:2000 + cpe:/a:microsoft:office_web_components:2002 + cpe:/a:microsoft:office_web_components:2000 + + CVE-2002-0861 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:02.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-044 + + + XF + owc-spreadsheet-clipboard-access (8779) + + + BID + 4457 + + + BUGTRAQ + 20020408 Controlling the clipboard with OWC in IE (GM#007-IE) + + Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/a:microsoft:office:v.x + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:kde:kde:3.0 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/a:microsoft:ie:5.0.1 + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:alpha + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:kde:kde:2.2.2 + cpe:/a:microsoft:ie:5.5 + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/a:microsoft:ie:5.0 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/a:microsoft:office:98::mac + cpe:/a:adam_megacz:tinyssl:1.0.2 + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp6a + cpe:/o:microsoft:windows_nt:4.0:sp5:alpha + cpe:/o:microsoft:windows_nt:4.0:sp3 + cpe:/o:microsoft:windows_nt:4.0:sp4 + cpe:/o:baltimore_technologies:mailsecure + cpe:/o:microsoft:windows_nt:4.0:sp6:alpha + cpe:/o:kde:kde:2.2.1 + cpe:/a:kde:konqueror:3.0.2 + cpe:/a:kde:konqueror:3.0.1 + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0 + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_nt:4.0:sp6 + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp5 + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2 + cpe:/o:microsoft:windows_nt:4.0:sp3:alpha + cpe:/o:microsoft:windows_nt:4.0:sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:alpha + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_nt:4.0:sp1:alpha + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:alpha + cpe:/o:kde:kde:3.0.2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:kde:konqueror:2.2.2 + cpe:/o:kde:kde:3.0.1 + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/a:microsoft:ie_for_macintosh:5.1.1 + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:office:2001:sr1:mac_os + cpe:/a:microsoft:ie_for_macintosh:5.0 + cpe:/a:microsoft:ie_for_macintosh:5.1 + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/a:kde:konqueror:3.0 + cpe:/a:microsoft:outlook_express:5.0::macos + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0::alpha + cpe:/a:microsoft:outlook_express:4.5::macos + cpe:/a:microsoft:office:2001::macintosh + cpe:/a:microsoft:outlook_express:5.0.1::macos + cpe:/a:microsoft:outlook_express:5.0.2::macos + cpe:/a:microsoft:outlook_express:5.0.3::macos + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0862 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:02.477-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + MS + MS02-050 + + + XF + ssl-ca-certificate-spoofing(9776) + + + BUGTRAQ + 20020819 Insufficient Verification of Client Certificates in IIS 5.0 pre sp3 + + + BUGTRAQ + 20020812 IE SSL Exploit + + + BUGTRAQ + 20020805 IE SSL Vulnerability + + + + + + + + + + + The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:64-bit + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/a:microsoft:.net_windows_server:beta3::standard + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2002-0863 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:02.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#865833 + + + MS + MS02-051 + + + BUGTRAQ + 20020916 Microsoft Windows Remote Desktop Protocol checksum and keystroke vulnerabilities + + + BID + 5712 + + + BID + 5711 + + + XF + win-rdp-keystroke-monitoring(10122) + + + XF + win-rdp-checksum-leak(10121) + + + BUGTRAQ + 20020918 Microsoft Windows Terminal Services vulnerabilities + + + + + Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol." + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:64-bit + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_xp:::home + cpe:/a:microsoft:.net_windows_server:beta3::standard + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2002-0864 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:09.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5713 + + + MS + MS02-051 + + + BUGTRAQ + 20020916 Microsoft Windows XP Remote Desktop denial of service vulnerability + + + XF + winxp-remote-desktop-dos(10120) + + + BUGTRAQ + 20020918 Microsoft Windows Terminal Services vulnerabilities + + The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop." + + + + + + + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3000 + cpe:/a:microsoft:virtual_machine:3300 + cpe:/a:microsoft:virtual_machine:3100 + cpe:/a:microsoft:virtual_machine:3200 + cpe:/a:microsoft:virtual_machine:3188 + cpe:/a:microsoft:virtual_machine:3802 + cpe:/a:microsoft:virtual_machine:3805 + cpe:/a:microsoft:virtual_machine:2000 + + CVE-2002-0865 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:02.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#140898 + + + MS + MS02-052 + + + XF + msvm-xml-methods-access(10135) + + + BID + 5752 + + A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes." + + + + + + + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3000 + cpe:/a:microsoft:virtual_machine:3300 + cpe:/a:microsoft:virtual_machine:3100 + cpe:/a:microsoft:virtual_machine:3200 + cpe:/a:microsoft:virtual_machine:3188 + cpe:/a:microsoft:virtual_machine:3802 + cpe:/a:microsoft:virtual_machine:3805 + cpe:/a:microsoft:virtual_machine:2000 + + CVE-2002-0866 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:02.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#307306 + + + MS + MS02-052 + + + XF + msvm-jdbc-dll-execution(10133) + + + BID + 5751 + + + BUGTRAQ + 20020923 Technical information about the vulnerabilities fixed by MS-02-52 + + Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes." + + + + + + + + + + + + + + + + cpe:/a:microsoft:virtual_machine:3000 + cpe:/a:microsoft:virtual_machine:3300 + cpe:/a:microsoft:virtual_machine:3100 + cpe:/a:microsoft:virtual_machine:3200 + cpe:/a:microsoft:virtual_machine:3188 + cpe:/a:microsoft:virtual_machine:3802 + cpe:/a:microsoft:virtual_machine:3805 + cpe:/a:microsoft:virtual_machine:2000 + + CVE-2002-0867 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:02.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#792881 + + + MS + MS02-052 + + + XF + msvm-jdbc-ie-dos(10134) + + + BID + 5750 + + Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw." + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-0869 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:13:05.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + MS + MS02-062 + + + XF + iis-outofprocess-privilege-elevation(10502) + + + MISC + http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt + + + CIAC + N-011 + + + VULNWATCH + 20021104 [A3SC] MS IIS out of process privilege elevation vulnerability(A3CR@K-Vul-2002-06-002) + + + BUGTRAQ + 20021104 [A3SC] MS IIS out of process privilege elevation vulnerability(A3CR@K-Vul-2002-06-002) + + + + + + + + + + + Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation." + + + + + + + + + + + + + + cpe:/h:cisco:content_services_switch_11000 + cpe:/a:cisco:webns + + CVE-2002-0870 + 2002-09-05T00:00:00.000-04:00 + 2008-09-05T16:29:10.537-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20020814 Cisco Content Service Switch 11000 Series Web Management Vulnerability + + The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549. + + + + + + + + + + + cpe:/a:xinetd:xinetd:2.3.5 + cpe:/a:xinetd:xinetd:2.3.6 + cpe:/a:xinetd:xinetd:2.3.4 + + CVE-2002-0871 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:05.367-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-151 + + + BID + 5458 + + + REDHAT + RHSA-2003:228 + + + REDHAT + RHSA-2002:196 + + + MANDRAKE + MDKSA-2002:053 + + + XF + xinetd-signal-leak-dos(9844) + + + BUGTRAQ + 20020814 GLSA: xinetd + + xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe. + + + + + + + + + + + + + + cpe:/a:l2tpd:l2tpd:0.62 + cpe:/a:l2tpd:l2tpd:0.63 + cpe:/a:l2tpd:l2tpd:0.65 + cpe:/a:l2tpd:l2tpd:0.64 + cpe:/a:l2tpd:l2tpd:0.67 + cpe:/a:l2tpd:l2tpd:0.66 + + CVE-2002-0872 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:05.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5451 + + + XF + l2tpd-rand-number-predictable(9845) + + + DEBIAN + DSA-152 + + l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions. + + + + + + + + + + + + + + cpe:/a:l2tpd:l2tpd:0.62 + cpe:/a:l2tpd:l2tpd:0.63 + cpe:/a:l2tpd:l2tpd:0.65 + cpe:/a:l2tpd:l2tpd:0.64 + cpe:/a:l2tpd:l2tpd:0.67 + cpe:/a:l2tpd:l2tpd:0.66 + + CVE-2002-0873 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:05.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + l2tpd-vendor-field-bo(10460) + + + DEBIAN + DSA-152 + + Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow. + + + + + + + + + + + + + cpe:/a:redhat:interchange:4.8.1 + cpe:/a:redhat:interchange:4.8.4 + cpe:/a:redhat:interchange:4.8.5 + cpe:/a:redhat:interchange:4.8.2 + cpe:/a:redhat:interchange:4.8.3 + + CVE-2002-0874 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:05.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-150 + + Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files. + + + + + + + + + + + + + + + + + + cpe:/a:sgi:fam:2.6.8 + cpe:/a:sgi:fam:2.6.6 + cpe:/o:debian:debian_linux:3.0 + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + + CVE-2002-0875 + 2002-09-05T00:00:00.000-04:00 + 2008-09-10T15:13:05.663-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-154 + + + BID + 5487 + + + REDHAT + RHSA-2005:005 + + + XF + sgi-fam-insecure-permissions(9880) + + + SGI + 20000301-03-I + + + FREEBSD + FreeBSD-SN-02:05 + + Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group. + + + + + + + + + cpe:/a:evolvable_corporation:shambala_server:4.5 + + CVE-2002-0876 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:11.503-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4897 + + + XF + shambala-web-request-dos(9225) + + + BUGTRAQ + 20020709 Exploit for previously reported DoS issues in Shambala Server 4.5 + + + BUGTRAQ + 20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS + + Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request. + + + + + + + + + cpe:/a:evolvable_corporation:shambala_server:4.5 + + CVE-2002-0877 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:11.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4896 + + + XF + shambala-dotdot-directory-traversal(9224) + + + BUGTRAQ + 20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS + + Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands. + + + + + + + + + + + cpe:/a:logisense:hawk-i:asp + cpe:/a:logisense:hawk-i:5.2 + cpe:/a:logisense:dns_manager_system + + CVE-2002-0878 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:11.800-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4931 + + + XF + logisense-sql-injection(9268) + + + BUGTRAQ + 20020604 sql injection in Logisense software + + SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field. + + + + + + + + + + cpe:/a:gafware:cfximage:1.6.6 + cpe:/a:gafware:cfximage:1.6.4 + + CVE-2002-0879 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:11.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4882 + + + XF + cfximage-dotdot-directory-traversal(9196) + + + BUGTRAQ + 20020529 Gafware's CFXImage vulnerability + + showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter. + + + + + + + + + + + + + + + + + cpe:/o:cisco:voip_phone_cp-7960:3.0 + cpe:/o:cisco:voip_phone_cp-7910:3.1 + cpe:/h:cisco:voip_phone_cp-7940:3.1 + cpe:/o:cisco:voip_phone_cp-7960:3.1 + cpe:/o:cisco:voip_phone_cp-7910:3.2 + cpe:/h:cisco:voip_phone_cp-7940:3.2 + cpe:/o:cisco:voip_phone_cp-7960:3.2 + cpe:/o:cisco:voip_phone_cp-7910:3.0 + cpe:/h:cisco:voip_phone_cp-7940:3.0 + + CVE-2002-0880 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:12.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20020522 Multiple Vulnerabilities in Cisco IP Telephones + + Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2." + + + + + + + + + + + + + + + + + cpe:/o:cisco:voip_phone_cp-7960:3.0 + cpe:/o:cisco:voip_phone_cp-7910:3.1 + cpe:/h:cisco:voip_phone_cp-7940:3.1 + cpe:/o:cisco:voip_phone_cp-7960:3.1 + cpe:/o:cisco:voip_phone_cp-7910:3.2 + cpe:/h:cisco:voip_phone_cp-7940:3.2 + cpe:/o:cisco:voip_phone_cp-7960:3.2 + cpe:/o:cisco:voip_phone_cp-7910:3.0 + cpe:/h:cisco:voip_phone_cp-7940:3.0 + + CVE-2002-0881 + 2002-10-04T00:00:00.000-04:00 + 2009-04-03T00:13:42.343-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4799 + + + XF + cisco-ipphone-configuration-access(9144) + + + CISCO + 20020522 Multiple Vulnerabilities in Cisco IP Telephones + + + BUGTRAQ + 20020522 Multiple Vulnerabilities in CISCO VoIP Phones + + Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings. + + + + + + + + + + + + + + + + + cpe:/o:cisco:voip_phone_cp-7960:3.0 + cpe:/o:cisco:voip_phone_cp-7910:3.1 + cpe:/h:cisco:voip_phone_cp-7940:3.1 + cpe:/o:cisco:voip_phone_cp-7960:3.1 + cpe:/o:cisco:voip_phone_cp-7910:3.2 + cpe:/h:cisco:voip_phone_cp-7940:3.2 + cpe:/o:cisco:voip_phone_cp-7960:3.2 + cpe:/o:cisco:voip_phone_cp-7910:3.0 + cpe:/h:cisco:voip_phone_cp-7940:3.0 + + CVE-2002-0882 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:12.457-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4798 + + + BID + 4794 + + + XF + cisco-ipphone-portinformation(9143) + + + XF + cisco-ipphone-streamingstatistics-dos(9142) + + + CISCO + 20020522 Multiple Vulnerabilities in Cisco IP Telephones + + + BUGTRAQ + 20020522 Multiple Vulnerabilities in CISCO VoIP Phones + + The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script. + + + + + + + + + + cpe:/h:compaq:proliant_bl_e-class_integrated_administrator_firmware:1.10 + cpe:/h:compaq:proliant_bl_e-class_integrated_administrator_firmware:1.0 + + CVE-2002-0883 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:12.630-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4802 + + + XF + compaq-proliant-gain-access(9202) + + + COMPAQ + SSRT2179 + + Vulnerability in Compaq ProLiant BL e-Class Integrated Administrator 1.0 and 1.10, allows authenticated users with Telnet, SSH, or console access to conduct unauthorized activities. + + + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:caldera:openunix:8.0 + cpe:/o:sun:solaris:8.0 + + CVE-2002-0884 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:12.787-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4791 + + + XF + solaris-inrarpd-code-execution(9150) + + + BUGTRAQ + 20020522 [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd + + + VULNWATCH + 20020521 [VulnWatch] [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd + + + CALDERA + CSSA-2002-SCO.29 + + Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error. + + + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:sun:solaris:7.0 + cpe:/o:caldera:openunix:8.0 + cpe:/o:sun:solaris:8.0 + + CVE-2002-0885 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:12.943-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4791 + + + XF + solaris-inrarpd-code-execution(9150) + + + BUGTRAQ + 20020522 [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd + + + VULNWATCH + 20020521 [VulnWatch] [DER Adv #7] - Multiple Vulnerabilities in solaris in.rarpd + + + MISC + ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.29/CSSA-2002-SCO.29.txt + + Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:cbos:2.0.1 + cpe:/o:cisco:cbos:2.1.0a + cpe:/o:cisco:cbos:2.2.1 + cpe:/o:cisco:cbos:2.2.0 + cpe:/o:cisco:cbos:2.4.2b + cpe:/o:cisco:cbos:2.1.0 + cpe:/o:cisco:cbos:2.2.1a + cpe:/o:cisco:cbos:2.3 + cpe:/o:cisco:cbos:2.4.2ap + cpe:/o:cisco:cbos:2.3_.053 + cpe:/o:cisco:cbos:2.4.4 + cpe:/o:cisco:cbos:2.3.2 + cpe:/o:cisco:cbos:2.4.2 + cpe:/o:cisco:cbos:2.3.7 + cpe:/o:cisco:cbos:2.4.3 + cpe:/o:cisco:cbos:2.3.8 + cpe:/o:cisco:cbos:2.3.5 + cpe:/o:cisco:cbos:2.3.5.015 + cpe:/o:cisco:cbos:2.4.1 + cpe:/o:cisco:cbos:2.3.9 + cpe:/o:cisco:cbos:2.3.7.002 + + CVE-2002-0886 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:13.097-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4813 + + + XF + cisco-cbos-dhcp-dos(9151) + + + XF + cisco-cbos-telnet-cpe-dos(9152) + + + BID + 4815 + + + BID + 4814 + + + XF + cisco-cbos-tcpip-dos(9153) + + + CISCO + 20020523 CBOS - Improving Resilience to Denial-of-Service Attacks + + Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory. + + + + + + + + + + cpe:/a:caldera:openserver:5.0.5 + cpe:/a:caldera:openserver:5.0.6 + + CVE-2002-0887 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:13.300-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4875 + + + XF + openserver-scoadmin-symlink(9210) + + + CALDERA + CSSA-2002-SCO.22 + + + BUGTRAQ + 20010522 [SRT2001-10] - scoadmin /tmp issues + + scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files. + + + + + + + + + + cpe:/h:3com:3cp4144:1.1.9 + cpe:/h:3com:3cp4144:1.1.7 + + CVE-2002-0888 + 2002-10-04T00:00:00.000-04:00 + 2012-05-11T21:16:11.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4841 + + + XF + 3com-officeconnect-pat-access(9185) + + + BUGTRAQ + 20020612 Part II: Vulnerability in 3Com® OfficeConnect® Remote 812 ADSL Router + + + BUGTRAQ + 20020527 Vulnerability in 3Com® OfficeConnect® Remote 812 ADSL Router + + 3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router. + + + + + + + + + + cpe:/a:qualcomm:qpopper:4.0.4 + cpe:/a:qualcomm:qpopper:4.0.3 + + CVE-2002-0889 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:07.633-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4614 + + + XF + qpopper-bulldir-bo(8949) + + + BUGTRAQ + 20020428 QPopper 4.0.4 buffer overflow + + + VULN-DEV + 20020428 QPopper 4.0.4 buffer overflow + + Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:juniper:netscreen_screenos:2.8_r1 + cpe:/o:juniper:netscreen_screenos:2.7.1 + cpe:/o:juniper:netscreen_screenos:2.5r1 + cpe:/o:juniper:netscreen_screenos:3.0.1r1 + cpe:/o:juniper:netscreen_screenos:2.10_r4 + cpe:/o:juniper:netscreen_screenos:2.6.1r3 + cpe:/o:juniper:netscreen_screenos:2.10_r3 + cpe:/o:juniper:netscreen_screenos:2.5r2 + cpe:/o:juniper:netscreen_screenos:2.6.1r2 + cpe:/o:juniper:netscreen_screenos:3.0.0 + cpe:/o:juniper:netscreen_screenos:2.6.1r5 + cpe:/o:juniper:netscreen_screenos:2.5 + cpe:/o:juniper:netscreen_screenos:2.6.1r4 + cpe:/o:juniper:netscreen_screenos:3.0.0r2 + cpe:/o:juniper:netscreen_screenos:2.7.1r2 + cpe:/o:juniper:netscreen_screenos:3.0.0r3 + cpe:/o:juniper:netscreen_screenos:2.7.1r1 + cpe:/o:juniper:netscreen_screenos:2.5r6 + cpe:/o:juniper:netscreen_screenos:2.6.1r1 + cpe:/o:juniper:netscreen_screenos:3.0.0r1 + cpe:/o:juniper:netscreen_screenos:2.7.1r3 + cpe:/o:juniper:netscreen_screenos:3.0.0r4 + cpe:/o:juniper:netscreen_screenos:2.6.1 + + CVE-2002-0891 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:13.770-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4842 + + + CONFIRM + http://www.netscreen.com/support/ns25_reboot.html + + + XF + netscreen-screenos-username-dos(9186) + + + BUGTRAQ + 20020527 Netscreen 25 unauthorised reboot issue + + The web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause a denial of service (crash) via a long user name. + + + + + + + + + cpe:/a:new_atlanta_communications:servletexec_isapi:4.1 + + CVE-2002-0892 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:13.973-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4793 + + + XF + servletexec-jsp10servlet-path-disclosure(9139) + + + CONFIRM + http://www.newatlanta.com/do/findFaq?faq_id=151 + + + BUGTRAQ + 20020522 Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + + VULNWATCH + 20020522 [VulnWatch] Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message. + + + + + + + + + cpe:/a:new_atlanta_communications:servletexec_isapi:4.1 + + CVE-2002-0893 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4795 + + + XF + servletexec-dotdot-directory-traversal(9140) + + + BUGTRAQ + 20020522 Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + + VULNWATCH + 20020522 [VulnWatch] Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences. + + + + + + + + + cpe:/a:new_atlanta_communications:servletexec_isapi:4.1 + + CVE-2002-0894 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.270-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4796 + + + XF + servletexec-long-jsp-dos(9141) + + + BUGTRAQ + 20020522 Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + + VULNWATCH + 20020522 [VulnWatch] Multiple vulnerabilities in NewAtlanta ServletExec ISAPI 4.1 + + NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet. + + + + + + + + + cpe:/a:matu:matu_ftp:1.13 + + CVE-2002-0895 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.410-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4792 + + + XF + matuftpserver-pass-bo(9138) + + + BUGTRAQ + 20020522 MatuFtpServer Remote Buffer Overflow and Possible DoS + + Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PASS (password) command. + + + + + + + + + + cpe:/a:swatch:swatch:3.0.4 + cpe:/a:swatch:swatch:3.0.3 + + CVE-2002-0896 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.567-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4746 + + + XF + swatch-event-reporting-failure(9100) + + + BUGTRAQ + 20020515 swatch bug in throttle + + The throttle capability in Swatch may fail to report certain events if (1) the same type of event occurs after the throttle period, or (2) when multiple events matching the same "watchfor" expression do not occur after the throttle period, which could allow attackers to avoid detection. + + + + + + + + + cpe:/a:intranet-server:localweb2000:2.1.0_standard_version + + CVE-2002-0897 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4820 + + + XF + localweb2k-protection-bypass(9165) + + + BUGTRAQ + 20020524 [SecurityOffice] LocalWeb2000 Web Server Protected File Access Vulnerability + + + VULNWATCH + 20020524 [SecurityOffice] LocalWeb2000 Web Server Protected File Access Vulnerability + + LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory. + + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0.1::win32 + cpe:/a:opera_software:opera_web_browser:6.0.2::win32 + + CVE-2002-0898 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:14.880-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4834 + + + XF + opera-browser-file-retrieval(9188) + + + CONFIRM + http://www.opera.com/windows/changelog/log603.html + + + BUGTRAQ + 20020527 Reading ANY local file in Opera (GM#001-OP) + + + NTBUGTRAQ + 20020527 Reading ANY local file in Opera (GM#001-OP) + + Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline. + + + + + + + + + + cpe:/a:blueface:falcon_web_server:2.0.0.1021_ssl + cpe:/a:blueface:falcon_web_server:2.0.0.1021 + + CVE-2002-0899 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4833 + + + XF + falcon-protected-file-access(9179) + + + BUGTRAQ + 20020527 [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability #2 + + + VULNWATCH + 20020527 [VulnWatch] [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability #2 + + Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot). + + + + + + + + + + cpe:/a:mit:pgp_public_key_server:0.9.2 + cpe:/a:mit:pgp_public_key_server:0.9.4 + + CVE-2002-0900 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4828 + + + XF + pgp-pks-search-bo(9171) + + + CONFIRM + http://www.rubin.ch/pgp/src/patch_buffoverflow20020525 + + + BUGTRAQ + 20020524 pks public key server DOS and remote execution + + Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability. + + + + + + + + + cpe:/a:amanda:amanda:2.3.0.4 + + CVE-2002-0901 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.333-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4840 + + + BID + 4836 + + + XF + amanda-operator-bo(9182) + + + XF + amanda-amindexd-bo(9181) + + + BUGTRAQ + 20020527 AMANDA security issues + + Multiple buffer overflows in Advanced Maryland Automatic Network Disk Archiver (AMANDA) 2.3.0.4 allow (1) remote attackers to execute arbitrary code via long commands to the amindexd daemon, or certain local users to execute arbitrary code via long command line arguments to the programs (2) amcheck, (3) amgetidx, (4) amtrmidx, (5) createindex-dump, or (6) createindex-gnutar. + + + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0_beta1 + cpe:/a:phpbb_group:phpbb:2.0.0 + cpe:/a:phpbb_group:phpbb:2.0_rc4 + cpe:/a:phpbb_group:phpbb:2.0_rc2 + cpe:/a:phpbb_group:phpbb:2.0_rc3 + cpe:/a:phpbb_group:phpbb:2.0_rc1 + + CVE-2002-0902 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.490-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4858 + + + XF + phpbb-bbcode-image-css(9178) + + + BUGTRAQ + 20020526 Cross Site Scripting Vulnerability in phpBB2's [IMG] tag and remote avatar + + Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script. + + + + + + + + + cpe:/a:woltlab:burning_board:1.1.1 + + CVE-2002-0903 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4859 + + + XF + burningboard-bbs-account-hijacking(9177) + + + BUGTRAQ + 20020526 wbbboard 1.1.1 registration _new_users_vulnerability_ + + register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID's, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value. + + + + + + + + + + cpe:/a:kismet:kismet:2.2.1 + cpe:/a:kismet:kismet:2.2 + + CVE-2002-0904 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.800-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4883 + + + XF + kismet-saytext-command-execution(9213) + + + CONFIRM + http://www.kismetwireless.net/CHANGELOG + + + VULN-DEV + 20020529 New Kismet Packages available - SayText() and suid kismet_server issues + + + BUGTRAQ + 20020528 New Kismet Packages available - SayText() and suid kismet_server issues + + SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument. + + + + + + + + + + + cpe:/a:ibm:informix:7.25_.uc1_se + cpe:/a:ibm:informix:7.25_.uc3_se + cpe:/a:ibm:informix:7.25_.uc2_se + + CVE-2002-0905 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:15.957-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4891 + + + XF + informix-sqlexec-bo(9219) + + + BUGTRAQ + 20020529 Informix SE-7.25 /lib/sqlexec Vulnerability + + Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable. + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/a:sendmail:sendmail:8.12.4 + cpe:/a:sendmail:sendmail:8.12.0 + + CVE-2002-0906 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:10.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#814627 + + + XF + sendmail-dns-txt-bo(9443) + + + CONFIRM + http://www.sendmail.org/8.12.5.html + + + BID + 5122 + + + + + Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server. + + + + + + + + + + + + + cpe:/a:nullsoft:shoutcast_server:1.8.9::win32 + cpe:/a:nullsoft:shoutcast_server:1.8.9::linux + cpe:/a:nullsoft:shoutcast_server:1.8.9::freebsd + cpe:/a:nullsoft:shoutcast_server:1.8.9::solaris + cpe:/a:nullsoft:shoutcast_server:1.8.9::mac_os_x + + CVE-2002-0907 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:16.270-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4934 + + + XF + shoutcast-icy-remote-bo(9251) + + + BUGTRAQ + 20020604 SHOUTcast 1.8.9 bufferoverflow + + Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-". + + + + + + + + + cpe:/a:cisco:ids_device_manager:3.1.1 + + CVE-2002-0908 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:16.427-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4760 + + + XF + cisco-ids-directory-traversal(9174) + + + BUGTRAQ + 20020524 Cisco IDS Device Manager 3.1.1 Advisory + + Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request. + + + + + + + + + cpe:/a:matsushita_research:mnews:1.2.2 + + CVE-2002-0909 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:16.583-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4900 + + + BID + 4899 + + + XF + mnews-multiple-local-bo(9227) + + + XF + mnews-nntp-response-bo(9226) + + + BUGTRAQ + 20020531 SRT Security Advisory (SRT2002-04-31-1159): Mnews + + + VULN-DEV + 20020531 Mnews 1.22 PoC exploit + + + BUGTRAQ + 20020531 Mnews 1.22 PoC exploit + + Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long environment variables (7) JNAMES or (8) MAILSERVER. + + + + + + + + + cpe:/a:debian:netstd:3.07 + + CVE-2002-0910 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:16.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4816 + + + XF + netstd-utilities-bo(9164) + + + BUGTRAQ + 20020525 Re: Netstd 3.07-17 multiple remote buffer overflows + + + BUGTRAQ + 20020524 Netstd 3.07-17 multiple remote buffer overflows + + Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1) linux-ftpd, (2) pcnfsd, (3) tftp, (4) traceroute, or (5) from/to. + + + + + + + + + cpe:/a:caldera:volution_manager:1.1 + + CVE-2002-0911 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:16.880-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4923 + + + XF + volution-manager-plaintext-password(9240) + + + CALDERA + CSSA-2002-024.0 + + Caldera Volution Manager 1.1 stores the Directory Administrator password in cleartext in the slapd.conf file, which could allow local users to gain privileges. + + + + + + + + + + + + + + cpe:/o:debian:debian_linux:2.2::ia-32 + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:debian:debian_linux:2.2::powerpc + + CVE-2002-0912 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.037-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4910 + + + XF + debian-in-uucpd-dos(9230) + + + DEBIAN + DSA-129 + + in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow. + + + + + + + + + cpe:/a:stephen_hebditch:slurp:1.1.0 + + CVE-2002-0913 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.193-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4935 + + + XF + slurp-syslog-format-string(9270) + + + BUGTRAQ + 20020604 SRT Security Advisory (SRT2002-06-04-1011): slurp + + + VULN-DEV + 20020604 SRT Security Advisory (SRT2002-06-04-1011): slurp + + Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response. + + + + + + + + + cpe:/a:double_precision_incorporated:courier_mta:0.38.1 + + CVE-2002-0914 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.347-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + courier-mta-year-dos(9228) + + + BID + 4908 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=93065 + + + OSVDB + 5052 + + Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop. + + + + + + + + + + + + + + cpe:/o:harald_hoyer:xandros_desktop_os:1.0 + cpe:/a:harald_hoyer:autorun:2.7 + + CVE-2002-0915 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.490-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4884 + + + XF + xandros-autorun-view-files(9211) + + + BUGTRAQ + 20020528 Xandros based linux autorun -c + + autorun in Xandros based Linux distributions allows local users to read the first line of arbitrary files via the -c parameter, which causes autorun to print the first line of the file. + + + + + + + + + cpe:/a:stellar-x_software:msntauth:2.0.3 + + CVE-2002-0916 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.squid-cache.org/Versions/v2/2.4/diff-2.4.STABLE6-2.4.STABLE7.gz + + + BID + 4929 + + + XF + msntauth-squid-format-string(9248) + + + BUGTRAQ + 20020604 [DER #11] - Remotey exploitable fmt string bug in squid + + + VULNWATCH + 20020603 [VulnWatch] [DER #11] - Remotey exploitable fmt string bug in squid + + Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call. + + + + + + + + + cpe:/a:cgiscript.net:cspassword:1.0 + + CVE-2002-0917 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.787-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4885 + + + XF + cgiscript-cspassword-htpasswd-access(9220) + + + BUGTRAQ + 20020529 CGIscript.net - csPassword.cgi - Multiple Vulnerabilities + + CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users. + + + + + + + + + cpe:/a:cgiscript.net:cspassword:1.0 + + CVE-2002-0918 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:17.943-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4887 + + + XF + cgiscript-cspassword-information-disclosure(9221) + + + BUGTRAQ + 20020529 CGIscript.net - csPassword.cgi - Multiple Vulnerabilities + + CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error. + + + + + + + + + cpe:/a:cgiscript.net:cspassword:1.0 + + CVE-2002-0919 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:18.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4888 + + + XF + cgiscript-cspassword-htaccess-modification(9222) + + + BUGTRAQ + 20020529 CGIscript.net - csPassword.cgi - Multiple Vulnerabilities + + CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. + + + + + + + + + cpe:/a:cgiscript.net:cspassword:1.0 + + CVE-2002-0920 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:11.197-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cgiscript-cspassword-tmpfile-access(9223) + + + BUGTRAQ + 20020529 CGIscript.net - csPassword.cgi - Multiple Vulnerabilities + + + BID + 4889 + + CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. + + + + + + + + + + cpe:/a:cgiscript.net:csnews:1.0_professional + cpe:/a:cgiscript.net:csnews:1.0 + + CVE-2002-0921 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:18.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cgiscript-csnews-information-disclosure(9331) + + + BUGTRAQ + 20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities + + CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other configuration settings, via the viewnews command with an invalid database, which leaks the information in error messages. + + + + + + + + + + cpe:/a:cgiscript.net:csnews:1.0_professional + cpe:/a:cgiscript.net:csnews:1.0 + + CVE-2002-0922 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:18.550-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4993 + + + BID + 4991 + + + XF + cgiscript-csnews-admin-access(9333) + + + XF + cgiscript-csnews-file-disclosure(9332) + + + BUGTRAQ + 20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities + + CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. + + + + + + + + + + cpe:/a:cgiscript.net:csnews:1.0_professional + cpe:/a:cgiscript.net:csnews:1.0 + + CVE-2002-0923 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:18.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4994 + + + XF + cgiscript-csnews-admin-access(9333) + + + BUGTRAQ + 20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities + + CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability. + + + + + + + + + + cpe:/a:cgiscript.net:csnews:1.0_professional + cpe:/a:cgiscript.net:csnews:1.0 + + CVE-2002-0924 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:11.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020611 CGIscript.net - csNews.cgi - Multiple Vulnerabilities + + + BID + 4451 + + CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability. + + + + + + + + + + cpe:/a:matthew_mondor:mmftpd:0.0.7 + cpe:/a:matthew_mondor:mmmail:0.0.13 + + CVE-2002-0925 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.037-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4999 + + + BID + 4990 + + + XF + mmftpd-mmsyslog-format-string(9337) + + + XF + mmmail-mmsyslog-format-string(9336) + + + BUGTRAQ + 20020612 [CERT-intexxia] mmftpd FTP Daemon Format String Vulnerability + + + CONFIRM + http://mmondor.gobot.ca/software/linux/mmmail-changelog.txt + + + CONFIRM + http://mmondor.gobot.ca/software/linux/mmftpd-changelog.txt + + + BUGTRAQ + 20020612 [CERT-intexxia] mmmail POP3-SMTP Daemon Format String Vulnerability + + Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier. + + + + + + + + + + cpe:/a:wolfram_research:webmathematica:4.0_professional + cpe:/a:wolfram_research:webmathematica:4.0_amateur + + CVE-2002-0926 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.177-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#664323 + + + BID + 5035 + + + XF + webmathematica-dot-directory-traversal(9373) + + + CONFIRM + http://support.wolfram.com/webmathematica/security/fileaccess.html + + + BUGTRAQ + 20020617 Directory Traversal in Wolfram Research's webMathematica + + Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter. + + + + + + + + + cpe:/a:pirch:pirch_irc:98 + + CVE-2002-0928 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + pirch-irc-link-bo(9409) + + + BID + 5079 + + + BUGTRAQ + 20020621 Pirch 98 Link Handling Buffer Overflow + + Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hyperlink in a channel or private message. + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + + CVE-2002-0929 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.457-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5097 + + + XF + netware-dhcp-dos(9428) + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2962999 + + + VULNWATCH + 20020625 [VulnWatch] cqure.net.20020604.netware_dhcpsrvr + + Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests. + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + + CVE-2002-0930 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.597-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5099 + + + XF + netware-ftp-username-dos(9429) + + + BUGTRAQ + 20020625 cqure.net.20020521.netware_nwftpd_fmtstr + + + VULNWATCH + 20020625 [VulnWatch] cqure.net.20020521.netware_nwftpd_fmtstr + + Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command. + + + + + + + + + cpe:/a:luis_bernardo:myhelpdesk:2002-05-09 + + CVE-2002-0931 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.817-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4970 + + + BID + 4967 + + + XF + myhelpdesk-index-php-xss(9320) + + + XF + myhelpdesk-new-ticket-xss(9319) + + + BUGTRAQ + 20020610 [ARL02-A15] Multiple Security Issues in MyHelpdesk + + Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4) ticketfiles, or (5) updateticketlog operations, or (6) via the update section when a ticket is edited. + + + + + + + + + cpe:/a:luis_bernardo:myhelpdesk:2002-05-09 + + CVE-2002-0932 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:19.973-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4971 + + + XF + myhelpdesk-sql-injection(9321) + + + BUGTRAQ + 20020610 [ARL02-A15] Multiple Security Issues in MyHelpdesk + + SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog. + + + + + + + + + cpe:/a:datalex:bookit_consumer:2.1 + + CVE-2002-0933 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.130-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4972 + + + XF + bookit-plaintext-passwords(9316) + + + BUGTRAQ + 20020610 Datalex BookIt! Consumer Password Vulnerabilities + + Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks. + + + + + + + + + cpe:/a:jon_hedley:alienform2:1.5 + + CVE-2002-0934 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.270-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4983 + + + XF + alienform2-directory-traversal(9325) + + + BUGTRAQ + 20020610 AlienForm2 CGI script: arbitrary file read/write + + Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file. + + + + + + + + + cpe:/a:apache:tomcat:4.0.3 + + CVE-2002-0935 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.427-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5067 + + + XF + tomcat-null-thread-dos(9396) + + + OSVDB + 5051 + + + BUGTRAQ + 20020620 KPMG-2002025: Apache Tomcat Denial of Service + + + VULNWATCH + 20020620 [VulnWatch] KPMG-2002025: Apache Tomcat Denial of Service + + Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang. + + + + + + + + + cpe:/a:apache:tomcat:4.0.3 + + CVE-2002-0936 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.583-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4995 + + + XF + jsp-engine-wprinterjob-dos(9339) + + + VULNWATCH + 20020611 [VulnWatch] Generic Crash-JSP + + + CONFIRM + http://tomcat.apache.org/security-4.html + + The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-0937 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4997 + + + XF + jsp-engine-wprinterjob-dos(9339) + + + VULNWATCH + 20020611 [VulnWatch] Generic Crash-JSP + + The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). + + + + + + + + + + cpe:/a:cisco:secure_access_control_server:3.0.1 + cpe:/a:cisco:secure_access_control_server:3.0 + + CVE-2002-0938 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:20.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5026 + + + XF + ciscosecure-web-css(9353) + + + BUGTRAQ + 20020621 Re: XSS in CiscoSecure ACS v3.0 + + + BUGTRAQ + 20020614 XSS in CiscoSecure ACS v3.0 + + Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe. + + + + + + + + + + cpe:/a:ncipher:mscapi_csp:5.50 + cpe:/a:ncipher:mscapi_csp:5.54 + + CVE-2002-0939 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:25.070-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mscapi-csp-key-generation(9076) + + + BUGTRAQ + 20020513 nCipher Security Advisory #3: MSCAPI CSP Install Wizard + + + BID + 4729 + + The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). + + + + + + + + + + cpe:/a:ncipher:mscapi_csp:5.50 + cpe:/a:ncipher:mscapi_csp:5.54 + + CVE-2002-0940 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:25.147-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020617 nCipher Advisory #3: MSCAPI keys erroneously module-protected - update + + + BUGTRAQ + 20020513 nCipher Security Advisory #3: MSCAPI CSP Install Wizard + + + BID + 4729 + + domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). + + + + + + + + + + + + + + cpe:/a:ncipher:nforce + cpe:/h:ncipher:nshield + + CVE-2002-0941 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:21.347-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5024 + + + XF + ncipher-consolecallback-passphrase-leak(9354) + + + BUGTRAQ + 20020617 nCipher Advisory #4: Console Java apps can leak passphrases on Windows + + The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges. + + + + + + + + + cpe:/a:lumigent:log_explorer:3.01 + + CVE-2002-0942 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:21.503-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + logexplorer-mssql-xplogattach-bo(9346) + + + BID + 5018 + + + BID + 5017 + + + BID + 5016 + + + CONFIRM + http://www.lumigent.com/LogExplorer/Support/whatsnew3_03.htm + + + BUGTRAQ + 20020614 Follow-up on Lumigent Log Explorer 3.xx extended stored procedures buffer overflow + + + BUGTRAQ + 20020614 Lumigent Log Explorer 3.xx extended stored procedures buffer overflow + + Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures (1) xp_logattach_StartProf, (2) xp_logattach_setport, or (3) xp_logattach. + + + + + + + + + cpe:/a:metalinks:metacart2.sql + + CVE-2002-0943 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:21.660-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + metacart2sql-insecure-database-access(9393) + + + BID + 5042 + + + BUGTRAQ + 20020618 Metacart vuln. + + MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb. + + + + + + + + + cpe:/a:deepmetrix:livestats:6.2 + + CVE-2002-0944 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:21.817-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5047 + + + XF + livestats-report-execute-code(9390) + + + CONFIRM + http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp + + + BUGTRAQ + 20020617 DeepMetrix LiveStats javascript injection + + Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. + + + + + + + + + cpe:/a:seanox:devwex:2002-05-20 + + CVE-2002-0945 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:21.973-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4979 + + + XF + devwex-get-bo(9298) + + + CONFIRM + http://www.seanox.de/projects.devwex.php + + + OSVDB + 5047 + + + BUGTRAQ + 20020608 SeaNox Devwex - Denial of Service and Directory traversal + + Buffer overflow in SeaNox Devwex allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. + + + + + + + + + cpe:/a:seanox:devwex:2002-05-20 + + CVE-2002-0946 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:22.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4978 + + + XF + devwex-dotdot-directory-traversal(9299) + + + CONFIRM + http://www.seanox.de/projects.devwex.php + + + OSVDB + 5048 + + + BUGTRAQ + 20020608 SeaNox Devwex - Denial of Service and Directory traversal + + Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot) sequences in an HTTP request. + + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:oracle:reports:6.0.8 + + CVE-2002-0947 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:22.270-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#997403 + + + BID + 4848 + + + XF + oracle-reports-server-bo(9289) + + + MISC + http://www.nextgenss.com/vna/ora-reports.txt + + + CONFIRM + http://technet.oracle.com/deploy/security/pdf/reports6i_alert.pdf + + + BUGTRAQ + 20020612 Oracle Reports Server Buffer Overflow (#NISR12062002B) + + + VULNWATCH + 20020612 [VulnWatch] Oracle Reports Server Buffer Overflow (#NISR12062002B) + + Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter. + + + + + + + + + cpe:/a:scripts_for_educators:makebook:2.2 + + CVE-2002-0948 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:26.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + makebook-name-field-validation(9356) + + + CONFIRM + http://www.tesol.net/scriptmail.html + + + CONFIRM + http://www.linguistic-funland.com/scripts/MakeBook/makebook.script + + + BID + 4996 + + + BUGTRAQ + 20020613 Re: SSI & CSS execution in MakeBook 2.2 + + + BUGTRAQ + 20020612 SSI & CSS execution in MakeBook 2.2 + + Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered. + + + + + + + + + + cpe:/h:telindus:adsl_router:1120 + cpe:/h:telindus:adsl_router:1110 + + CVE-2002-0949 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:22.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4946 + + + XF + telindus-adsl-information-leak(9277) + + + BUGTRAQ + 20020605 Some vulnerabilities in the Telindus 11xx router series + + Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext. + + + + + + + + + + cpe:/a:transware:active_mail:2.0 + cpe:/a:transware:active_mail:1.422 + + CVE-2002-0950 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:22.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5007 + + + XF + activemail-script-tag-header(9358) + + + BUGTRAQ + 20020613 [SNS Advisory No.54] Active! mail Executing the Script upon the Opening of a Mail Message Vulnerability + + Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered. + + + + + + + + + cpe:/a:ruslan_communications:body_builder + + CVE-2002-0951 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:22.880-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5008 + + + XF + bodybuilder-bypass-authentication(9359) + + + BUGTRAQ + 20020613 [LBYTE] Ruslan Communications <BODY>Builder SQL modification + + SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password. + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + + CVE-2002-0952 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5058 + + + XF + cisco-ons-tcc-dos(9377) + + + CISCO + 20020619 Cisco ONS15454 IP TOS Bit Vulnerability + + Cisco ONS15454 optical transport platform running ONS 3.1.0 to 3.2.0 allows remote attackers to cause a denial of service (reset) by sending IP packets with non-zero Type of Service (TOS) bits to the Timing Control Card (TCC) LAN interface. + + + + + + + + + cpe:/a:php_address:php_address:0.2e + + CVE-2002-0953 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5039 + + + XF + phpaddress-include-remote-files(9379) + + + BUGTRAQ + 20020619 Source Injection into PHPAddress + + + BUGTRAQ + 20020617 PHP source injection in PHPAddress + + globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter. + + + + + + + + + cpe:/a:cisco:pix_firewall + + CVE-2002-0954 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.333-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020712 The answer to the PIX encryption issue + + + VULNWATCH + 20020621 [VulnWatch] Weak Cisco Pix Password Encryption Algorithm + + The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques. + + + + + + + + + cpe:/a:yabb:yabb:1_gold_sp_1 + + CVE-2002-0955 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.487-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5078 + + + XF + yabb-invalid-thread-xss(9408) + + + BUGTRAQ + 20020621 [AP] YaBB Cross-Site Scripting vulnerability + + Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message. + + + + + + + + + cpe:/a:iss:blackice_agent:3.1eal + + CVE-2002-0956 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.643-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4950 + + + XF + blackice-standby-inactivate(9275) + + + BUGTRAQ + 20020606 KPMG-2002019: BlackICE Agent not Firewalling After Standby + + + VULNWATCH + 20020606 [VulnWatch] KPMG-2002019: BlackICE Agent not Firewalling After Standby + + BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions. + + + + + + + + + + cpe:/a:iss:blackice_agent:3.1eal + cpe:/a:iss:blackice_agent:3.1ebh + + CVE-2002-0957 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.800-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + blackice-excessive-memory-consumption(9405) + + + VULNWATCH + 20020619 [VulnWatch] KPMG-2002023: BlackICE Agent Temporary Memory Buildup + + The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user. + + + + + + + + + cpe:/a:ekilat_llc:php%28reactor%29:1.2.7 + + CVE-2002-0958 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:23.940-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4952 + + + XF + phpreactor-browse-xss(9280) + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=91877 + + + BUGTRAQ + 20020606 [ARL02-A12] PHP(Reactor) Cross Site Scripting Vulnerability + + Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section. + + + + + + + + + cpe:/a:splatt:splatt_forum:3.0 + + CVE-2002-0959 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + splatt-forum-img-xss(9279) + + + BID + 4953 + + + BUGTRAQ + 20020606 Splatt Forum XSS + + + VULNWATCH + 20020606 [VulnWatch] Splatt Forum XSS + + Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script. + + + + + + + + + cpe:/a:voxel:cbms:0.7 + + CVE-2002-0960 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4957 + + + XF + cbms-php-xss(9294) + + + BUGTRAQ + 20020606 CBMS: XSS and SQL Injection holes + + Multiple cross-site scripting vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allows remote attackers to execute arbitrary script as other CBMS users. + + + + + + + + + cpe:/a:voxel:cbms:0.7 + + CVE-2002-0961 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.393-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4957 + + + XF + cbms-php-sql-injection(9295) + + + BUGTRAQ + 20020606 CBMS: XSS and SQL Injection holes + + Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack. + + + + + + + + + cpe:/a:geeklog:geeklog:1.3.5 + + CVE-2002-0962 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.550-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 4974 + + + BID + 4969 + + + XF + geeklog-index-comment-xss(9310) + + + XF + geeklog-calendar-event-xss(9309) + + + CONFIRM + http://geeklog.sourceforge.net/article.php?story=20020610013358149 + + + BUGTRAQ + 20020610 [ARL02-A13] Multiple Security Issues in GeekLog + + Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, (2) the topic parameter in index.php, or (3) the title parameter in comment.php. + + + + + + + + + cpe:/a:geeklog:geeklog:1.3.5 + + CVE-2002-0963 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.690-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 4968 + + + XF + geeklog-sql-injection(9311) + + + CONFIRM + http://geeklog.sourceforge.net/article.php?story=20020610013358149 + + + BUGTRAQ + 20020610 [ARL02-A13] Multiple Security Issues in GeekLog + + SQL injection vulnerability in comment.php for GeekLog 1.3.5 and earlier allows remote attackers to obtain sensitive user information via the pid parameter. + + + + + + + + + + + + + + + cpe:/a:valve_software:half-life:1.1.0.4::linux + cpe:/a:valve_software:half-life:1.1.0.4::windows + cpe:/a:valve_software:half-life:1.1.0.8 + cpe:/a:valve_software:half-life:1.1.0.9 + cpe:/a:valve_software:half-life:1.1.1.0 + cpe:/a:valve_software:half-life_dedicated_server:3.1 + cpe:/a:valve_software:half-life_dedicated_server:3.1.3 + + CVE-2002-0964 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:24.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5076 + + + XF + halflife-mulitple-player-dos(9412) + + + BUGTRAQ + 20020620 Half-life fake players bug + + Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out. + + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0.2 + cpe:/a:oracle:oracle9i:9.0 + + CVE-2002-0965 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:25.020-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#630091 + + + BID + 4845 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/net9_dos_alert.pdf + + + XF + oracle-listener-servicename-bo(9288) + + + BUGTRAQ + 20020612 Oracle TNS Listener Buffer Overflow (#NISR12062002A) + + + VULNWATCH + 20020612 [VulnWatch] Oracle TNS Listener Buffer Overflow (#NISR12062002A) + + Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file. + + + + + + + + + cpe:/a:aci:4d_webserver:6.7.3 + + CVE-2002-0966 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:25.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + 4d-long-http-bo(9374) + + + BID + 5045 + + + BUGTRAQ + 20020618 4D 6.7 DOS and Buffer Overflow Vulnerability + + Buffer overflow in 4D web server 6.7.3 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request. + + + + + + + + + + cpe:/a:edonkey2000:edonkey_2000_client:35.16.60 + cpe:/a:edonkey2000:edonkey_2000_client:35.16.59 + + CVE-2002-0967 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:25.317-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4951 + + + XF + edonkey2000-ed2k-filename-bo(9278) + + + CONFIRM + http://www.edonkey2000.com/ + + + OSVDB + 5042 + + + BUGTRAQ + 20020606 eDonkey 2000 ed2k: URL Buffer Overflow + + Buffer overflow in eDonkey 2000 35.16.60 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long "ed2k:" URL. + + + + + + + + + cpe:/a:analogx:simpleserver_www:1.16 + + CVE-2002-0968 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:25.473-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5006 + + + XF + analogx-simpleserver-at-dos(9338) + + + CONFIRM + http://www.analogx.com/contents/download/network/sswww.htm + + + OSVDB + 3780 + + + BUGTRAQ + 20020702 Re: Remote DoS in AnlaogX SimpleServer:www 1.16 + + + BUGTRAQ + 20020613 Remote DoS in AnalogX SimpleServer:www 1.16 + + Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name. + + + + + + + + + + + cpe:/a:mysql:mysql:4.0.0 + cpe:/a:mysql:mysql:4.0.1 + cpe:/a:mysql:mysql:3.23.49 + + CVE-2002-0969 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:28.163-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + VULNWATCH + 20021002 wp-02-0003: MySQL Locally Exploitable Buffer Overflow + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0003.txt + + + CONFIRM + http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.x + + + XF + mysql-myini-datadir-bo(10243) + + + BID + 5853 + + + BUGTRAQ + 20021002 wp-02-0003: MySQL Locally Exploitable Buffer Overflow + + Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group. + + + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:3.0 + cpe:/a:kde:konqueror:3.0.2 + cpe:/a:kde:konqueror:3.0.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + cpe:/a:kde:konqueror:3.0 + cpe:/a:kde:konqueror:2.2.2 + + CVE-2002-0970 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:25.787-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5410 + + + DEBIAN + DSA-155 + + + XF + ssl-ca-certificate-spoofing(9776) + + + CONFIRM + http://www.kde.org/info/security/advisory-20020818-1.txt + + + BUGTRAQ + 20020812 Re: IE SSL Vulnerability (Konqueror affected too) + + + REDHAT + RHSA-2002:221 + + + REDHAT + RHSA-2002:220 + + + MANDRAKE + MDKSA-2002:058 + + + CONECTIVA + CLA-2002:519 + + + BUGTRAQ + 20020818 KDE Security Advisory: Konqueror SSL vulnerability + + + CALDERA + CSSA-2002-047.0 + + The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. + + + + + + + + + + + + + + + + + cpe:/a:tridia:tridiavnc:1.5.4 + cpe:/a:tridia:tridiavnc:1.5 + cpe:/a:tightvnc:tightvnc:1.2.0 + cpe:/a:att:winvnc_server:3.3.3_r9 + cpe:/a:tightvnc:tightvnc:1.2.1 + cpe:/a:tridia:tridiavnc:1.5.2 + cpe:/a:tridia:tridiavnc:1.5.1 + cpe:/a:att:winvnc_server:3.3.3_r7 + cpe:/a:tightvnc:tightvnc:1.2.5 + + CVE-2002-0971 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.413-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5530 + + + XF + vnc-win32-messaging-privileges(9979) + + + BUGTRAQ + 20020821 Win32 API 'shatter' vulnerability found in VNC-based products + + Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box. + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-0972 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.493-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020820 @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows in PostgreSQL. + + + REDHAT + RHSA-2003:001 + + Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.6:release + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.3:release + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:4.4:stable + cpe:/o:freebsd:freebsd:4.5:stable + cpe:/o:freebsd:freebsd:4.6.1:release_p10 + cpe:/o:freebsd:freebsd:4.2:stable + cpe:/o:freebsd:freebsd:4.3:stable + cpe:/o:freebsd:freebsd:4.1.1:release + cpe:/o:freebsd:freebsd:4.6 + + CVE-2002-0973 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.557-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + FREEBSD + FreeBSD-SA-02:38 + + + XF + freebsd-negative-system-call-bo(9903) + + + BID + 5493 + + Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl. + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + + CVE-2002-0974 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020815 Delete arbitrary files using Help and Support Center [MSRC 1198dg] + + + XF + winxp-helpctr-delete-files(9878) + + + MSKB + Q328940 + + + BID + 5478 + + + OSVDB + 3001 + + + MS + MS02-060 + + Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm. + + + + + + + + + cpe:/a:microsoft:directx_files_viewer_control:2.0.6.15 + + CVE-2002-0975 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020816 Repost: Buffer overflow in Microsoft DirectX Files Viewer xweb.ocx (<2,0,16,15) ActiveX sample + + + BID + 5489 + + + XF + ms-directx-files-viewer-bo(9877) + + Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:4.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-0976 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.773-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020817 Internet explorer can read local files + + + BID + 5490 + + + XF + ie-xml-read-files(9885) + + Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet. + + + + + + + + + cpe:/a:microsoft:file_transfer_manager + + CVE-2002-0977 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020817 Multiple security vulnerabilities inside Microsoft File Transfer Manager ActiveX control (<4.0) [buffer overflow, arbitrary file upload/download] + + Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value. + + + + + + + + + cpe:/a:microsoft:file_transfer_manager + + CVE-2002-0978 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:28.913-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020817 Multiple security vulnerabilities inside Microsoft File Transfer Manager ActiveX control (<4.0) [buffer overflow, arbitrary file upload/download] + + Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function. + + + + + + + + + cpe:/a:microsoft:virtual_machine + + CVE-2002-0979 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:27.253-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5491 + + + XF + ie-javalogging-code-execution(9886) + + + BUGTRAQ + 20020817 Enableing java logging in MSIE is dangerous + + The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-0980 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:29.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5473 + + + MS + MS03-014 + + + XF + ie-webfolder-script-injection(9881) + + + BUGTRAQ + 20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0 + + + VULN-DEV + 20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0 + + + NTBUGTRAQ + 20020815 SILLY BEHAVIOR : Internet Explorer 5.5 - 6.0 + + The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0981 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:29.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CALDERA + CSSA-2002-SCO.36 + + + BID + 5551 + + + XF + openunix-unixware-ndcfg-bo(9945) + + Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line. + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp2 + + CVE-2002-0982 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:27.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020822 Arbitrary Command Execution on Distributor SQL Server 2000 machines (#NISR22002002A) + + Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure. + + + + + + + + + cpe:/a:irssi:irssi:0.8.4 + + CVE-2002-0983 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:27.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5055 + + + DEBIAN + DSA-157 + + + XF + irssi-long-topic-dos(9395) + + + FREEBSD + FreeBSD-SN-02:05 + + IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a buffer overflow. + + + + + + + + + + cpe:/a:light:light:2.7.30p4 + cpe:/a:light:light:2.8_pre9 + + CVE-2002-0984 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:29.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-156 + + + BID + 5555 + + + XF + light-channel-execute-script(9943) + + + BUGTRAQ + 20020822 Light Security Advisory: Remotely-exploitable code execution + + The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.2 + cpe:/a:php:php:4.0.3:patch1 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + cpe:/a:php:php:4.0.1:patch1 + + CVE-2002-0985 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:28.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:213 + + + DEBIAN + DSA-168 + + + XF + php-mail-safemode-bypass(9966) + + + BUGTRAQ + 20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() + + + REDHAT + RHSA-2003:159 + + + REDHAT + RHSA-2002:248 + + + REDHAT + RHSA-2002:244 + + + REDHAT + RHSA-2002:243 + + + REDHAT + RHSA-2002:214 + + + OSVDB + 2111 + + + SUSE + SuSE-SA:2002:036 + + + MANDRAKE + MDKSA-2003:082 + + + BUGTRAQ + 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) + + + CONECTIVA + CLA-2002:545 + + + CALDERA + CSSA-2003-008.0 + + Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.2 + cpe:/a:php:php:4.0.3:patch1 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + cpe:/a:php:php:4.0.1:patch1 + + CVE-2002-0986 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:28.363-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#410609 + + + BID + 5562 + + + XF + php-mail-ascii-injection(9959) + + + BUGTRAQ + 20020823 PHP: Bypass safe_mode and inject ASCII control chars with mail() + + + REDHAT + RHSA-2003:159 + + + REDHAT + RHSA-2002:248 + + + REDHAT + RHSA-2002:244 + + + REDHAT + RHSA-2002:243 + + + REDHAT + RHSA-2002:214 + + + REDHAT + RHSA-2002:213 + + + OSVDB + 2160 + + + SUSE + SuSE-SA:2002:036 + + + MANDRAKE + MDKSA-2003:082 + + + DEBIAN + DSA-168 + + + BUGTRAQ + 20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php) + + + CONECTIVA + CLA-2002:545 + + + CALDERA + CSSA-2003-008.0 + + The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy." + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0987 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:29.540-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5575 + + + OSVDB + 5044 + + + XF + openunix-unixware-xsco-privileges(9976) + + + CALDERA + CSSA-2002-SCO.38 + + X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges. + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-0988 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:30.227-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5577 + + + XF + openunix-unixware-xsco-bo(9977) + + + CALDERA + CSSA-2002-SCO.38 + + Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities. + + + + + + + + + + + + + + + + + cpe:/a:rob_flynn:gaim:0.58 + cpe:/a:rob_flynn:gaim:0.59 + cpe:/a:rob_flynn:gaim:0.53 + cpe:/a:rob_flynn:gaim:0.52 + cpe:/a:rob_flynn:gaim:0.51 + cpe:/a:rob_flynn:gaim:0.57 + cpe:/a:rob_flynn:gaim:0.56 + cpe:/a:rob_flynn:gaim:0.55 + cpe:/a:rob_flynn:gaim:0.54 + + CVE-2002-0989 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:30.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-158 + + + CONFIRM + http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=72728 + + + CONFIRM + http://gaim.sourceforge.net/ChangeLog + + + BID + 5574 + + + REDHAT + RHSA-2003:156 + + + REDHAT + RHSA-2002:191 + + + REDHAT + RHSA-2002:190 + + + REDHAT + RHSA-2002:189 + + + OSVDB + 5033 + + + XF + gaim-url-handler-command-execution(9978) + + + HP + HPSBTL0209-067 + + + BUGTRAQ + 20020827 GLSA: gaim + + + MANDRAKE + MDKSA-2002:054 + + + CONECTIVA + CLA-2002:521 + + + FREEBSD + FreeBSD-SN-02:06 + + The URL handler in the manual browser option for Gaim before 0.59.1 allows remote attackers to execute arbitrary script via shell metacharacters in a link. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:symantec:raptor_firewall:6.5.3::solaris + cpe:/a:symantec:enterprise_firewall:6.5.2::windows_2000_nt + cpe:/h:symantec:gateway_security:5300 + cpe:/a:symantec:enterprise_firewall:7.0::windows_2000_nt + cpe:/a:symantec:raptor_firewall:6.5::windows_nt + cpe:/a:symantec:velociraptor:500 + cpe:/a:symantec:velociraptor:1000 + cpe:/h:symantec:gateway_security:5110 + cpe:/a:symantec:velociraptor:1200 + cpe:/h:symantec:gateway_security:5200 + cpe:/a:symantec:velociraptor:1300 + cpe:/a:symantec:velociraptor:700 + cpe:/a:symantec:enterprise_firewall:7.0::solaris + cpe:/a:symantec:velociraptor:1100 + + CVE-2002-0990 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:29:29.050-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11.html + + + BUGTRAQ + 20021014 Multiple Symantec Firewall Secure Webserver timeout DoS + + + XF + simple-webserver-url-dos(10364) + + + BID + 5958 + + The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout. + + + + + + + + + + cpe:/a:hp:cifs-9000_server:a.01.06 + cpe:/a:hp:cifs-9000_server:a.01.05 + + CVE-2002-0991 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:29.237-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5088 + + + XF + hp-cifs-login-bo(9431) + + + HP + HPSBUX0207-200 + + + BUGTRAQ + 20020624 Sharity Cifslogin Buffer Overflow (arguments) + + Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters. + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + + CVE-2002-0992 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:29.393-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5143 + + + XF + hp-ipv6-dce-dos(9475) + + + HP + HPSBUX0207-196 + + Unknown vulnerability in IPV6 functionality for DCE daemons (1) dced or (2) rpcd on HP-UX 11.11 allows attackers to cause a denial of service (crash) via an attack that modifies internal data. + + + + + + + + + cpe:/a:hp:instant_support::enterprise + + CVE-2002-0993 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:29.550-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5267 + + + XF + hp-isee-unauth-access(9620) + + + HP + HPSBUX0207-201 + + Unknown vulnerability in HP Instant Support Enterprise Edition (ISEE) product U2512A for HP-UX 11.00 and 11.11 may allow authenticated users access to access restricted files. + + + + + + + + + cpe:/a:sun:sun_pci_ii_driver:2.3 + + CVE-2002-0994 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:29.707-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5146 + + + XF + sunpci-vnc-weak-authentication(9476) + + + VULNWATCH + 20020703 SunPCi II VNC weak authentication scheme vulnerability + + SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications. + + + + + + + + + + + + cpe:/a:gianluca_baldo:phpauction:1.2 + cpe:/a:gianluca_baldo:phpauction:2.0 + cpe:/a:gianluca_baldo:phpauction:1.3 + cpe:/a:gianluca_baldo:phpauction:2.1 + + CVE-2002-0995 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:29.893-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5141 + + + CONFIRM + http://www.phpauction.org/viewnew.php?id=5 + + + XF + phpauction-admin-account-creation(9462) + + + BUGTRAQ + 20020702 PHPAuction bug + + login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table. + + + + + + + + + + + cpe:/a:novell:netmail_xe:3.1 + cpe:/a:novell:netmail:3.0.3a:b + cpe:/a:novell:netmail:3.1 + + CVE-2002-0996 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.083-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5231 + + + BID + 5230 + + + XF + netmail-web-interface-bo(9560) + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963051 + + + BUGTRAQ + 20020715 pwc.20020630.nims_modweb.b + + Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb. + + + + + + + + + + + cpe:/a:novell:netmail_xe:3.1 + cpe:/a:novell:netmail:3.0.3a:b + cpe:/a:novell:netmail:3.1 + + CVE-2002-0997 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.253-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5232 + + + XF + netmail-imap-dos(9559) + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2962974 + + + BUGTRAQ + 20020715 pwc.20020630.nims_3.0.3_imapd.a + + Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service. + + + + + + + + + + cpe:/a:care_2002:care_2002:1.0.01 + cpe:/a:care_2002:care_2002:1.0 + + CVE-2002-0998 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.410-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5218 + + + XF + care2002-include-read-files(9552) + + + BUGTRAQ + 20020712 Several problems in CARE 2002 + + + CONFIRM + http://www.care2x.com/modul.php?thispage=headlines&m_titel=NEWS&m_item=Headlines&lang=en + + Directory traversal vulnerability in cafenews.php for CARE 2002 before beta 1.0.02 allows remote attackers to read arbitrary files via .. (dot dot) sequences and null characters in the lang parameter, which is processed by a call to the include function. + + + + + + + + + + cpe:/a:care_2002:care_2002:1.0.01 + cpe:/a:care_2002:care_2002:1.0 + + CVE-2002-0999 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.537-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 5219 + + + XF + care2002-sql-injection(9553) + + + CONFIRM + http://www.care2x.com/modul.php?thispage=headlines&m_titel=NEWS&m_item=Headlines&lang=en + + + BUGTRAQ + 20020712 Several problems in CARE 2002 + + Multiple SQL injection vulnerabilities in CARE 2002 before beta 1.0.02 allow remote attackers to perform unauthorized database operations. + + + + + + + + + cpe:/a:analogx:simpleserver_shout:1.0 + + CVE-2002-1000 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.677-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5104 + + + XF + analogx-simpleserver-shout-bo(9427) + + + CONFIRM + http://www.analogx.com/contents/download/network/ssshout.htm + + + OSVDB + 3782 + + + BUGTRAQ + 20020626 Foundstone Advisory - Buffer Overflow in AnalogX SimpleServer:Shout (fwd) + + Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001. + + + + + + + + + + + + + + + + cpe:/a:analogx:proxy:4.0.7 + cpe:/a:analogx:proxy:4.0.6 + cpe:/a:analogx:proxy:4.0.3 + cpe:/a:analogx:proxy:4.0.2 + cpe:/a:analogx:proxy:4.0.5 + cpe:/a:analogx:proxy:4.0.4 + cpe:/a:analogx:proxy:4.0.1 + cpe:/a:analogx:proxy:4.0 + + CVE-2002-1001 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:30.833-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5139 + + + BID + 5138 + + + XF + analogx-proxy-socks4a-bo(9456) + + + XF + analogx-proxy-http-bo(9455) + + + CONFIRM + http://www.analogx.com/contents/download/network/proxy.htm + + + BUGTRAQ + 20020701 Foundstone Advisory - Buffer Overflow in AnalogX Proxy (fwd) + + Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname. + + + + + + + + + cpe:/a:novell:emframe:1.2.1 + + CVE-2002-1002 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.020-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5117 + + + XF + netware-imanage-username-dos(9444) + + + BUGTRAQ + 20020627 Cluestick Advisory #001 + + + BUGTRAQ + 20020812 NOVL-2002-2963081 - Novell iManager (eMFrame 1.2.1) DoS Attack + + Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name. + + + + + + + + + + cpe:/a:mywebserver:mywebserver:1.0.1 + cpe:/a:mywebserver:mywebserver:1.0.2 + + CVE-2002-1003 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.160-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5184 + + + XF + mywebserver-long-url-bo(9501) + + + BUGTRAQ + 20020708 Foundstone Advisory - Buffer Overflow in MyWebServer (fwd) + + Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + + cpe:/a:argosoft:argosoft_mail_server:1.8.1.5::plus + cpe:/a:argosoft:argosoft_mail_server:1.8.1.5::pro + + CVE-2002-1004 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.317-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5144 + + + XF + argosoft-dotdot-directory-traversal(9477) + + + CONFIRM + http://www.argosoft.com/applications/mailserver/changelist.asp + + + BUGTRAQ + 20020703 Argosoft Mail Server Plus/Pro Webmail Reverse Directory Traversal + + Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL. + + + + + + + + + + + cpe:/a:argosoft:argosoft_mail_server:1.8.1.5::pro + cpe:/a:argosoft:argosoft_mail_server:1.8.1.7::pro + cpe:/a:argosoft:argosoft_mail_server:1.8.1.6::pro + + CVE-2002-1005 + 2002-10-04T00:00:00.000-04:00 + 2013-09-30T21:22:41.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5395 + + + XF + argosoft-autoresponse-dos(9759) + + + BUGTRAQ + 20020804 Advisory: ArGoSoft Mail Server Pro 1.8.1.7 DoS + + ArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user while autoresponse is enabled, which creates an infinite loop. + + + + + + + + + + + + + + + + + + + + cpe:/a:bbc_education:betsie:1.5.8 + cpe:/a:bbc_education:betsie:1.5.9 + cpe:/a:bbc_education:betsie:1.5.11 + cpe:/a:bbc_education:betsie:1.5.4 + cpe:/a:bbc_education:betsie:1.5.5 + cpe:/a:bbc_education:betsie:1.5.6 + cpe:/a:bbc_education:betsie:1.5.7 + cpe:/a:bbc_education:betsie:1.5 + cpe:/a:bbc_education:betsie:1.5.1 + cpe:/a:bbc_education:betsie:1.5.2 + cpe:/a:bbc_education:betsie:1.5.3 + cpe:/a:bbc_education:betsie:1.5.10 + + CVE-2002-1006 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.643-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5135 + + + XF + betsie-parserl-xss(9468) + + + CONFIRM + http://www.bbc.co.uk/education/betsie/parser.pl.txt + + + BUGTRAQ + 20020701 PTL-2002-03 Betsie XSS Vuln + + Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl. + + + + + + + + + cpe:/a:blackboard:blackboard:5.0 + + CVE-2002-1007 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.830-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5137 + + + XF + blackboard-login-xss(9467) + + + BUGTRAQ + 20020701 CSS in blackboard + + Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi. + + + + + + + + + + cpe:/a:summit_computer_networks:lil_http_server:2.1 + cpe:/a:summit_computer_networks:lil_http_server:2.2 + + CVE-2002-1008 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:31.987-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5115 + + + XF + lilhttp-report-urlcount-xss(9445) + + + BUGTRAQ + 20020708 Technical Details of Urlcount.cgi Vulnerability + + + BUGTRAQ + 20020626 ALERT: Lil'HTTP Server (Summit Computer Networks) + + Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request. + + + + + + + + + + cpe:/a:summit_computer_networks:lil_http_server:2.1 + cpe:/a:summit_computer_networks:lil_http_server:2.2 + + CVE-2002-1009 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.143-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5211 + + + XF + lilhttp-pbcgi-xss(9548) + + + BUGTRAQ + 20020711 Lil'HTTP Pbcgi.cgi XSS Vulnerability + + Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters. + + + + + + + + + cpe:/a:lotus:domino_r4:4.0 + + CVE-2002-1010 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + VULNWATCH + 20020703 [VulnWatch] Lotus Domino R4 File Retrieval Vulnerability... + + Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypasses the web handlers. + + + + + + + + + + + + cpe:/a:ibm:tivoli_management_framework:3.6.1 + cpe:/a:ibm:tivoli_management_framework:3.6 + cpe:/a:ibm:tivoli_management_framework:3.7 + cpe:/a:ibm:tivoli_management_framework:3.7.1 + + CVE-2002-1011 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.440-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5235 + + + XF + tivoli-tmr-endpoint-bo(9555) + + + MISC + http://www.tivoli.com/secure/support/documents/security/mgt-fwk-http-vul.html + + + BUGTRAQ + 20020715 Tivoli TMF Endpoint Buffer Overflow + + + VULNWATCH + 20020715 Tivoli TMF Endpoint Buffer Overflow + + Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. + + + + + + + + + + + + cpe:/a:ibm:tivoli_management_framework:3.6.1 + cpe:/a:ibm:tivoli_management_framework:3.6 + cpe:/a:ibm:tivoli_management_framework:3.7 + cpe:/a:ibm:tivoli_management_framework:3.7.1 + + CVE-2002-1012 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.597-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5233 + + + XF + tivoli-tmr-managednode-bo(9556) + + + MISC + http://www.tivoli.com/secure/support/documents/security/mgt-fwk-http-vul.html + + + BUGTRAQ + 20020715 Tivoli TMF ManagedNode Buffer Overflow + + + VULNWATCH + 20020715 Tivoli TMF ManagedNode Buffer Overflow + + Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. + + + + + + + + + + + + + + + + + cpe:/a:inktomi:traffic_server:5.2.0r + cpe:/a:inktomi:traffic_edge:1.5.0 + cpe:/a:inktomi:traffic_server:5.1.3 + cpe:/a:inktomi:traffic_server:4.0.20 + cpe:/a:inktomi:traffic_server:5.2.2 + cpe:/a:inktomi:traffic_edge:1.1.2 + cpe:/a:inktomi:traffic_server:5.2.1 + cpe:/a:inktomi:media-ixt:3.0.4 + cpe:/a:inktomi:traffic_server:4.0.18 + + CVE-2002-1013 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.753-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5098 + + + XF + inktomi-trafficserver-manager-bo(9465) + + + CONFIRM + http://support.inktomi.com/kb/070202-003.html + + + BUGTRAQ + 20020702 CORE-20020620: Inktomi Traffic Server Buffer Overflow + + Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argument. + + + + + + + + + + + + + cpe:/a:realnetworks:realjukebox_2_plus:1.0.2.379 + cpe:/a:realnetworks:realjukebox_2:1.0.2.340 + cpe:/a:realnetworks:realjukebox_2:1.0.2.379 + cpe:/a:realnetworks:realone_player:6.0.10.505:gold + cpe:/a:realnetworks:realjukebox_2_plus:1.0.2.340 + + CVE-2002-1014 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:32.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#843667 + + + BID + 5217 + + + XF + realplayer-rjs-controlnimage-bo(9538) + + + CONFIRM + http://service.real.com/help/faq/security/bufferoverrun07092002.html + + + BUGTRAQ + 20020712 [SPSadvisory#48]RealONE Player Gold / RealJukebox2 Buffer Overflow + + Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image. + + + + + + + + + + + + + cpe:/a:realnetworks:realjukebox_2_plus:1.0.2.379 + cpe:/a:realnetworks:realjukebox_2:1.0.2.340 + cpe:/a:realnetworks:realjukebox_2:1.0.2.379 + cpe:/a:realnetworks:realone_player:6.0.10.505:gold + cpe:/a:realnetworks:realjukebox_2_plus:1.0.2.340 + + CVE-2002-1015 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.080-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#888547 + + + BID + 5210 + + + XF + realplayer-rjs-file-download(9539) + + + CONFIRM + http://service.real.com/help/faq/security/bufferoverrun07092002.html + + + BUGTRAQ + 20020712 [SPSadvisory#47]RealONE Player Gold / RealJukebox2 skin file download vulnerability + + RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers. + + + + + + + + + cpe:/a:adobe:digital_editions:2.2::win + + CVE-2002-1016 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.237-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#438867 + + + BID + 5273 + + + XF + adobe-ebook-bypass-restrictions(9634) + + + FULLDISC + 20020719 Vulnerability found: Adobe Acrobat eBook Reader and Content Server + + Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files. + + + + + + + + + + + + cpe:/a:adobe:digital_editions:2.1::win + cpe:/a:adobe:digital_editions:9.2.1::mac_os_x + cpe:/a:adobe:digital_editions:9.2.2::mac_os_x + cpe:/a:adobe:digital_editions:2.2::win + + CVE-2002-1017 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.393-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5358 + + + XF + adobe-ebook-bypass-activation(9740) + + + BUGTRAQ + 20020730 Vulnerability: protected Adobe eBooks can be copied between computers + + Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the activation code. + + + + + + + + + cpe:/a:adobe:adobe_content_server:3.0 + + CVE-2002-1018 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.550-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020712 Vulnerability found: The Adobe eBook Library + + + VULN-DEV + 20020712 Vulnerability found: The Adobe eBook Library + + + VULNWATCH + 20020712 [VulnWatch] Vulnerability found: The Adobe eBook Library (fwd) + + The library feature for Adobe Content Server 3.0 does not verify if a customer has already checked out an eBook, which allows remote attackers to cause a denial of service (resource exhaustion) by checking out the same book multiple times. + + + + + + + + + cpe:/a:adobe:adobe_content_server:3.0 + + CVE-2002-1019 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.707-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020712 Vulnerability found: The Adobe eBook Library + + + VULN-DEV + 20020712 Vulnerability found: The Adobe eBook Library + + + VULNWATCH + 20020712 [VulnWatch] Vulnerability found: The Adobe eBook Library (fwd) + + The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp. + + + + + + + + + cpe:/a:adobe:adobe_content_server:3.0 + + CVE-2002-1020 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:33.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020712 Vulnerability found: The Adobe eBook Library + + + VULN-DEV + 20020712 Vulnerability found: The Adobe eBook Library + + + VULNWATCH + 20020712 [VulnWatch] Vulnerability found: The Adobe eBook Library (fwd) + + The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available. + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.3_personal + cpe:/a:working_resources_inc.:badblue:1.7.3_enterprise + + CVE-2002-1021 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:34.003-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5226 + + + XF + badblue-null-file-disclosure(9557) + + + BUGTRAQ + 20020712 Three BadBlue Vulnerabilities + + BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte. + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.3_personal + cpe:/a:working_resources_inc.:badblue:1.7.3_enterprise + + CVE-2002-1022 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:34.160-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5228 + + + XF + badblue-plaintext-passwords(9558) + + + BUGTRAQ + 20020712 Three BadBlue Vulnerabilities + + BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges. + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.3_personal + cpe:/a:working_resources_inc.:badblue:1.7.3_enterprise + + CVE-2002-1023 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:34.300-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5187 + + + XF + badblue-get-dos(9528) + + + BUGTRAQ + 20020712 Three BadBlue Vulnerabilities + + + BUGTRAQ + 20020709 ALERT: Working Resources BadBlue #2 (DoS, Heap Overflow) + + BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1yd + cpe:/o:cisco:ios:12.1yc + cpe:/o:cisco:ios:12.2xb + cpe:/o:cisco:ios:12.1yb + cpe:/o:cisco:ios:12.2xa + cpe:/o:cisco:ios:12.2xd + cpe:/o:cisco:ios:12.2xf + cpe:/o:cisco:ios:12.1yf + cpe:/o:cisco:ios:12.2xe + cpe:/o:cisco:ios:12.1ye + cpe:/o:cisco:catos:5.5%283%29 + cpe:/o:cisco:ios:12.2xq + cpe:/o:cisco:ios:12.2xr + cpe:/o:cisco:ios:12.2xs + cpe:/o:cisco:ios:12.2xt + cpe:/o:cisco:catos:6.1%281b%29 + cpe:/o:cisco:ios:12.2xg + cpe:/o:cisco:ios:12.2xh + cpe:/o:cisco:ios:12.2xi + cpe:/o:cisco:ios:12.1yi + cpe:/o:cisco:ios:12.2xj + cpe:/o:cisco:ios:12.2xk + cpe:/o:cisco:ios:12.2xl + cpe:/o:cisco:ios:12.2xm + cpe:/o:cisco:ios:12.2xn + cpe:/o:cisco:catos:5.5%284%29 + cpe:/o:cisco:ios:12.2dd + cpe:/o:cisco:catos:6.1%281c%29 + cpe:/o:cisco:ios:12.1ec + cpe:/o:cisco:catos:6.1%281%29 + cpe:/o:cisco:catos:7.1 + cpe:/o:cisco:ios:12.2da + cpe:/o:cisco:catos:5.4%281%29 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:catos:5.3%283%29csx + cpe:/o:cisco:ios:12.1%288a%29ex + cpe:/o:cisco:ios:12.2yg + cpe:/a:cisco:css11000_content_services_switch + cpe:/o:cisco:ios:12.2yf + cpe:/o:cisco:ios:12.2yd + cpe:/o:cisco:ios:12.2yc + cpe:/o:cisco:ios:12.2yb + cpe:/o:cisco:ios:12.2ya + cpe:/o:cisco:ios:12.0xb + cpe:/o:cisco:catos:5.4 + cpe:/o:cisco:ios:12.2xw + cpe:/o:cisco:catos:5.5 + cpe:/o:cisco:ios:12.0xm + cpe:/o:cisco:ios:12.2bc + cpe:/o:cisco:catos:7.1%282%29 + cpe:/o:cisco:catos:6.3%280.7%29pan + cpe:/o:cisco:ios:12.0xv + cpe:/o:cisco:ios:12.2yh + cpe:/o:cisco:ios:12.1%289%29ex + cpe:/o:cisco:catos:6.3%284%29 + cpe:/o:cisco:catos:6.1%281a%29 + cpe:/o:cisco:catos:5.4%283%29 + cpe:/o:cisco:ios:12.2s + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:catos:5.5%2813%29 + cpe:/o:cisco:catos:5.3%286%29csx + cpe:/o:cisco:catos:5.3%285%29csx + cpe:/o:cisco:pix_firewall:6.0 + cpe:/o:cisco:pix_firewall:6.1 + cpe:/o:cisco:pix_firewall:6.2 + cpe:/o:cisco:catos:5.4%282%29 + cpe:/o:cisco:pix_firewall:5.2 + cpe:/o:cisco:pix_firewall:5.3 + cpe:/o:cisco:catos:5.3%281%29csx + cpe:/o:cisco:ios:12.1%285c%29ex + cpe:/o:cisco:catos:6.1%282.13%29 + cpe:/o:cisco:catos:5.5%281%29 + cpe:/o:cisco:ios:12.1e + cpe:/o:cisco:ios:12.0sp + cpe:/o:cisco:catos:5.5%284a%29 + cpe:/o:cisco:catos:6.2%280.111%29 + cpe:/o:cisco:catos:5.3%281a%29csx + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1%281%29ex + cpe:/o:cisco:ios:12.2b + cpe:/o:cisco:ios:12.1xm + cpe:/o:cisco:catos:5.3%285a%29csx + cpe:/o:cisco:catos:5.5%282%29 + cpe:/o:cisco:ios:12.1xl + cpe:/o:cisco:catos:5.3%284%29csx + cpe:/o:cisco:ios:12.1xj + cpe:/o:cisco:catos:5.5%284b%29 + cpe:/o:cisco:ios:12.1xi + cpe:/o:cisco:ios:12.1xh + cpe:/o:cisco:catos:6.2%280.110%29 + cpe:/o:cisco:ios:12.1xu + cpe:/o:cisco:ios:12.1xt + cpe:/o:cisco:ios:12.1xq + cpe:/o:cisco:catos:5.3%282%29csx + cpe:/o:cisco:ios:12.1xp + cpe:/o:cisco:catos:5.4%284%29 + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.1xf + cpe:/o:cisco:ios:12.1xg + cpe:/o:cisco:ios:12.0st + cpe:/o:cisco:ios:12.1xb + cpe:/o:cisco:ios:12.1xc + + CVE-2002-1024 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:34.457-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#290140 + + + BID + 5114 + + + XF + cisco-ssh-scan-dos(9437) + + + CISCO + 20020627 Scanning for SSH Can Cause a Crash + + + + + Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144). + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-1025 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:34.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5134 + + + XF + jrun-null-view-source(9459) + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23164 + + + OSVDB + 5028 + + + BUGTRAQ + 20020701 KPMG-2002026: Jrun sourcecode Disclosure + + + VULNWATCH + 20020701 [VulnWatch] KPMG-2002026: Jrun sourcecode Disclosure + + JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed. + + + + + + + + + cpe:/a:macromedia:sitespring:1.2.0 + + CVE-2002-1026 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.097-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5132 + + + XF + sitespring-sybase-dos(9458) + + + BUGTRAQ + 20020701 KPMG-2002028: Sitespring Server Denial of Service + + + VULNWATCH + 20020701 [VulnWatch] KPMG-2002028: Sitespring Server Denial of Service + + Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly triggering a buffer overflow. + + + + + + + + + cpe:/a:macromedia:sitespring:1.2.0 + + CVE-2002-1027 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.253-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5249 + + + XF + sitespring-500error-xss(9588) + + + BUGTRAQ + 20020717 KPMG-2002032: Macromedia Sitespring Cross Site Scripting + + + VULNWATCH + 20020717 [VulnWatch] KPMG-2002032: Macromedia Sitespring Cross Site Scripting + + Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter. + + + + + + + + + cpe:/a:oddsock:song_requester:2.1 + + CVE-2002-1028 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.410-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5248 + + + MISC + http://www.oddsock.org/tools/gen_songrequester/#Release%202.2%20Notes%20: + + + XF + oddsock-song-requester-dos(9585) + + + BUGTRAQ + 20020716 Outpost24 Advisory: Oddsock PlaylistGenerator Multiple BufferOverlow vulnerability + + Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments. + + + + + + + + + cpe:/a:worldspan:res_manager:4.1 + + CVE-2002-1029 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.550-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5169 + + + XF + worldspan-res-manager-dos(9490) + + + BUGTRAQ + 20020704 Worldspan DoS + + + OSVDB + 14478 + + Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 17990. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:6.1:sp1 + cpe:/a:bea:weblogic_server:5.1:sp2:express + cpe:/a:bea:weblogic_server:6.0:sp2 + cpe:/a:bea:weblogic_server:6.1:sp2 + cpe:/a:bea:weblogic_server:6.0:sp1 + cpe:/a:bea:weblogic_server:5.1:sp3:express + cpe:/a:bea:weblogic_server:6.1:sp3 + cpe:/a:bea:weblogic_server:5.1:sp4:express + cpe:/a:bea:weblogic_server:5.1:sp1:express + cpe:/a:bea:weblogic_server:5.1:sp11:express + cpe:/a:bea:weblogic_server:5.1:sp7:express + cpe:/a:bea:weblogic_server:5.1:sp8:express + cpe:/a:bea:weblogic_server:5.1:sp5:express + cpe:/a:bea:weblogic_server:5.1:sp12:express + cpe:/a:bea:weblogic_server:5.1 + cpe:/a:bea:weblogic_server:5.1:sp10:express + cpe:/a:bea:weblogic_server:5.1:sp9:express + cpe:/a:bea:weblogic_server:6.1:sp2:express + cpe:/a:bea:weblogic_server:6.0:sp1:express + cpe:/a:bea:weblogic_server:6.1:sp1:express + cpe:/a:bea:weblogic_server:6.1:sp3:express + cpe:/a:bea:weblogic_server:6.0:sp2:express + cpe:/a:bea:weblogic_server:6.0 + cpe:/a:bea:weblogic_server:6.1 + cpe:/a:bea:weblogic_server:5.1:sp10 + cpe:/a:bea:weblogic_server:5.1:sp4 + cpe:/a:bea:weblogic_server:5.1:sp3 + cpe:/a:bea:weblogic_server:5.1:sp2 + cpe:/a:bea:weblogic_server:5.1:sp12 + cpe:/a:bea:weblogic_server:5.1:sp1 + cpe:/a:bea:weblogic_server:5.1:sp9 + cpe:/a:bea:weblogic_server:5.1:sp7 + cpe:/a:bea:weblogic_server:5.1:sp8 + cpe:/a:bea:weblogic_server:5.1:sp5 + cpe:/a:bea:weblogic_server:5.1:sp6 + cpe:/a:bea:weblogic_server:7.0::express + cpe:/a:bea:weblogic_server:5.1:sp6:express + cpe:/a:bea:weblogic_server:6.1::express + cpe:/a:bea:weblogic_server:6.0::express + cpe:/a:bea:weblogic_server:5.1::express + + CVE-2002-1030 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.707-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5159 + + + XF + weblogic-race-condition-dos(9486) + + + BUGTRAQ + 20020708 KPMG-2002029: Bea Weblogic Performance Pack Denial of Service + + + CONFIRM + http://dev2dev.bea.com/resourcelibrary/advisoriesdetail.jsp?highlight=advisoriesnotifications&path=components%2Fdev2dev%2Fresourcelibrary%2Fadvisoriesnotifications%2Fadvisory_BEA02-19.htm + + + VULNWATCH + 20020708 [VulnWatch] KPMG-2002029: Bea Weblogic Performance Pack Denial of Service + + Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections. + + + + + + + + + cpe:/a:key_focus:kf_web_server:1.0.2 + + CVE-2002-1031 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:35.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5177 + + + XF + kfwebserver-null-view-dir(9500) + + + CONFIRM + http://www.keyfocus.net/kfws/support/ + + + BUGTRAQ + 20020707 KF Web Server version 1.0.2 shows file and directory content + + + VULNWATCH + 20020707 [VulnWatch] KF Web Server version 1.0.2 shows file and directory content + + KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character. + + + + + + + + + cpe:/a:key_focus:kf_web_server:1.0.5 + + CVE-2002-1032 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.keyfocus.net/kfws/support/ + + Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header. + + + + + + + + + cpe:/a:sun:i-runbook:2.5.2 + + CVE-2002-1033 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.237-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5209 + + + XF + sun-irunbook-information-disclosure(9549) + + + BUGTRAQ + 20020711 Portcullis Security Advisory - Directory Traversal Vulnerability in SunPS iRunbook 2.5.2 + + Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument. + + + + + + + + + cpe:/a:sun:i-runbook:2.5.2 + + CVE-2002-1034 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.393-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5209 + + + XF + sun-irunbook-information-disclosure(9549) + + + BUGTRAQ + 20020711 Portcullis Security Advisory - Directory Traversal Vulnerability in SunPS iRunbook 2.5.2 + + none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument. + + + + + + + + + cpe:/a:omnicron:omnihttpd:2.09 + + CVE-2002-1035 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.550-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5136 + + + XF + omnihttpd-http-version-bo(9457) + + + OSVDB + 5000 + + + BUGTRAQ + 20020701 BufferOverflow in OmniHTTPd 2.09 + + Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number. + + + + + + + + + + + + + cpe:/a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0052 + cpe:/a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0053 + cpe:/a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0050 + cpe:/a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0051 + cpe:/a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0054 + + CVE-2002-1036 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.690-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5199 + + + XF + fd-search-xss(9533) + + + CONFIRM + http://www.xav.com/scripts/search/changes.htm#4 + + + BUGTRAQ + 20020710 XSS Hole in Fluid Dynamics search Engine + + + BUGTRAQ + 20020710 RE: XSS Hole in Fluid Dynamics Search engine + + Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters. + + + + + + + + + + cpe:/a:michael_dean:double_choco_latte:2002-01-20 + cpe:/a:michael_dean:double_choco_latte:2002-02-15 + + CVE-2002-1037 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:36.847-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5182 + + + XF + dcl-html-injection(9532) + + + BUGTRAQ + 20020714 Double Choco Latte multiple vulnerabilities + + + CONFIRM + http://dcl.sourceforge.net/index.php + + + VULNWATCH + 20020714 [VulnWatch] Double Choco Latte multiple vulnerabilities + + Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features. + + + + + + + + + + cpe:/a:michael_dean:double_choco_latte:2002-01-20 + cpe:/a:michael_dean:double_choco_latte:2002-02-15 + + CVE-2002-1038 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.003-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dcl-file-upload(9742) + + + BUGTRAQ + 20020714 Double Choco Latte multiple vulnerabilities + + + CONFIRM + http://dcl.sourceforge.net/index.php + + + VULNWATCH + 20020714 [VulnWatch] Double Choco Latte multiple vulnerabilities + + Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features. + + + + + + + + + + cpe:/a:michael_dean:double_choco_latte:2002-01-20 + cpe:/a:michael_dean:double_choco_latte:2002-02-15 + + CVE-2002-1039 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.160-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + dcl-dotdot-directory-traversal(9743) + + + CONFIRM + http://dcl.sourceforge.net/index.php + + + BUGTRAQ + 20020714 Double Choco Latte multiple vulnerabilities + + + VULNWATCH + 20020714 [VulnWatch] Double Choco Latte multiple vulnerabilities + + Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1040 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.317-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY29749 + + Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1041 + 2002-10-04T00:00:00.000-04:00 + 2011-03-07T21:09:24.437-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY23359 + + Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sun:iplanet_web_server:4.1:sp2 + cpe:/a:sun:iplanet_web_server:4.1:sp1 + cpe:/a:sun:iplanet_web_server:4.1:sp9:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp4 + cpe:/a:sun:iplanet_web_server:4.1:sp3 + cpe:/a:sun:iplanet_web_server:4.1:sp7:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp5:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp8:enterprise + cpe:/a:sun:one_application_server:6.0 + cpe:/a:sun:iplanet_web_server:4.1:sp6:enterprise + cpe:/a:sun:one_web_server:6.0:sp3 + cpe:/a:sun:iplanet_web_server:4.1 + cpe:/a:sun:one_application_server:6.0:sp2 + cpe:/a:sun:iplanet_web_server:4.1:sp6 + cpe:/a:sun:iplanet_web_server:4.1:sp8 + cpe:/a:sun:iplanet_web_server:4.1:sp5 + cpe:/a:sun:one_application_server:6.0:sp1 + cpe:/a:sun:iplanet_web_server:4.1:sp3:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp7 + cpe:/a:sun:iplanet_web_server:4.1:sp4:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp1:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp9 + cpe:/a:sun:iplanet_web_server:4.1:sp2:enterprise + cpe:/a:sun:iplanet_web_server:4.1:sp10:enterprise + cpe:/a:netscape:enterprise_server:3.6 + cpe:/a:sun:iplanet_web_server:4.1:sp10 + + CVE-2002-1042 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.613-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5191 + + + XF + iplanet-search-view-files(9517) + + + BUGTRAQ + 20020709 iPlanet Remote File Viewing + + Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter. + + + + + + + + + cpe:/a:ultrafunk:popcorn:1.20 + + CVE-2002-1043 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.817-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5212 + + + XF + popcorn-mail-dos(9547) + + + BUGTRAQ + 20020711 Popcorn vulnerabilities + + Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t"). + + + + + + + + + cpe:/a:ultrafunk:popcorn:1.20 + + CVE-2002-1044 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:37.973-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5212 + + + XF + popcorn-mail-dos(9547) + + + BUGTRAQ + 20020711 Popcorn vulnerabilities + + Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field. + + + + + + + + + cpe:/a:ultrafunk:popcorn:1.20 + + CVE-2002-1045 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5212 + + + XF + popcorn-mail-dos(9547) + + + BUGTRAQ + 20020711 Popcorn vulnerabilities + + Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037. + + + + + + + + + + + + + + cpe:/h:watchguard:soho_firewall:5.0.35a + cpe:/h:watchguard:soho_firewall:5.0.31 + cpe:/h:watchguard:soho_firewall:5.0.35 + cpe:/h:watchguard:firebox:5.0 + cpe:/h:watchguard:soho_firewall:5.0.28 + cpe:/h:watchguard:soho_firewall:5.0.29 + + CVE-2002-1046 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.270-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5186 + + + XF + firebox-dvcp-dos(9509) + + + VULNWATCH + 20020709 KPMG-2002030: Watchguard Firebox Dynamic VPN Configuration Protocol DoS + + Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110. + + + + + + + + + cpe:/h:watchguard:soho_firewall:5.0.35a + + CVE-2002-1047 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.427-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + firebox-soho-ftp-insecure(9511) + + + VULNWATCH + 20020701 [VulnWatch] KPMG-2002027: Watchguard Soho FTP authentication flaw + + The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name. + + + + + + + + + + + + + + + + + + + + + cpe:/h:hp:jetdirect:x.20.00 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.17 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.02 + cpe:/h:hp:jetdirect:j3111a_rev._g.07.03 + cpe:/h:hp:jetdirect:x.08.20 + cpe:/h:hp:jetdirect:j3111a_rev._g.05.35 + cpe:/h:hp:jetdirect:j3111a_rev._g.08.03 + cpe:/h:hp:jetdirect:x.08.32 + cpe:/h:hp:jetdirect:x.08.00 + cpe:/h:hp:jetdirect:x.21.00 + cpe:/h:hp:jetdirect:j3111a_rev._a.08.06 + cpe:/h:hp:jetdirect:x.08.04 + cpe:/h:hp:jetdirect:x.08.05 + + CVE-2002-1048 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#377003 + + + BID + 5331 + + + XF + hp-jetdirect-snmp-read(9693) + + + BUGTRAQ + 20020727 Phenoelit Advisory #0815 +-+ + + HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0. + + + + + + + + + + + + + + + + + + cpe:/a:hylafax:hylafax:4.1_beta3 + cpe:/a:hylafax:hylafax:4.1_beta2 + cpe:/a:hylafax:hylafax:4.0.2 + cpe:/a:hylafax:hylafax:4.1 + cpe:/a:hylafax:hylafax:4.1.1 + cpe:/a:hylafax:hylafax:4.1.2 + cpe:/a:hylafax:hylafax:4.1_beta1 + cpe:/a:hylafax:hylafax:4.0_pl0 + cpe:/a:hylafax:hylafax:4.0_pl1 + cpe:/a:hylafax:hylafax:4.0_pl2 + + CVE-2002-1049 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.753-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5348 + + + XF + hylafax-faxgetty-tsi-dos(9728) + + + DEBIAN + DSA-148 + + + CONFIRM + http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=300 + + + OSVDB + 5002 + + + SUSE + SuSE-SA:2002:035 + + + MANDRAKE + MDKSA-2002:055 + + + BUGTRAQ + 20020729 HylaFAX - Various Vulnerabilities Fixed + + Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element. + + + + + + + + + + + + + + + + + + cpe:/a:hylafax:hylafax:4.1_beta3 + cpe:/a:hylafax:hylafax:4.1_beta2 + cpe:/a:hylafax:hylafax:4.0.2 + cpe:/a:hylafax:hylafax:4.1 + cpe:/a:hylafax:hylafax:4.1.1 + cpe:/a:hylafax:hylafax:4.1.2 + cpe:/a:hylafax:hylafax:4.1_beta1 + cpe:/a:hylafax:hylafax:4.0_pl0 + cpe:/a:hylafax:hylafax:4.0_pl1 + cpe:/a:hylafax:hylafax:4.0_pl2 + + CVE-2002-1050 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:38.927-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5349 + + + XF + hylafax-faxgetty-image-bo(9729) + + + DEBIAN + DSA-148 + + + CONFIRM + http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=312 + + + SUSE + SuSE-SA:2002:035 + + + MANDRAKE + MDKSA-2002:055 + + + BUGTRAQ + 20020729 HylaFAX - Various Vulnerabilities Fixed + + Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data. + + + + + + + + + + + cpe:/a:ehud_gavron:tracesroute:6.1.1 + cpe:/a:ehud_gavron:tracesroute:6.0 + cpe:/a:ehud_gavron:tracesroute:6.1 + + CVE-2002-1051 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:48.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4956 + + + XF + tracesroute-t-format-string(9291) + + + SUSE + SuSE-SA:2000:041 + + + BUGTRAQ + 20020724 Re: Nanog traceroute format string exploit. + + + BUGTRAQ + 20020721 Nanog traceroute format string exploit. + + + BUGTRAQ + 20020723 Re: Nanog traceroute format string exploit. + + + BUGTRAQ + 20020606 Format String bug in TrACESroute 6.0 GOLD + + Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument. + + + + + + + + + cpe:/a:w3c:jigsaw:2.2.1 + + CVE-2002-1052 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:39.237-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5258 + + + BID + 5251 + + + XF + jigsaw-dos-device-dos(9587) + + + XF + jigsaw-aux-path-disclosure(9586) + + + VULNWATCH + 20020717 [VulnWatch] KPMG-2002034: Jigsaw Webserver DOS device DoS + + + VULNWATCH + 20020717 [VulnWatch] KPMG-2002031: Jigsaw Webserver Path Disclosure + + + BUGTRAQ + 20020717 KPMG-2002034: Jigsaw Webserver DOS device DoS + + + BUGTRAQ + 20020717 KPMG-2002031: Jigsaw Webserver Path Disclosure + + Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device. + + + + + + + + + cpe:/a:w3c:jigsaw:2.2 + + CVE-2002-1053 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:39.393-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5506 + + + XF + jigsaw-http-proxy-xss(9914) + + + CONFIRM + http://www.w3.org/Jigsaw/RelNotes.html#2.2.1 + + + OSVDB + 4015 + + + BUGTRAQ + 20020817 W3C Jigsaw Proxy Server: Cross-Site Scripting Vulnerability (REPOST) + + Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message. + + + + + + + + + cpe:/a:pablo_software_solutions:pablo_ftp_server:1.0_build_9 + + CVE-2002-1054 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:39.533-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5283 + + + XF + pablo-ftp-directory-traversal(9647) + + + CONFIRM + http://www.pablovandermeer.nl/ftpserversrc.zip + + + OSVDB + 4995 + + + BUGTRAQ + 20020722 Pablo Sofware Solutions FTP server Directory Traversal Vulnerability + + + VULNWATCH + 20020722 [VulnWatch] Pablo Sofware Solutions FTP server Directory Traversal Vulnerability + + Directory traversal vulnerability in Pablo FTP server 1.0 build 9 and earlier allows remote authenticated users to list arbitrary directories via "..\" (dot-dot backslash) sences in a LIST command. + + + + + + + + + cpe:/h:brother:nc-3100h + + CVE-2002-1055 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:39.690-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5339 + + + XF + brother-nc-password-bo(9701) + + + BUGTRAQ + 20020727 phenoelit advisory, Brother Printers ++/- + + Buffer overflow in administrative web server for Brother NC-3100h printer allows remote attackers to cause a denial of service via a long password. + + + + + + + + + + + + + + cpe:/a:microsoft:word:2000:sr1a + cpe:/a:microsoft:word:2002 + cpe:/a:microsoft:outlook:2002 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:outlook:2000 + cpe:/a:microsoft:word:2000:sr1 + + CVE-2002-1056 + 2002-05-16T00:00:00.000-04:00 + 2008-09-10T15:13:48.837-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + MS + MS02-021 + + + BID + 4397 + + + XF + outlook-object-execute-script(8708) + + + BUGTRAQ + 20020403 More Office XP problems (Version 2.0) + + + BUGTRAQ + 20020331 More Office XP Problems + + + + + + + + Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to. + + + + + + + + + cpe:/a:smartmax_software:mailmax:4.8 + + CVE-2002-1057 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.003-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5285 + + + XF + mailmax-pop3max-user-bo(9651) + + + BUGTRAQ + 20020723 MailMax security advisory/exploit/patch + + Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command. + + + + + + + + + cpe:/a:cobalt:qube:3.0 + + CVE-2002-1058 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.207-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5297 + + + XF + cobalt-qube-admin-access(9669) + + + BUGTRAQ + 20020723 Cobalt Qube 3 Administration page + + Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:van_dyke_technologies:securecrt:3.4.5 + cpe:/a:van_dyke_technologies:securecrt:4.0_beta_2 + cpe:/a:van_dyke_technologies:securecrt:3.4 + cpe:/a:van_dyke_technologies:securecrt:3.3 + cpe:/a:van_dyke_technologies:securecrt:3.4.2 + cpe:/a:van_dyke_technologies:securecrt:3.2 + cpe:/a:van_dyke_technologies:securecrt:3.4.1 + cpe:/a:van_dyke_technologies:securecrt:3.1 + cpe:/a:van_dyke_technologies:securecrt:3.4.4 + cpe:/a:van_dyke_technologies:securecrt:3.0 + cpe:/a:van_dyke_technologies:securecrt:3.4.3 + cpe:/a:van_dyke_technologies:securecrt:3.1.1 + cpe:/a:van_dyke_technologies:securecrt:3.1.2 + cpe:/a:van_dyke_technologies:securecrt:4.0_beta_1 + cpe:/a:van_dyke_technologies:securecrt:2.4 + cpe:/a:van_dyke_technologies:securecrt:3.3.1 + cpe:/a:van_dyke_technologies:securecrt:3.2.1 + cpe:/a:van_dyke_technologies:securecrt:3.3.3 + cpe:/a:van_dyke_technologies:securecrt:3.3.2 + + CVE-2002-1059 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.363-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5287 + + + XF + securecrt-ssh1-identifier-bo(9650) + + + CONFIRM + http://www.vandyke.com/products/securecrt/security07-25-02.html + + + OSVDB + 4991 + + + BUGTRAQ + 20020723 Re: Arbitrary Code Execution Vulnerability in VanDyke SecureCRT + + + BUGTRAQ + 20020723 Arbitrary Code Execution Vulnerability in VanDyke SecureCRT 3.4 & 4.0 beta + + Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string. + + + + + + + + + + + + + + + + + + cpe:/o:bluecoat:cacheos:4.0.14 + cpe:/o:bluecoat:cacheos:3.1.21 + cpe:/o:bluecoat:cacheos:4.1.6 + cpe:/o:bluecoat:cacheos:3.1.19 + cpe:/o:bluecoat:cacheos:3.1.18 + cpe:/o:bluecoat:cacheos:4.0.11 + cpe:/o:bluecoat:cacheos:4.0.12 + cpe:/o:bluecoat:cacheos:3.1.17 + cpe:/o:bluecoat:cacheos:4.0.13 + cpe:/o:bluecoat:cacheos:4.0 + + CVE-2002-1060 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.550-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5305 + + + XF + cacheos-unresolved-error-xss(9674) + + + BID + 5608 + + + CONFIRM + http://download.cacheflow.com/release/CA/4.1.00-docs/CACacheOS41fixes.htm + + + BUGTRAQ + 20020724 CacheFlow CacheOS Cross-site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1061 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.723-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5320 + + + BID + 5324 + + + BID + 5322 + + + BID + 5319 + + + XF + jana-smtp-logging-bo(9686) + + + XF + jana-pop3-logging-bo(9685) + + + XF + jana-http-proxy-bo(9683) + + + XF + jana-http-logging-bo(9682) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP GET request with a long major version number, (2) an HTTP GET request to the HTTP proxy on port 3128 with a long major version number, (3) a long OK reply from a POP3 server, and (4) a long SMTP server response. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1062 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:40.893-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5321 + + + XF + jana-socks5-bo(9684) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1063 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.067-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5325 + + + XF + jana-ftp-pasv-dos(9687) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes all available FTP ports. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1064 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.223-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5326 + + + XF + jana-pop3-bruteforce(9688) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1065 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.393-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + jana-pop3-bruteforce(9688) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing. + + + + + + + + + + + + + + + cpe:/a:t._hauck:jana_web_server:1.46 + cpe:/a:t._hauck:jana_web_server:1.45 + cpe:/a:t._hauck:jana_web_server:2.0_beta2 + cpe:/a:t._hauck:jana_web_server:2.2.1 + cpe:/a:t._hauck:jana_web_server:2.0_beta1 + cpe:/a:t._hauck:jana_web_server:1.0 + cpe:/a:t._hauck:jana_web_server:2.0 + + CVE-2002-1066 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.567-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5327 + + + XF + jana-pop3-index-bo(9689) + + + BUGTRAQ + 20020726 SECURITY.NNOV: multiple vulnerabilities in JanaServer + + Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack. + + + + + + + + + + cpe:/h:seh:ic9_pocket_print_server_firmware:7.1.36 + cpe:/h:seh:ic9_pocket_print_server_firmware:7.1.30 + + CVE-2002-1067 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.723-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5329 + + + XF + seh-ic9-password-bo(9702) + + + BUGTRAQ + 20020727 0815 ++ */ SEH_Web + + Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow. + + + + + + + + + cpe:/h:d-link:dp-303 + + CVE-2002-1068 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:41.877-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5330 + + + XF + dlink-dp-post-dos(9703) + + + BUGTRAQ + 20020727 Phenoelit Advisory #0815 ++-+ dp_300 (DLINK) + + + VULN-DEV + 20020727 Phenoelit Advisory #0815 ++-+ dp_300 (DLINK) + + The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request. + + + + + + + + + cpe:/h:d-link:di-804:4.68 + + CVE-2002-1069 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.017-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5553 + + + BID + 5544 + + + XF + dlink-admin-device-information(9969) + + + XF + dlink-admin-dhcp-release(9967) + + + BUGTRAQ + 20020822 possible exploit: D-Link DI-804 unauthorized DHCP release from WAN + + + BUGTRAQ + 20020822 Re: possible exploit: D-Link DI-804 unauthorized DHCP release + + The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information. + + + + + + + + + + + + + + cpe:/a:php-wiki:php-wiki:1.2.2 + cpe:/a:php-wiki:php-wiki:1.2.1 + cpe:/a:php-wiki:php-wiki:1.2 + cpe:/a:php-wiki:php-wiki:1.3.3 + cpe:/a:php-wiki:php-wiki:1.3.2 + cpe:/a:php-wiki:php-wiki:1.3.1 + + CVE-2002-1070 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.177-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5254 + + + XF + phpwiki-xss(9627) + + + BUGTRAQ + 20020716 Wiki module postnuke Cross Site Scripting Vulnerability + + Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter. + + + + + + + + + + cpe:/h:zyxel:prestige:642r + cpe:/h:zyxel:prestige:310 + + CVE-2002-1071 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.330-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5034 + + + XF + zyxel-tcp-packet-dos(9372) + + + BUGTRAQ + 20020617 Re: ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS -- 643R testing + + + BUGTRAQ + 20020617 Follow: ZyXEL 642R-11 AJ.6 service DoS -- additional informations + + + BUGTRAQ + 20020617 ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS + + ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set. + + + + + + + + + + cpe:/h:zyxel:prestige:642r + cpe:/h:zyxel:prestige:310 + + CVE-2002-1072 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.487-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5292 + + + XF + zyxel-jolt-dos(9655) + + + BUGTRAQ + 20020724 Denial of Service in ZyXEL prestige 642R w/ZyNOS v2.50(FA.1) + + + VULNWATCH + 20020724 [VulnWatch] Denial of Service in ZyXEL prestige 642R w/ZyNOS v2.50(FA.1) + + ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet. + + + + + + + + + + + + + + cpe:/a:atrium_software:mercur_mailserver:3.3 + cpe:/a:atrium_software:mercur_mailserver:4.1_sp1 + cpe:/a:atrium_software:mercur_mailserver:4.2 + cpe:/a:atrium_software:mercur_mailserver:4.1 + cpe:/a:atrium_software:mercur_mailserver:3.3_sp2 + cpe:/a:atrium_software:mercur_mailserver:3.3_sp1 + + CVE-2002-1073 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mercur-control-service-bo(9618) + + + BID + 5261 + + + BUGTRAQ + 20020717 MERCUR Mailserver advisory/remote exploit + + Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. + + + + + + + + + cpe:/a:david_harris:pegasus_mail:4.01 + + CVE-2002-1075 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.800-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5302 + + + XF + pegasus-message-header-bo(9673) + + + BUGTRAQ + 20020724 Pegasus mail DoS + + Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers. + + + + + + + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:7.0.1 + cpe:/a:ipswitch:imail:7.1 + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:7.0.7 + cpe:/a:ipswitch:imail:6.4 + cpe:/a:ipswitch:imail:7.0.6 + cpe:/a:ipswitch:imail:6.3 + cpe:/a:ipswitch:imail:7.0.5 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:7.0.3 + cpe:/a:ipswitch:imail:7.0.2 + + CVE-2002-1076 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:42.940-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5323 + + + XF + imail-web-messaging-bo(9679) + + + CONFIRM + http://support.ipswitch.com/kb/IM-20020731-DM02.htm + + + CONFIRM + http://support.ipswitch.com/kb/IM-20020729-DM01.htm + + + BUGTRAQ + 20020729 Re: Hoax Exploit (2c79cbe14ac7d0b8472d3f129fa1df55 RETURNS) + + + BUGTRAQ + 20020729 Hoax Exploit + + + BUGTRAQ + 20020725 IPSwitch IMail ADVISORY/EXPLOIT/PATCH + + Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0. + + + + + + + + + + + + + + + + + + + + cpe:/a:ipswitch:imail:7.0.1 + cpe:/a:ipswitch:imail:7.1 + cpe:/a:ipswitch:imail:6.2 + cpe:/a:ipswitch:imail:6.1 + cpe:/a:ipswitch:imail:7.0.7 + cpe:/a:ipswitch:imail:6.4 + cpe:/a:ipswitch:imail:7.0.6 + cpe:/a:ipswitch:imail:6.3 + cpe:/a:ipswitch:imail:7.0.5 + cpe:/a:ipswitch:imail:7.0.4 + cpe:/a:ipswitch:imail:7.0.3 + cpe:/a:ipswitch:imail:7.0.2 + + CVE-2002-1077 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.113-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5365 + + + XF + imail-iwebcal-content-length-dos(9722) + + + BUGTRAQ + 20020730 IPSwitch IMail Advisory #2 + + IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field. + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0.3 + + CVE-2002-1078 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.283-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5345 + + + XF + abyss-slash-directory-traversal(9721) + + + BUGTRAQ + 20020729 Abyss Web Server version 1.0.3 shows file and directory content + + + VULNWATCH + 20020729 [VulnWatch] Abyss Web Server version 1.0.3 shows file and directory content + + Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters. + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0.3_p2 + + CVE-2002-1079 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.440-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + abyss-get-directory-traversal(9941) + + + XF + abyss-http-directory-traversal(9940) + + + CONFIRM + http://www.aprelium.com/news/patch1033.html + + + BID + 5547 + + + OSVDB + 3285 + + + BUGTRAQ + 20020822 Abyss 1.0.3 directory traversal and administration bugs + + Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request. + + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0 + cpe:/a:aprelium_technologies:abyss_web_server:1.0.3 + + CVE-2002-1080 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.580-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5548 + + + XF + abyss-admin-console-access(9957) + + + BUGTRAQ + 20020822 Abyss 1.0.3 directory traversal and administration bugs + + + CONFIRM + http://www.aprelium.com/news/patch1033.html + + The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl. + + + + + + + + + + cpe:/a:aprelium_technologies:abyss_web_server:1.0 + cpe:/a:aprelium_technologies:abyss_web_server:1.0.3 + + CVE-2002-1081 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + abyss-plus-file-disclosure(9956) + + + CONFIRM + http://www.aprelium.com/news/patch1033.html + + + BID + 5549 + + + OSVDB + 3286 + + + BUGTRAQ + 20020822 Abyss 1.0.3 directory traversal and administration bugs + + The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.40 + + CVE-2002-1082 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:43.893-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ezcontents-image-file-upload(9698) + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.41 + + CVE-2002-1083 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.050-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ezcontents-dotdot-directory-traversal(9710) + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.41 + + CVE-2002-1084 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.190-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ezcontents-verifylogin-post-data(9711) + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.41 + + CVE-2002-1085 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.330-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ezcontents-diary-entry-xss(9712) + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.41 + + CVE-2002-1086 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.487-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + ezcontents-sql-injection(9713) + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities. + + + + + + + + + cpe:/a:visualshapers:ezcontents:1.41 + + CVE-2002-1087 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.627-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020725 ezContents multiple vulnerabilities + + + VULNWATCH + 20020725 [VulnWatch] ezContents multiple vulnerabilities + + The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request. + + + + + + + + + + + cpe:/a:novell:groupwise:6.0 + cpe:/a:novell:groupwise:6.0.1:sp1 + cpe:/a:novell:groupwise:6.0:sp1 + + CVE-2002-1088 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.783-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5313 + + + XF + groupwise-rcpt-bo(9671) + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963273 + + + BUGTRAQ + 20020725 Novell GroupWise 6.0.1 Support Pack 1 Bufferoverflow + + Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command. + + + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:oracle:reports:6.0.8 + cpe:/a:oracle:reports:6.0.8.19 + + CVE-2002-1089 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:44.940-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5262 + + + XF + oracle-reports-information-disclosure(9628) + + + BUGTRAQ + 20020717 [AP] Oracle Reports Server Information Disclosure Vulnerability + + rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. + + + + + + + + + cpe:/a:libesmtp:libesmtp:0.8.11 + + CVE-2002-1090 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.stafford.uklinux.net/libesmtp/ChangeLog.txt + + Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses. + + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:mozilla:0.9.6 + cpe:/a:mozilla:mozilla:0.9.5 + cpe:/a:netscape:navigator:6.2 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:0.9.8 + cpe:/a:mozilla:mozilla:0.9.7 + cpe:/a:opera_software:opera_web_browser:6.0 + cpe:/a:netscape:navigator:6.2.3 + cpe:/a:netscape:navigator:6.2.2 + cpe:/a:netscape:navigator:6.2.1 + cpe:/a:opera_software:opera_web_browser:5.12 + cpe:/a:opera_software:opera_web_browser:6.0.1 + cpe:/a:mozilla:mozilla:1.0 + + CVE-2002-1091 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.253-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5665 + + + REDHAT + RHSA-2002:192 + + + XF + netscape-zero-gif-bo(10058) + + + BUGTRAQ + 20020906 zero-width gif: exploit PoC for NS6.2.3 (fixed in 7.0) [Was: GIFs + + + MISC + http://crash.ihug.co.nz/~Sneuro/zerogif/ + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=157989 + + + REDHAT + RHSA-2003:046 + + + MANDRAKE + MDKSA-2002:075 + + Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:3.6%28rel%29 + + CVE-2002-1092 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.423-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cisco-vpn-bypass-authentication(10017) + + + BID + 5613 + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication. + + + + + + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1093 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.567-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-html-parser-dos(10018) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5615 + + HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:3.5.3 + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1094 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5624 + + + BID + 5623 + + + BID + 5621 + + + XF + cisco-vpn-banner-information(10020) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request. + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/a:cisco:secure_access_control_server:2.6.3::windows_nt + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1095 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:45.957-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-pptp-dos(10021) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5625 + + Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1096 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:46.127-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cisco-vpn-user-passwords(10019) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5611 + + Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1097 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:46.330-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cisco-vpn-certificate-passwords(10022) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5612 + + Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1098 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:46.533-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-xml-filter(10023) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5614 + + Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1099 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:46.753-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-web-access(10024) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + + BID + 5616 + + Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1100 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:46.970-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5617 + + + XF + cisco-vpn-html-interface-dos(10025) + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:3.5.3 + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.5.4 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.6%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1101 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:47.190-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:3.5.3 + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1102 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:47.423-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-lan-connection-dos(10027) + + + BID + 5622 + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:vpn_3000_concentrator:3.5.3 + cpe:/a:cisco:vpn_3002_hardware_client + cpe:/o:cisco:vpn_3000_concentrator:3.5.2 + cpe:/o:cisco:vpn_3000_concentrator:3.5.1 + cpe:/o:cisco:vpn_3000_concentrator:3.1.1 + cpe:/o:cisco:vpn_3000_concentrator:3.5.4 + cpe:/o:cisco:vpn_3000_concentrator:3.1.2 + cpe:/o:cisco:vpn_3000_concentrator:2.0 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.f + cpe:/o:cisco:vpn_3000_concentrator:3.5%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.0%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.6%28rel%29 + cpe:/o:cisco:vpn_3000_concentrator:3.1 + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.b + cpe:/o:cisco:vpn_3000_concentrator:3.0.3.a + cpe:/o:cisco:vpn_3000_concentrator:3.0 + cpe:/o:cisco:vpn_3000_concentrator:3.0.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.b + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.a + cpe:/o:cisco:vpn_3000_concentrator:3.1.4 + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.d + cpe:/o:cisco:vpn_3000_concentrator:2.5.2.c + + CVE-2002-1103 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:47.643-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#761651 + + + CISCO + 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities + + Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets. + + + + + + + + + + cpe:/a:cisco:vpn_client:2.0::windows + cpe:/a:cisco:vpn_client:3.0::windows + + CVE-2002-1104 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:47.863-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-tcp-dos(10042) + + + BID + 5649 + + + CISCO + 20020905 Cisco VPN Client Multiple Vulnerabilities - Second Set + + Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS). + + + + + + + + + + + + cpe:/a:cisco:vpn_client:2.0::windows + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.0::windows + cpe:/a:cisco:vpn_client:3.1::windows + + CVE-2002-1105 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:48.017-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-vpn-obtain-password(10044) + + + CISCO + 20020905 Cisco VPN Client Multiple Vulnerabilities - Second Set + + + BID + 5650 + + Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password. + + + + + + + + + + + + cpe:/a:cisco:vpn_client:2.0::windows + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.0::windows + cpe:/a:cisco:vpn_client:3.1::windows + + CVE-2002-1106 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:48.173-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-vpn-certificate-mitm(10045) + + + BID + 5652 + + + CISCO + 20020905 Cisco VPN Client Multiple Vulnerabilities - Second Set + + Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks. + + + + + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_client:3.0::windows + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.5.2::windows + cpe:/a:cisco:vpn_client:3.1::windows + cpe:/a:cisco:vpn_client:3.5.1c::windows + cpe:/a:cisco:vpn_client:3.0.5::windows + cpe:/a:cisco:vpn_client:3.5.1::mac_os_x + cpe:/a:cisco:vpn_client:2.0::windows + cpe:/a:cisco:vpn_client:3.5.2::mac_os_x + cpe:/a:cisco:vpn_client:3.5.2::linux + cpe:/a:cisco:vpn_client:3.5.1::linux + cpe:/a:cisco:vpn_client:3.5.2::solaris + cpe:/a:cisco:vpn_client:3.5.1::solaris + + CVE-2002-1107 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:48.330-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cisco-vpn-random-numbers(10046) + + + BID + 5653 + + + CISCO + 20020905 Cisco VPN Client Multiple Vulnerabilities - Second Set + + Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing. + + + + + + + + + + + + + + + + + cpe:/a:cisco:vpn_client:3.5.1c::windows + cpe:/a:cisco:vpn_client:3.0.5::windows + cpe:/a:cisco:vpn_client:3.5.1::mac_os_x + cpe:/a:cisco:vpn_client:2.0::windows + cpe:/a:cisco:vpn_client:3.5.1::windows + cpe:/a:cisco:vpn_client:3.0::windows + cpe:/a:cisco:vpn_client:3.5.1::linux + cpe:/a:cisco:vpn_client:3.1::windows + cpe:/a:cisco:vpn_client:3.5.1::solaris + + CVE-2002-1108 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:48.517-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cisco-vpn-tcp-filter(10047) + + + BID + 5651 + + + CISCO + 20020905 Cisco VPN Client Multiple Vulnerabilities - Second Set + + Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel. + + + + + + + + + cpe:/a:amavis:virus_scanner:0.2.1 + + CVE-2002-1109 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:53.930-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + amavis-securetar-tar-dos(10056) + + + BUGTRAQ + 20020905 GLSA: amavis + + + CONFIRM + http://marc.theaimsgroup.com/?l=amavis-announce&m=103121272122242&w=2 + + securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.15.3 + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.16.1 + cpe:/a:mantis:mantis:0.16.0 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.15.10 + cpe:/a:mantis:mantis:0.15.9 + cpe:/a:mantis:mantis:0.15.8 + cpe:/a:mantis:mantis:0.15.7 + cpe:/a:mantis:mantis:0.15.6 + cpe:/a:mantis:mantis:0.15.11 + cpe:/a:mantis:mantis:0.15.5 + cpe:/a:mantis:mantis:0.15.12 + cpe:/a:mantis:mantis:0.15.4 + + CVE-2002-1110 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:48.830-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5510 + + + DEBIAN + DSA-153 + + + XF + mantis-user-sql-injection(9897) + + + CONFIRM + http://mantisbt.sourceforge.net/advisories/2002/2002-01.txt + + + BUGTRAQ + 20020819 [Mantis Advisory/2002-01] SQL poisoning vulnerability in Mantis + + Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php. + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.16.1 + cpe:/a:mantis:mantis:0.16.0 + + CVE-2002-1111 + 2002-10-04T00:00:00.000-04:00 + 2010-10-06T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 5515 + + + DEBIAN + DSA-153 + + + BUGTRAQ + 20020819 [Mantis Advisory/2002-02] Limiting output to reporters can be bypassed + + + XF + mantis-limit-reporters-bypass(9898) + + + CONFIRM + http://mantisbt.sourceforge.net/advisories/2002/2002-02.txt + + print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.15.3 + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.16.1 + cpe:/a:mantis:mantis:0.16.0 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.15.10 + cpe:/a:mantis:mantis:0.15.9 + cpe:/a:mantis:mantis:0.15.8 + cpe:/a:mantis:mantis:0.15.7 + cpe:/a:mantis:mantis:0.15.6 + cpe:/a:mantis:mantis:0.15.11 + cpe:/a:mantis:mantis:0.15.5 + cpe:/a:mantis:mantis:0.15.12 + cpe:/a:mantis:mantis:0.15.4 + + CVE-2002-1112 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:49.207-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5514 + + + DEBIAN + DSA-153 + + + BUGTRAQ + 20020819 [Mantis Advisory/2002-03] Bug listings of private projects can be viewed through cookie manipulation + + + XF + mantis-private-project-bug-listing(9899) + + + CONFIRM + http://mantisbt.sourceforge.net/advisories/2002/2002-03.txt + + Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.15.3 + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.16.1 + cpe:/a:mantis:mantis:0.16.0 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.15.10 + cpe:/a:mantis:mantis:0.15.9 + cpe:/a:mantis:mantis:0.15.8 + cpe:/a:mantis:mantis:0.15.7 + cpe:/a:mantis:mantis:0.15.6 + cpe:/a:mantis:mantis:0.15.11 + cpe:/a:mantis:mantis:0.15.5 + cpe:/a:mantis:mantis:0.15.12 + cpe:/a:mantis:mantis:0.15.4 + + CVE-2002-1113 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:49.410-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5504 + + + DEBIAN + DSA-153 + + + XF + mantis-include-remote-files(9829) + + + OSVDB + 4858 + + + BUGTRAQ + 20020819 [Mantis Advisory/2002-04] Arbitrary code execution + + + BUGTRAQ + 20020813 mantisbt security flaw + + summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code. + + + + + + + + + + + + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + + CVE-2002-1114 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:49.597-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mantis-configinc-var-include(9900) + + + BID + 5509 + + + DEBIAN + DSA-153 + + + BUGTRAQ + 20020819 [Mantis Advisory/2002-05] Arbitrary code execution and file reading vulnerability in Mantis + + config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie. + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.17.4 + cpe:/a:mantis:mantis:0.17.4a + + CVE-2002-1115 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:49.753-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-161 + + + BID + 5563 + + + XF + mantis-view-private-bugs(9954) + + + CONFIRM + http://mantisbt.sourceforge.net/advisories/2002/2002-06.txt + + + BUGTRAQ + 20020823 [Mantis Advisory/2002-06] Private bugs accessible in Mantis + + Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php. + + + + + + + + + + + + + + cpe:/a:mantis:mantis:0.17.0 + cpe:/a:mantis:mantis:0.17.1 + cpe:/a:mantis:mantis:0.17.3 + cpe:/a:mantis:mantis:0.17.2 + cpe:/a:mantis:mantis:0.17.4 + cpe:/a:mantis:mantis:0.17.4a + + CVE-2002-1116 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:49.910-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-161 + + + XF + mantis-viewbugs-bug-listing(9955) + + + BID + 5565 + + + BUGTRAQ + 20020823 [Mantis Advisory/2002-07] Bugs in private projects listed on 'View Bugs' + + The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to any projects. + + + + + + + + + cpe:/a:symantec_veritas:backup_exec:8.5 + + CVE-2002-1117 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:50.080-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BUGTRAQ + 20020906 UPDATE: (Was Veritas Backup Exec opens networks for NetBIOS based attacks?) + + + XF + veritas-backupexec-restrictanonymous-zero(10093) + + + CONFIRM + http://seer.support.veritas.com/docs/238618.htm + + + OSVDB + 8230 + + + BUGTRAQ + 20020906 Veritas Backup Exec opens networks for NetBIOS based attacks? + + + + + Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:oracle:oracle8i:8.1.5.0.0_enterprise + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0.2 + cpe:/a:oracle:oracle9i:9.0.1_3 + cpe:/a:oracle:oracle8i:8.1.6 + cpe:/a:oracle:oracle8i:8.1.6.1.0_enterprise + cpe:/a:oracle:oracle8i:8.1.7 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle9i:release_2_9.2.2 + cpe:/a:oracle:oracle8i:8.1.5.1.0_enterprise + cpe:/a:oracle:oracle9i:release_2_9.2.1 + cpe:/a:oracle:oracle8i:8.1.7.1.0_enterprise + cpe:/a:oracle:oracle9i:9.0.1.2 + cpe:/a:oracle:oracle8i:8.1.7.0.0_enterprise + cpe:/a:oracle:oracle8i:8.1.6.0.0_enterprise + cpe:/a:oracle:oracle8i:8.1.7.1 + cpe:/a:oracle:oracle8i:8.1.5 + cpe:/a:oracle:oracle8i:8.1.5.0.2_enterprise + + CVE-2002-1118 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T20:03:00.507-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert42rev1.pdf + + + VULNWATCH + 20021009 R7-0006: Oracle 8i/9i Listener SERVICE_CURLOAD Denial of Service + + + XF + oracle-net-services-dos(10283) + + + BID + 5678 + + TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command. + + + + + + + + + cpe:/a:python_software_foundation:python:2.2.1 + + CVE-2002-1119 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:50.487-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5581 + + + DEBIAN + DSA-159 + + + XF + python-execvpe-tmpfile-symlink(10009) + + + MISC + http://mail.python.org/pipermail/python-dev/2002-August/027229.html + + + REDHAT + RHSA-2003:048 + + + REDHAT + RHSA-2002:202 + + + MANDRAKE + MDKSA-2002:082 + + + BUGTRAQ + 20030123 [OpenPKG-SA-2003.006] OpenPKG Security Advisory (python) + + + CONECTIVA + CLA-2002:527 + + + CALDERA + CSSA-2002-045.0 + + os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack. + + + + + + + + + cpe:/a:savant:savant_web_server:3.1 + + CVE-2002-1120 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:50.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + VULNWATCH + 20020910 Foundstone Labs Advisory - Buffer Overflow in Savant Web Server + + + BID + 5686 + + + XF + savant-long-url-bo(10076) + + Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + + + + + + + + + + + cpe:/a:roaring_penguin:canit:1.2 + cpe:/a:network_associates:webshield_smtp:4.5.74.0 + cpe:/a:roaring_penguin:mimedefang:2.20 + cpe:/a:trend_micro:interscan_viruswall:3.5 + cpe:/a:network_associates:webshield_smtp:4.5 + cpe:/a:gfi:mailsecurity:7.2::exchange_smtp + cpe:/a:network_associates:webshield_smtp:4.5.44 + cpe:/a:trend_micro:interscan_viruswall:3.52 + cpe:/a:trend_micro:interscan_viruswall:3.51 + cpe:/a:network_associates:webshield_smtp:4.0.5 + cpe:/a:roaring_penguin:mimedefang:2.14 + + CVE-2002-1121 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T20:03:00.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#836088 + + + BUGTRAQ + 20020912 MIMEDefang update (was Re: Bypassing SMTP Content Protection ) + + + BID + 5696 + + + MISC + http://www.securiteam.com/securitynews/5YP0A0K8CM.html + + + XF + smtp-content-filtering-bypass(10088) + + + VULNWATCH + 20020912 Bypassing SMTP Content Protection with a Flick of a Button + + + BUGTRAQ + 20020912 FW: Bypassing SMTP Content Protection with a Flick of a Button + + + BUGTRAQ + 20020912 Bypassing SMTP Content Protection with a Flick of a Button + + + BUGTRAQ + 20020912 Roaring Penguin fixes for "Bypassing SMTP Content Protection with a Flick of a Button" + + SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type. + + + + + + + + + cpe:/a:iss:internet_scanner:6.2.1 + + CVE-2002-1122 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:55.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + ISS + 20020918 Flaw in Internet Scanner Parsing Mechanism + + + BID + 5738 + + + OSVDB + 3150 + + + XF + is-http-response-bo(10130) + + Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response. + + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-1123 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:55.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mssql-preauth-bo(9788) + + + BUGTRAQ + 20020807 MS SQL Server Hello Overflow NASL script + + + BID + 5411 + + + MS + MS02-056 + + + CIAC + N-003 + + + BUGTRAQ + 20020806 SPIKE 2.5 and associated vulns + + Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow. + + + + + + + + + + + cpe:/a:purity:purity:1.15 + cpe:/a:purity:purity:1.14 + cpe:/a:purity:purity:1.9 + + CVE-2002-1124 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:51.253-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5702 + + + DEBIAN + DSA-166 + + + XF + linux-purity-bo(10100) + + Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables. + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:4.6 + + CVE-2002-1125 + 2002-09-24T00:00:00.000-04:00 + 2008-09-10T15:13:55.290-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5720 + + + BID + 5719 + + + BID + 5718 + + + BID + 5716 + + + BID + 5714 + + + XF + bsd-libkvm-descriptor-leak(10109) + + + VULNWATCH + 20020916 iDEFENSE Security Advisory 09.16.2002: FreeBSD Ports libkvm Security Vulnerabilities + + + FREEBSD + FreeBSD-SA-02:39 + + + BUGTRAQ + 20020916 iDEFENSE Security Advisory 09.16.2002: FreeBSD Ports libkvm Security Vulnerabilities + + FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory. + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:mozilla:0.9.6 + cpe:/a:mozilla:mozilla:0.9.5 + cpe:/a:mozilla:mozilla:0.9.4 + cpe:/a:mozilla:mozilla:0.9.3 + cpe:/a:mozilla:mozilla:1.0.1 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:0.9.8 + cpe:/a:mozilla:mozilla:0.9.7 + cpe:/a:galeon:galeon_browser:1.2.6 + cpe:/a:galeon:galeon_browser:1.2.5 + cpe:/a:galeon:galeon_browser:1.2.4 + cpe:/a:mozilla:mozilla:1.1 + + CVE-2002-1126 + 2002-09-24T00:00:00.000-04:00 + 2008-09-05T16:29:51.567-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5694 + + + REDHAT + RHSA-2002:192 + + + XF + mozilla-onunload-url-leak(10084) + + + BUGTRAQ + 20020911 Privacy leak in mozilla + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=145579 + + + REDHAT + RHSA-2003:046 + + + MANDRAKE + MDKSA-2002:075 + + Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler. + + + + + + + + + + + + + + + + + + cpe:/o:digital:osf_1:3.0b + cpe:/o:digital:osf_1:3.2d + cpe:/o:digital:osf_1:3.2 + cpe:/o:digital:osf_1:3.2c + cpe:/o:digital:osf_1:3.2b + cpe:/o:digital:osf_1:3.2g + cpe:/o:digital:osf_1:3.2de1 + cpe:/o:digital:osf_1:3.0 + cpe:/o:digital:osf_1:3.2f + cpe:/o:digital:osf_1:3.2de2 + + CVE-2002-1127 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:51.737-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20020918 iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3. + + + BID + 5745 + + + XF + osf1-uucp-source-bo(10146) + + Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter. + + + + + + + + + + + + + + + + + + + + cpe:/o:digital:osf_1:3.0b + cpe:/o:digital:osf_1:4.0 + cpe:/o:digital:osf_1:3.2d + cpe:/o:digital:osf_1:3.2 + cpe:/o:digital:osf_1:3.2c + cpe:/o:digital:osf_1:3.2b + cpe:/o:digital:osf_1:3.2g + cpe:/o:digital:osf_1:3.2de1 + cpe:/o:digital:osf_1:3.0 + cpe:/o:digital:osf_1:3.2f + cpe:/o:digital:ultrix:3.0 + cpe:/o:digital:osf_1:3.2de2 + + CVE-2002-1128 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:55.493-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20020918 iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3. + + + BID + 5747 + + + XF + osf1-inc-mh-bo(10147) + + Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:digital:osf_1:3.0b + cpe:/o:digital:osf_1:3.2d + cpe:/o:digital:osf_1:3.2c + cpe:/o:compaq:tru64:5.1_pk5_bl19 + cpe:/o:digital:osf_1:3.2b + cpe:/o:digital:osf_1:3.2de1 + cpe:/o:compaq:tru64:5.1a + cpe:/o:digital:osf_1:3.2de2 + cpe:/o:compaq:tru64:4.0g_pk3_bl17 + cpe:/o:compaq:tru64:5.1_pk3_bl17 + cpe:/o:digital:osf_1:3.2 + cpe:/o:digital:osf_1:3.2g + cpe:/o:compaq:tru64:4.0f_pk7_bl18 + cpe:/o:digital:osf_1:3.0 + cpe:/o:digital:osf_1:3.2f + cpe:/o:compaq:tru64:5.1a_pk1_bl1 + cpe:/o:compaq:tru64:4.0f_pk6_bl17 + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:5.0 + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:4.0f + cpe:/o:compaq:tru64:5.1a_pk2_bl2 + cpe:/o:compaq:tru64:5.1_pk4_bl18 + cpe:/o:compaq:tru64:5.0_pk4_bl17 + cpe:/o:compaq:tru64:5.0_pk4_bl18 + cpe:/o:compaq:tru64:5.0a_pk3_bl17 + + CVE-2002-1129 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:55.557-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + VULNWATCH + 20020918 iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3. + + + BID + 5746 + + + XF + osf1-dxterm-xrm-bo(10148) + + + BUGTRAQ + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument. + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.7 + + CVE-2002-1131 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:52.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5763 + + + REDHAT + RHSA-2002:204 + + + XF + squirrelmail-php-xss(10145) + + + DEBIAN + DSA-191 + + + BUGTRAQ + 20020919 Squirrel Mail 1.2.7 XSS Exploit + + + CONFIRM + http://sourceforge.net/project/shownotes.php?group_id=311&release_id=110774 + + Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php. + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.7 + + CVE-2002-1132 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:52.440-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-191 + + + XF + squirrelmail-options-path-disclosure(10345) + + + BUGTRAQ + 20020919 Squirrel Mail 1.2.7 XSS Exploit + + + BID + 5949 + + + REDHAT + RHSA-2002:204 + + SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script. + + + + + + + + + cpe:/a:funsoft:dinos_webserver:1.2 + + CVE-2002-1133 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:55.773-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5782 + + + XF + dinos-dotdot-directory-traversal(10168) + + + BUGTRAQ + 20020923 iDEFENSE Security Advisory 09.23.2002: Directory Traversal in Dino's Webserver + + + VULNWATCH + 20020923 iDEFENSE Security Advisory 09.23.2002: Directory Traversal in Dino's Webserver + + Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) characters. + + + + + + + + + + + + + + + + cpe:/a:hp:webes_service_tools:4.0:sp1 + cpe:/a:hp:webes_service_tools:4.0:sp2 + cpe:/a:hp:webes_service_tools:4.0:sp3 + cpe:/a:hp:webes_service_tools:4.0:sp4 + cpe:/a:hp:webes_service_tools:3.1 + cpe:/a:hp:webes_service_tools:4.0 + cpe:/a:hp:webes_service_tools:4.0:sp5 + cpe:/a:hp:webes_service_tools:2.0 + + CVE-2002-1134 + 2002-10-04T00:00:00.000-04:00 + 2008-09-05T16:29:52.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5773 + + + BUGTRAQ + 20020923 [security bulletin] SSRT2362 WEBES Service Tools (HP Tru64 UNIX, HP + + + XF + webes-unauth-file-access(10167) + + + COMPAQ + SSRT2362 + + Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files. + + + + + + + + + cpe:/a:phpwebsite:phpwebsite:0.8.2 + + CVE-2002-1135 + 2002-10-04T00:00:00.000-04:00 + 2008-09-10T15:13:55.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://phpwebsite.appstate.edu/article.php?sid=400 + + + BUGTRAQ + 20020922 PHP source injection in phpWebSite + + + BID + 5779 + + + OSVDB + 3848 + + + XF + phpwebsite-modsecurity-file-include(10164) + + modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp4 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2002-1137 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:53.050-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5877 + + + MS + MS02-056 + + + XF + mssql-dbcc-bo-variant(10255) + + + MISC + http://www.scan-associates.net/papers/foxpro.txt + + + CISCO + 20030203 Microsoft SQL Server 2000 Vulnerabilities in Cisco Products - MS02-061 + + + CIAC + N-003 + + Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp4 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2002-1138 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:56.383-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-056 + + + XF + mssql-agent-create-files(10257) + + + CIAC + N-003 + + Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs." + + + + + + + + + + + + + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/a:microsoft:windows_98_plus_pack + + CVE-2002-1139 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:56.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-054 + + + XF + win-zip-incorrect-path(10252) + + + BID + 5876 + + The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression." + + + + + + + + + cpe:/a:microsoft:services:3.0::unix + + CVE-2002-1140 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:56.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-057 + + + XF + sfu-rpc-parameter-bo(10258) + + + BID + 5879 + + The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service." + + + + + + + + + cpe:/a:microsoft:services:3.0::unix + + CVE-2002-1141 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:56.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-057 + + + XF + sfu-invalid-rpc-dos(10259) + + + BID + 5880 + + An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request." + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:data_access_components:2.5 + cpe:/a:microsoft:data_access_components:2.6 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:data_access_components:2.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1142 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:13:57.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + CERT + CA-2002-33 + + + CERT-VN + VU#542081 + + + MS + MS02-065 + + + XF + mdac-rds-server-bo(10659) + + + MISC + http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337 + + + XF + mdac-rds-client-bo(10669) + + + BID + 6214 + + + VULNWATCH + 20021120 Foundstone Advisory + + + + + + + + + + + Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:word:2002 + cpe:/a:microsoft:word:97:sr2 + cpe:/a:microsoft:word:97:sr1 + cpe:/a:microsoft:word:98::mac + cpe:/a:microsoft:word:2000:sr1 + cpe:/a:microsoft:word:2002:sp1 + cpe:/a:microsoft:word:2002:sp2 + cpe:/a:microsoft:excel:2002:sp2 + cpe:/a:microsoft:word:2000:sp2 + cpe:/a:microsoft:word:2000:sr1a + cpe:/a:microsoft:word:::mac + cpe:/a:microsoft:word:98:::japanese + cpe:/a:microsoft:word:2001::mac + cpe:/a:microsoft:word:98 + cpe:/a:microsoft:word:97 + cpe:/a:microsoft:excel:2002 + cpe:/a:microsoft:word:2000 + cpe:/a:microsoft:excel:2002:sp1 + + CVE-2002-1143 + 2003-04-11T00:00:00.000-04:00 + 2008-09-10T15:13:57.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#899713 + + + BID + 5586 + + + MS + MS02-059 + + + XF + word-includetext-read-files(10008) + + + BID + 5764 + + + CONFIRM + http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp + + + XF + word-includepicture-read-files(10155) + + + BUGTRAQ + 20020826 Security side-effects of Word fields + + + BUGTRAQ + 20020919 More vulnerabilities (Re: Security side-effects of Word fields) + + + + + Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure." + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp4 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:data_engine:2000 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:data_engine:1.0 + + CVE-2002-1145 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:13:57.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS02-061 + + + BID + 5980 + + + MISC + http://www.nextgenss.com/advisories/mssql-webtasks.txt + + + XF + mssql-webtask-gain-privileges(10388) + + + CISCO + 20030203 Microsoft SQL Server 2000 Vulnerabilities in Cisco Products - MS02-061 + + + NTBUGTRAQ + 20021017 Microsoft SQL Server Webtasks privilege upgrade (#NISR17102002) + + + BUGTRAQ + 20021017 Microsoft SQL Server Webtasks privilege upgrade (#NISR17102002) + + The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions. + + + + + + + + + cpe:/a:gnu:glibc:2.2.5 + + CVE-2002-1146 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:57.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#738331 + + + XF + dns-resolver-lib-read-bo(10295) + + + REDHAT + RHSA-2003:212 + + + REDHAT + RHSA-2003:022 + + + REDHAT + RHSA-2002:258 + + + REDHAT + RHSA-2002:197 + + + MANDRAKE + MDKSA-2004:009 + + + CONECTIVA + CLA-2002:535 + + + NETBSD + NetBSD-SA2002-015 + + The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash). + + + + + + + + + cpe:/h:hp:procurve_switch_4000m:c.09.15 + + CVE-2002-1147 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:57.383-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020924 HP Procurve 4000M Stacked Switch HTTP Reset Vulnerability + + + MISC + http://www.tech-serve.com/research/advisories/2002/a092302-1.txt + + + BID + 5784 + + + XF + hp-procurve-http-reset-dos(10172) + + + HP + HPSBUX0209-219 + + The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:tomcat:3.3.1 + cpe:/a:apache:tomcat:3.3 + cpe:/a:apache:tomcat:4.1.3:beta + cpe:/a:apache:tomcat:3.2 + cpe:/a:apache:tomcat:3.1 + cpe:/a:apache:tomcat:3.0 + cpe:/a:apache:tomcat:4.0.0 + cpe:/a:apache:tomcat:4.0.1 + cpe:/a:apache:tomcat:4.0.2 + cpe:/a:apache:tomcat:3.2.2:beta2 + cpe:/a:apache:tomcat:4.0.3 + cpe:/a:apache:tomcat:4.0.4 + cpe:/a:apache:tomcat:4.1.10 + cpe:/a:apache:tomcat:3.2.1 + cpe:/a:apache:tomcat:3.2.3 + cpe:/a:apache:tomcat:3.2.4 + cpe:/a:apache:tomcat:4.1.9:beta + cpe:/a:apache:tomcat:4.1.0 + cpe:/a:apache:tomcat:3.1.1 + + CVE-2002-1148 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:54.690-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5786 + + + XF + tomcat-servlet-source-code(10175) + + + REDHAT + RHSA-2002:218 + + + REDHAT + RHSA-2002:217 + + + DEBIAN + DSA-170 + + + HP + HPSBUX0212-229 + + + BUGTRAQ + 20020924 JSP source code exposure in Tomcat 4.x + + The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet. + + + + + + + + + + cpe:/a:invision_power_services:invision_board:1.0.1 + cpe:/a:invision_power_services:invision_board:1.0 + + CVE-2002-1149 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:57.523-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5789 + + + OSVDB + 3356 + + + XF + invision-phpinfo-information-disclosure(10178) + + + BUGTRAQ + 20020924 Information Disclosure with Invision Board installation (fwd) + + The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings. + + + + + + + + + cpe:/a:microsoft:netmeeting:3.01 + + CVE-2002-1150 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.033-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5715 + + + XF + netmeeting-rds-session-hijacking(10119) + + + BUGTRAQ + 20020913 NetMeeting 3.01 Local RDS Session Hijacking + + The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:3.0 + cpe:/a:kde:konqueror:3.0.2 + cpe:/a:kde:konqueror:3.0.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + cpe:/a:kde:konqueror:3.0.3 + cpe:/a:kde:konqueror:3.0 + cpe:/a:kde:konqueror:2.2.2 + + CVE-2002-1151 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.190-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5689 + + + DEBIAN + DSA-167 + + + BUGTRAQ + 20020910 KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability + + + CONFIRM + http://www.kde.org/info/security/advisory-20020908-2.txt + + + XF + ie-sameoriginpolicy-bypass(10039) + + + REDHAT + RHSA-2002:221 + + + REDHAT + RHSA-2002:220 + + + OSVDB + 7867 + + + MANDRAKE + MDKSA-2002:064 + + + CONECTIVA + CLA-2002:525 + + + CALDERA + CSSA-2002-047.0 + + The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains. + + + + + + + + + + + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1152 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.377-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5691 + + + BUGTRAQ + 20020910 KDE Security Advisory: Secure Cookie Vulnerability + + + CONFIRM + http://www.kde.org/info/security/advisory-20020908-1.txt + + + XF + kde-konqueror-cookie-hijacking(10083) + + + REDHAT + RHSA-2002:220 + + Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing. + + + + + + + + + cpe:/a:ibm:websphere_application_server:4.0.3 + + CVE-2002-1153 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.533-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/pq62144/readme.txt + + + XF + websphere-host-header-bo(10140) + + + BUGTRAQ + 20020919 KPMG-2002035: IBM Websphere Large Header DoS + + + BID + 5749 + + + OSVDB + 2092 + + IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host". + + + + + + + + + cpe:/a:stephen_turner:analog:5.23 + + CVE-2002-1154 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.673-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + analog-anlgform-dos(10344) + + + CONFIRM + http://www.analog.cx/security5.html + + + REDHAT + RHSA-2002:059 + + + OSVDB + 3779 + + anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log. + + + + + + + + + + + + + cpe:/a:redhat:linux:7.3 + cpe:/a:redhat:linux:7.2 + cpe:/a:redhat:linux:7.1 + cpe:/a:redhat:linux:9.0 + cpe:/a:redhat:linux:8.0 + + CVE-2002-1155 + 2003-06-16T00:00:00.000-04:00 + 2008-09-10T15:13:57.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2003:047 + + + REDHAT + RHSA-2003:050 + + + BUGTRAQ + 20030616 Next kon2root - Redhat 9 + + + MANDRAKE + MDKSA-2003:064 + + + BUGTRAQ + 20030603 kon2_exploit!! + + Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument. + + + + + + + + + cpe:/a:apache:http_server:2.0.42 + + CVE-2002-1156 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:55.987-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#910713 + + + XF + apache-webdav-cgi-source(10499) + + + CONFIRM + http://www.apacheweek.com/issues/02-10-04 + + + CONFIRM + http://www.apache.org/dist/httpd/CHANGES_2.0 + + + BID + 6065 + + + HP + HPSBUX0210-224 + + Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled. + + + + + + + + + cpe:/a:mod_ssl:mod_ssl:2.8.9 + + CVE-2002-1157 + 2002-11-04T00:00:00.000-05:00 + 2008-09-05T16:29:56.143-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-181 + + + XF + apache-modssl-host-xss(10457) + + + BID + 6029 + + + REDHAT + RHSA-2003:106 + + + REDHAT + RHSA-2002:251 + + + REDHAT + RHSA-2002:248 + + + REDHAT + RHSA-2002:244 + + + REDHAT + RHSA-2002:243 + + + REDHAT + RHSA-2002:222 + + + OSVDB + 2107 + + + ENGARDE + ESA-20021029-027 + + + MANDRAKE + MDKSA-2002:072 + + + BUGTRAQ + 20021023 [OpenPKG-SA-2002.010] OpenPKG Security Advisory (apache) + + + CONECTIVA + CLA-2002:541 + + + BUGTRAQ + 20021026 GLSA: mod_ssl + + Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840. + + + + + + + + + cpe:/a:canna:canna:3.5b2 + + CVE-2002-1158 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:29:56.300-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6351 + + + REDHAT + RHSA-2002:246 + + + XF + canna-irwthrough-bo(10831) + + + CONFIRM + http://canna.sourceforge.jp/sec/Canna-2002-01.txt + + + REDHAT + RHSA-2003:115 + + + REDHAT + RHSA-2002:261 + + + DEBIAN + DSA-224 + + + BUGTRAQ + 20021220 GLSA: canna + + Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user. + + + + + + + + + + cpe:/a:canna:canna:3.5b2 + cpe:/a:canna:canna:3.6 + + CVE-2002-1159 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:13:58.697-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:246 + + + DEBIAN + DSA-224 + + + XF + canna-improper-request-validation(10832) + + + CONFIRM + http://canna.sourceforge.jp/sec/Canna-2002-01.txt + + + BID + 6354 + + + REDHAT + RHSA-2003:115 + + + REDHAT + RHSA-2002:261 + + Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak. + + + + + + + + + + + + cpe:/o:redhat:linux:8.0 + cpe:/o:redhat:linux:7.3 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + + CVE-2002-1160 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:13:58.790-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#911505 + + + BUGTRAQ + 20021214 BDT_AV200212140001: Insecure default: Using pam_xauth for su from sh-utils package + + + XF + linux-pamxauth-gain-privileges(11254) + + + BID + 6753 + + + REDHAT + RHSA-2003:035 + + + REDHAT + RHSA-2003:028 + + + MANDRAKE + MDKSA-2003:017 + + + SUNALERT + 55760 + + + CONECTIVA + CLA-2003:693 + + The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su. + + + CVE-2002-1161 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:13:59.447-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/a:sendmail:sendmail:8.12.5 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/a:sendmail:sendmail:8.12.6 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.12.2 + cpe:/o:netbsd:netbsd:1.5 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/o:netbsd:netbsd:1.6 + cpe:/a:sendmail:sendmail:8.12.4 + cpe:/a:sendmail:sendmail:8.12.0 + + CVE-2002-1165 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:56.860-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.sendmail.org/smrsh.adv.txt + + + BID + 5845 + + + BUGTRAQ + 20021001 iDEFENSE Security Advisory 10.01.02: Sendmail smrsh bypass vulnerabilities + + + REDHAT + RHSA-2003:073 + + + XF + sendmail-forward-bypass-smrsh(10232) + + + NETBSD + NetBSD-SA2002-023 + + + MANDRIVA + MDKSA-2002:083 + + + CONECTIVA + CLA-2002:532 + + Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:john_franks:wn_server:1.18.3 + cpe:/a:john_franks:wn_server:1.18.2 + cpe:/a:john_franks:wn_server:1.18.5 + cpe:/a:john_franks:wn_server:1.18.4 + cpe:/a:john_franks:wn_server:1.19.0 + cpe:/a:john_franks:wn_server:1.18.7 + cpe:/a:john_franks:wn_server:1.18.6 + cpe:/a:john_franks:wn_server:1.19.9 + cpe:/a:john_franks:wn_server:2.0.0 + cpe:/a:john_franks:wn_server:1.19.6 + cpe:/a:john_franks:wn_server:1.19.5 + cpe:/a:john_franks:wn_server:1.19.8 + cpe:/a:john_franks:wn_server:1.19.7 + cpe:/a:john_franks:wn_server:1.19.2 + cpe:/a:john_franks:wn_server:1.19.1 + cpe:/a:john_franks:wn_server:1.19.4 + cpe:/a:john_franks:wn_server:1.19.3 + + CVE-2002-1166 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:13:59.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5831 + + + XF + wn-server-get-bo(10223) + + + BUGTRAQ + 20020930 iDEFENSE Security Advisory 09.30.2002: Buffer Overflow in WN Server + + + VULNWATCH + 20020930 iDEFENSE Security Advisory 09.30.2002: Buffer Overflow in WN Server + + + OSVDB + 9836 + + Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request. + + + + + + + + + + cpe:/a:ibm:websphere_caching_proxy_server:3.6 + cpe:/a:ibm:websphere_caching_proxy_server:4.0 + + CVE-2002-1167 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:13:59.663-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + ibm-wte-html-xss(10453) + + + BID + 6000 + + Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request. + + + + + + + + + + cpe:/a:ibm:websphere_caching_proxy_server:3.6 + cpe:/a:ibm:websphere_caching_proxy_server:4.0 + + CVE-2002-1168 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:13:59.727-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + ibm-wte-header-injection(10454) + + + BID + 6001 + + Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response. + + + + + + + + + + cpe:/a:ibm:websphere_caching_proxy_server:3.6 + cpe:/a:ibm:websphere_caching_proxy_server:4.0 + + CVE-2002-1169 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:00.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.rapid7.com/advisories/R7-0007.txt + + + XF + ibm-wte-helpout-dos(10452) + + + BID + 6002 + + + OSVDB + 2090 + + + AIXAPAR + IY35970 + + IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash. + + + + + + + + + + + cpe:/a:net-snmp:net-snmp:5.0.3 + cpe:/a:net-snmp:net-snmp:5.0.4_pre2 + cpe:/a:net-snmp:net-snmp:5.0.1 + + CVE-2002-1170 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:57.643-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5862 + + + MISC + http://www.idefense.com/advisory/10.02.02.txt + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=216532 + + + XF + netsnmp-handlevarrequests-dos(10250) + + + REDHAT + RHSA-2002:228 + + + BUGTRAQ + 20021002 iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability + + The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.9.8 + cpe:/a:fetchmail:fetchmail:5.9.4 + cpe:/a:fetchmail:fetchmail:5.9.5 + cpe:/a:fetchmail:fetchmail:5.9.0 + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.8.13 + cpe:/a:fetchmail:fetchmail:5.8.11 + cpe:/a:fetchmail:fetchmail:5.8.17 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.14 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.6 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:6.0.0 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:5.9.10 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.9.13 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.9.11 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2002-1174 + 2002-10-11T00:00:00.000-04:00 + 2011-02-15T15:41:27.567-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + MANDRAKE + MDKSA-2002:063 + + + DEBIAN + DSA-171 + + + BID + 5827 + + + BID + 5825 + + + ENGARDE + ESA-20021003-023 + + + XF + fetchmail-multidrop-bo(10203) + + + REDHAT + RHSA-2002:215 + + + BUGTRAQ + 20020929 Advisory 03/2002: Fetchmail remote vulnerabilities + + + CONECTIVA + CLA-2002:531 + + Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.9.8 + cpe:/a:fetchmail:fetchmail:5.9.4 + cpe:/a:fetchmail:fetchmail:5.9.5 + cpe:/a:fetchmail:fetchmail:5.9.0 + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.8.13 + cpe:/a:fetchmail:fetchmail:5.8.11 + cpe:/a:fetchmail:fetchmail:5.8.17 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.14 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.6 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:6.0.0 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:5.9.10 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.9.13 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.9.11 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2002-1175 + 2002-10-11T00:00:00.000-04:00 + 2011-02-15T15:42:25.083-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MANDRAKE + MDKSA-2002:063 + + + BID + 5826 + + + ENGARDE + ESA-20021003-023 + + + XF + fetchmail-multidrop-bo(10203) + + + DEBIAN + DSA-171 + + + REDHAT + RHSA-2002:215 + + + BUGTRAQ + 20020929 Advisory 03/2002: Fetchmail remote vulnerabilities + + + CONECTIVA + CLA-2002:531 + + The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary. + + + + + + + + + cpe:/a:nullsoft:winamp:2.81 + + CVE-2002-1176 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:00.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021219 Foundstone Research Labs Advisory - Multiple Exploitable Buffer Overflows in Winamp + + Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file. + + + + + + + + + cpe:/a:nullsoft:winamp:3.0 + + CVE-2002-1177 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:00.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021219 Foundstone Research Labs Advisory - Multiple Exploitable Buffer Overflows in Winamp + + + BID + 6429 + + Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag. + + + + + + + + + cpe:/a:jetty:jetty_http_server:4.1.0 + + CVE-2002-1178 + 2002-10-11T00:00:00.000-04:00 + 2008-09-05T16:29:58.533-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5852 + + + BUGTRAQ + 20021002 wp-02-0011: Jetty CGIServlet Arbitrary Command Execution + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0011.txt + + + XF + jetty-cgiservlet-directory-traversal(10246) + + + CONFIRM + http://groups.yahoo.com/group/jetty-announce/message/45 + + Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory. + + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2002-1179 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:00.773-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-058 + + + XF + outlook-smime-bo(10338) + + + NTBUGTRAQ + 20021010 Outlook Express Remote Code Execution in Preview Pane (S/MIME) + + + BID + 5944 + + + NTBUGTRAQ + 20021010 Re: Problems applying MS02-058 + + + BUGTRAQ + 20021010 Outlook Express Remote Code Execution in Preview Pane (S/MIME) + + Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2002-1180 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:00.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-062 + + + XF + iis-script-source-access-bypass(10504) + + + BID + 6071 + + + BID + 6068 + + + CIAC + N-011 + + + + + A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability." + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + cpe:/a:microsoft:internet_information_server:4.0 + + CVE-2002-1181 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:00.913-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + + MS + MS02-062 + + + XF + iis-admin-pages-xss(10501) + + + BID + 6072 + + + BID + 6068 + + + MISC + http://www.lac.co.jp/security/intelligence/SNSAdvisory/58.html + + + CIAC + N-011 + + + BUGTRAQ + 20021105 [SNS Advisory No.58] Microsoft IIS Local Cross-site Scripting Vulnerability + + + + + + + + Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + + CVE-2002-1182 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:00.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + MS + MS02-062 + + + XF + iis-webdav-memory-allocation-dos(10503) + + + XF + iis-resource-utilization-dos(10184) + + + BID + 6070 + + + BID + 6068 + + + BID + 4846 + + + MISC + http://www.nextgenss.com/vna/ms-iisdos.txt + + + MISC + http://www.nextgenss.com/advisories/ms-iisdos.txt + + + CIAC + N-011 + + + VULNWATCH + 20021031 Microsoft Internet Information Server 5/5.1 Denial of Service (#NISR31102002) + + + + + + + + IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned. + + + + + + + + + + + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-1183 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:29:59.300-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + + BID + 5410 + + + MS + MS02-050 + + + XF + ssl-ca-certificate-spoofing(9776) + + + + + + + + + + + Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2002-1184 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:01.133-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-064 + + + XF + win2k-partition-weak-permissions(9779) + + + BID + 5415 + + The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs. + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1185 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:01.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + MS + MS02-066 + + + XF + ie-png-bo(10662) + + + BID + 6216 + + + EEYE + AD20021211 + + + BUGTRAQ + 20021212 PNG (Portable Network Graphics) Deflate Heap Corruption Vulnerability + + + VULNWATCH + 20021211 PNG (Portable Network Graphics) Deflate Heap Corruption Vulnerability + + + + + + + + Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure." + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1186 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:01.273-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + + MS + MS02-066 + + + XF + ie-sameoriginpolicy-bypass(10039) + + + BUGTRAQ + 20020903 MSIEv6 % encoding causes a problem again + + + BID + 5610 + + + OSVDB + 7845 + + + BUGTRAQ + 20020904 Re: MSIEv6 % encoding causes a problem again + + + + + + + + + + + Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure." + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1187 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:01.337-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + MS + MS02-066 + + + XF + ie-frame-script-execution (10066) + + + BUGTRAQ + 20020909 Who framed Internet Explorer (GM#010-IE) + + + BID + 5672 + + + OSVDB + 2998 + + + + + + + + Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1188 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:01.413-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + + MS + MS02-066 + + + XF + ie-object-read-tif(10665) + + + BUGTRAQ + 20020912 LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE + + + BID + 6217 + + + CIAC + N-018 + + + + + + + + Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading." + + + + + + + + + + + + + + + + cpe:/h:cisco:unity_server:2.46 + cpe:/h:cisco:unity_server:3.1 + cpe:/h:cisco:unity_server:2.4 + cpe:/h:cisco:unity_server:3.0 + cpe:/h:cisco:unity_server:2.3 + cpe:/h:cisco:unity_server:2.2 + cpe:/h:cisco:unity_server:2.1 + cpe:/h:cisco:unity_server:2.0 + + CVE-2002-1189 + 2002-10-11T00:00:00.000-04:00 + 2008-09-10T15:14:01.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20021004 Predefined Restriction Tables Allow Calls to International Operator + + + XF + cisco-unity-insecure-configuration(10282) + + + BID + 5896 + + The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding. + + + + + + + + + + + + + + + + cpe:/h:cisco:unity_server:2.46 + cpe:/h:cisco:unity_server:3.1 + cpe:/h:cisco:unity_server:2.4 + cpe:/h:cisco:unity_server:3.0 + cpe:/h:cisco:unity_server:2.3 + cpe:/h:cisco:unity_server:2.2 + cpe:/h:cisco:unity_server:2.1 + cpe:/h:cisco:unity_server:2.0 + + CVE-2002-1190 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:01.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CISCO + 20021004 Predefined Restriction Tables Allow Calls to International Operator + + + XF + cisco-unity-example-default-account(44545) + + + XF + cisco-unity-insecure-configuration(10282) + + Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. + + + + + + + + + cpe:/a:sabre:desktop_reservation_software:4.4g + + CVE-2002-1191 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:01.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5974 + + + XF + sabre-sabserv-client-dos(10378) + + + MISC + http://www.idefense.com/advisory/10.16.02.txt + + + IDEFENSE + 20021016 Denial of Service in Sabre Desktop Reservation Client for Windows + + + OSVDB + 6555 + + + IDEFENSE + 20021010 Denial of Service in Sabre Desktop Reservation Client for Windows + + The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001. + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.6 + cpe:/a:rogue:rogue:5.3 + + CVE-2002-1192 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.447-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020928 local exploitable overflow in rogue/FreeBSD + + + BID + 5837 + + + XF + freebsd-rogue-bo(10261) + + + NETBSD + NetBSD-SA2002-021 + + + XF + bsd-rogue-bo(10261) + + + OSVDB + 6098 + + Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file. + + + + + + + + + + + + + cpe:/a:tkmail:tkmail:4.0_beta9 + cpe:/a:tkmail:tkmail:4.0_beta8 + cpe:/a:tkmail:tkmail:4.0_beta6 + cpe:/a:tkmail:tkmail:4.0_beta4 + cpe:/a:tkmail:tkmail:4.0_beta1 + + CVE-2002-1193 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.523-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-172 + + + XF + tkmail-tmp-file-symlink(10307) + + + BID + 5911 + + tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files. + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.6 + + CVE-2002-1194 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5910 + + + XF + netbsd-talkd-bo(10303) + + + NETBSD + NetBSD-SA2002-019 + + Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message. + + + + + + + + + cpe:/a:gabriele_bartolini:ht_check:1.1 + + CVE-2002-1195 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.663-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-169 + + + XF + htcheck-server-header-xss(10089) + + + BUGTRAQ + 20020912 ht://Check XSS + + + BID + 5699 + + Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page. + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.3 + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.14.2 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-1196 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-173 + + + XF + bugzilla-usebuggroups-permissions-leak(10233) + + + BUGTRAQ + 20021001 [BUGZILLA] Security Advisory + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=167485#c12 + + + BID + 5843 + + editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits. + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.3 + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.14.2 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-1197 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.807-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + bugzilla-emailappend-command-injection(10234) + + + BUGTRAQ + 20021001 [BUGZILLA] Security Advisory + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=163024 + + + BID + 5844 + + bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail. + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.14.3 + cpe:/a:mozilla:bugzilla:2.14.4 + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.14.2 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + + CVE-2002-1198 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + bugzilla-email-sql-injection(10235) + + + BUGTRAQ + 20021001 [BUGZILLA] Security Advisory + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=165221 + + + BID + 5842 + + Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack. + + + + + + + + + + + + + + + + + cpe:/o:caldera:openlinux:2.4 + cpe:/o:sco:openserver:5.0.5 + cpe:/o:caldera:openlinux:2.3 + cpe:/o:sun:solaris:7.0 + cpe:/o:sco:openserver:5.0.6 + cpe:/o:caldera:openlinux:2.2 + cpe:/o:sun:solaris:8.0 + cpe:/o:sco:openserver:5.0.6a + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1199 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:02.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#538033 + + + BUGTRAQ + 20021010 Multiple vendor ypxfrd map handling vulnerability + + + BID + 5937 + + + XF + ypxfrd-file-disclosure(10329) + + + SUNALERT + 47903 + + + CALDERA + CSSA-2002-SCO.40 + + + + + The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments. + + + + + + + + + + + + + + + + cpe:/a:balabit:syslog-ng:1.4.10 + cpe:/a:balabit:syslog-ng:1.5.15 + cpe:/a:balabit:syslog-ng:1.4.0_rc3 + cpe:/a:balabit:syslog-ng:1.5.20 + cpe:/a:balabit:syslog-ng:1.4.9 + cpe:/a:balabit:syslog-ng:1.4.15 + cpe:/a:balabit:syslog-ng:1.4.8 + cpe:/a:balabit:syslog-ng:1.4.7 + + CVE-2002-1200 + 2002-10-28T00:00:00.000-05:00 + 2011-02-04T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + DEBIAN + DSA-175 + + + CONFIRM + http://www.balabit.hu/static/zsa/ZSA-2002-014-en.txt + + + BID + 5934 + + + SUSE + SuSE-SA:2002:039 + + + ENGARDE + ESA-20021029-028 + + + XF + syslogng-macro-expansion-bo(10339) + + + BUGTRAQ + 20021010 syslog-ng buffer overflow + + + CONECTIVA + CLA-2002:547 + + Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + cpe:/o:ibm:aix:5 + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-1201 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#102345 + + + BID + 5925 + + + XF + aix-tcp-flood-dos(10326) + + + BUGTRAQ + 20021009 Flood ACK packets cause AIX DoS + + + AIXAPAR + IY31641 + + IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers. + + + + + + + + + + + + + cpe:/o:compaq:tru64:4.0g_pk3_bl17 + cpe:/o:compaq:tru64:5.1_pk5_bl19 + cpe:/o:compaq:tru64:5.1a_pk3_bl3 + cpe:/o:compaq:tru64:4.0f_pk7_bl18 + cpe:/o:compaq:tru64:5.0a_pk3_bl17 + + CVE-2002-1202 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.147-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + COMPAQ + SSRT2208 + + + BID + 5913 + + + XF + tru64-routed-file-access(10316) + + Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files. + + + + + + + + + + cpe:/a:ibm:secureway_firewall:4.2.1 + cpe:/a:ibm:secureway_firewall:4.2 + + CVE-2002-1203 + 2002-10-28T00:00:00.000-05:00 + 2009-08-20T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 5924 + + + XF + secureway-tcp-flood-dos(10249) + + + BUGTRAQ + 20021009 Flood ACK packets cause an IBM SecureWay FireWall DoS + + IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set. + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.78 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.77 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.75 + cpe:/a:netscape:communicator:4.76 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.72 + + CVE-2002-1204 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:03.290-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6215 + + + XF + netscape-preferences-file(10655) + + + MISC + http://www.idefense.com/advisory/11.19.02c.txt + + + VULNWATCH + 20021119 iDEFENSE Security Advisory 11.19.02c: Netscape Predictable Directory Structure Allows Theft of Preferences File + + Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name. + + + + + + + + + cpe:/a:solarwinds:tftp_server:5.0.55_standard + + CVE-2002-1209 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:03.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.idefense.com/advisory/10.24.02.txt + + + XF + tftp-dot-directory-traversal(10469) + + + BID + 6045 + + + VULNWATCH + 20021024 iDEFENSE Security Advisory 10.24.02: Directory Traversal in SolarWinds TFTP Server + + Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request. + + + + + + + + + + cpe:/a:qualcomm:eudora:5.2 + cpe:/a:qualcomm:eudora:5.1.1 + + CVE-2002-1210 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:03.063-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.idefense.com/advisory/11.19.02b.txt + + + VULNWATCH + 20021119 iDEFENSE Security Advisory 11.19.02b: Eudora Script Execution Vulnerability + + Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context. + + + + + + + + + + + cpe:/a:jason_orcutt:prometheus:3.0_beta + cpe:/a:jason_orcutt:prometheus:4.0_beta + cpe:/a:jason_orcutt:prometheus:6.0 + + CVE-2002-1211 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:03.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.idefense.com/advisory/10.31.02b.txt + + + XF + prometheus-php-file-include(10515) + + + BID + 6087 + + + BUGTRAQ + 20021101 iDEFENSE Security Advisory 10.31.02b: Prometheus Application Framework Code Injection + + + VULNWATCH + 20021101 iDEFENSE Security Advisory 10.31.02b: Prometheus Application Framework Code Injection + + Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts. + + + + + + + + + + cpe:/a:radiobird_software:webserver_4_all:1.23 + cpe:/a:radiobird_software:webserver_4_all:1.27 + + CVE-2002-1212 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5967 + + + XF + webserver-4everyone-filename-bo(10372) + + + IDEFENSE + 20021014 DoS and Directory Traversal Vulnerabilities in WebServer 4 Everyone + + Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. + + + + + + + + + + cpe:/a:radiobird_software:webserver_4_all:1.23 + cpe:/a:radiobird_software:webserver_4_all:1.27 + + CVE-2002-1213 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5968 + + + XF + webserver-4everyone-encoded-traversal(10373) + + + IDEFENSE + 20021014 DoS and Directory Traversal Vulnerabilities in WebServer 4 Everyone + + Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-1214 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020926 Microsoft PPTP Server and Client remote vulnerability + + + BID + 5807 + + + MS + MS02-063 + + + XF + win-pptp-packet-bo (10199) + + Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data. + + + + + + + + + cpe:/a:linux-ha:heartbeat:0.4.9 + + CVE-2002-1215 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:03.837-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5955 + + + DEBIAN + DSA-174 + + + SUSE + SuSE-SA:2002:037 + + + XF + linuxha-heartbeat-bo(10357) + + + CONFIRM + http://linux-ha.org/security/sec01.txt + + + CONECTIVA + CLA-2002:540 + + Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources). + + + + + + + + + + cpe:/a:gnu:tar:1.13.19 + cpe:/a:gnu:tar:1.13.25 + + CVE-2002-1216 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:04.017-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:096 + + + BUGTRAQ + 20020928 GNU tar (Re: Allot Netenforcer problems, GNU TAR flaw) + + + XF + archive-extraction-directory-traversal(10224) + + + OPENPKG + OpenPKG-SA-2006.038 + + + MANDRIVA + MDKSA-2006:219 + + GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1217 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:04.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + + MISC + http://security.greymagic.com/adv/gm011-ie/ + + + BID + 5963 + + + MS + MS02-066 + + + XF + ie-iframe-document-script-execution(10371) + + + CIAC + N-018 + + + VULNWATCH + 20021015 Internet Explorer : The D-Day + + + NTBUGTRAQ + 20021015 Internet Explorer : The D-Day + + + BUGTRAQ + 20021015 Internet Explorer : The D-Day + + + + + + + + Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.2 + cpe:/a:isc:bind:8.2.4 + cpe:/o:openbsd:openbsd:3.1 + cpe:/a:isc:bind:8.2.5 + cpe:/o:openbsd:openbsd:3.0 + cpe:/a:isc:bind:8.2.6 + cpe:/a:isc:bind:4.9.9 + cpe:/a:isc:bind:8.3.3 + cpe:/a:isc:bind:4.9.10 + cpe:/a:isc:bind:4.9.8 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/o:freebsd:freebsd:4.7 + cpe:/a:isc:bind:8.2.1 + cpe:/o:freebsd:freebsd:4.6 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.3 + cpe:/a:isc:bind:8.2.2 + + CVE-2002-1219 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:04.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + CERT-VN + VU#852283 + + + CERT + CA-2002-31 + + + CONFIRM + http://www.isc.org/products/BIND/bind-security.html + + + BUGTRAQ + 20021112 [Fwd: Notice of serious vulnerabilities in ISC BIND 4 & 8] + + + ISS + 20021112 Multiple Remote Vulnerabilities in BIND4 and BIND8 + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F48818 + + + XF + bind-sig-rr-bo(10304) + + + BID + 6160 + + + MANDRAKE + MDKSA-2002:077 + + + DEBIAN + DSA-196 + + + CIAC + N-013 + + + BUGTRAQ + 20021115 [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8) + + + COMPAQ + SSRT2408 + + + BUGTRAQ + 20021118 TSLSA-2002-0076 - bind + + + APPLE + 2002-11-21 + + + CONECTIVA + CLA-2002:546 + + + SGI + 20021201-01-P + + + + + Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR). + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.2 + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/a:isc:bind:8.3.3 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/o:freebsd:freebsd:4.7 + cpe:/o:freebsd:freebsd:4.6 + + CVE-2002-1220 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:04.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#229595 + + + CERT + CA-2002-31 + + + CONFIRM + http://www.isc.org/products/BIND/bind-security.html + + + BUGTRAQ + 20021112 [Fwd: Notice of serious vulnerabilities in ISC BIND 4 & 8] + + + ISS + 20021112 Multiple Remote Vulnerabilities in BIND4 and BIND8 + + + XF + bind-opt-rr-dos(10332) + + + BID + 6161 + + + MANDRAKE + MDKSA-2002:077 + + + DEBIAN + DSA-196 + + + CIAC + N-013 + + + BUGTRAQ + 20021115 [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8) + + + COMPAQ + SSRT2408 + + + BUGTRAQ + 20021118 TSLSA-2002-0076 - bind + + + APPLE + 2002-11-21 + + + + + BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.2 + cpe:/a:isc:bind:8.2.4 + cpe:/o:openbsd:openbsd:3.1 + cpe:/a:isc:bind:8.2.5 + cpe:/o:openbsd:openbsd:3.0 + cpe:/a:isc:bind:8.1.1 + cpe:/a:isc:bind:8.2.6 + cpe:/a:isc:bind:8.1.2 + cpe:/a:isc:bind:8.3.3 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/o:freebsd:freebsd:4.7 + cpe:/a:isc:bind:8.2.1 + cpe:/o:freebsd:freebsd:4.6 + cpe:/a:isc:bind:8.1 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.3 + cpe:/a:isc:bind:8.2.2 + + CVE-2002-1221 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:04.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#581682 + + + CERT + CA-2002-31 + + + CONFIRM + http://www.isc.org/products/BIND/bind-security.html + + + BUGTRAQ + 20021112 [Fwd: Notice of serious vulnerabilities in ISC BIND 4 & 8] + + + ISS + 20021112 Multiple Remote Vulnerabilities in BIND4 and BIND8 + + + XF + bind-null-dereference-dos(10333) + + + BID + 6159 + + + MANDRAKE + MDKSA-2002:077 + + + DEBIAN + DSA-196 + + + CIAC + N-013 + + + BUGTRAQ + 20021115 [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8) + + + COMPAQ + SSRT2408 + + + BUGTRAQ + 20021118 TSLSA-2002-0076 - bind + + + APPLE + 2002-11-21 + + + CONECTIVA + CLA-2002:546 + + + + + BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference. + + + + + + + + + + + + + + + cpe:/o:cisco:catos:7.3 + cpe:/o:cisco:catos:7.4 + cpe:/o:cisco:catos:5.5%2813a%29 + cpe:/o:cisco:catos:6.1 + cpe:/o:cisco:catos:6.1%282%29 + cpe:/o:cisco:catos:5.4 + cpe:/o:cisco:catos:5.5 + + CVE-2002-1222 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:04.743-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 5976 + + + CISCO + 20021016 Cisco CatOS Embedded HTTP Server Buffer Overflow + + + XF + cisco-catalyst-ciscoview-bo(10382) + + Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request. + + + + + + + + + + cpe:/o:kde:kde:1.1 + cpe:/o:kde:kde:3.0.3a + + CVE-2002-1223 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:05.063-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:220 + + + CONFIRM + http://www.kde.org/info/security/advisory-20021008-1.txt + + + XF + gsview-dsc-ps-bo(11319) + + + MANDRAKE + MDKSA-2002:071 + + + CIAC + N-155 + + + SUNALERT + 101426 + + + BUGTRAQ + 20021009 KDE Security Advisory: KGhostview Arbitary Code Execution + + Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file. + + + + + + + + + + + + cpe:/o:kde:kde:3.0.3a + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1224 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:05.220-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5951 + + + CONFIRM + http://www.kde.org/info/security/advisory-20021008-2.txt + + + BUGTRAQ + 20021009 KDE Security Advisory: kpf Directory traversal + + + XF + kpf-icon-view-files(10347) + + + REDHAT + RHSA-2002:220 + + + BUGTRAQ + 20021011 Security hole in kpf - KDE personal fileserver. + + Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter. + + + + + + + + + + + + + + cpe:/a:kth:heimdal:0.4b + cpe:/a:kth:heimdal:0.4a + cpe:/a:kth:heimdal:0.4d + cpe:/a:kth:heimdal:0.4c + cpe:/a:kth:heimdal:0.4e + cpe:/a:kth:heimdal:0.3e + + CVE-2002-1225 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:05.377-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5729 + + + DEBIAN + DSA-178 + + + SUSE + SuSE-SA:2002:034 + + + XF + heimdal-kf-kfd-bo(10116) + + + BUGTRAQ + 20021014 GLSA: heimdal + + Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access. + + + + + + + + + + + + + + cpe:/a:kth:heimdal:0.4b + cpe:/a:kth:heimdal:0.4a + cpe:/a:kth:heimdal:0.4d + cpe:/a:kth:heimdal:0.4c + cpe:/a:kth:heimdal:0.4e + cpe:/a:kth:heimdal:0.3e + + CVE-2002-1226 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:05.533-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-178 + + + SUSE + SuSE-SA:2002:034 + + + BUGTRAQ + 20021014 GLSA: heimdal + + Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225). + + + + + + + + + cpe:/a:pam:pam:0.76 + + CVE-2002-1227 + 2002-10-28T00:00:00.000-05:00 + 2008-09-05T16:30:05.690-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-177 + + + XF + pam-disabled-bypass-authentication(10405) + + + BID + 5994 + + PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.5 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1228 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:05.163-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#855635 + + + BID + 5986 + + + XF + solaris-nfs-lockd-dos(10394) + + + SUNALERT + 47815 + + + BUGTRAQ + 20021017 NFS Denial of Service advisory from Sun + + Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon. + + + + + + + + + + + + + cpe:/h:avaya:cajun_p550r:5.2.14 + cpe:/h:avaya:cajun_p882:5.2.14 + cpe:/h:avaya:cajun_p580:5.2.14 + cpe:/h:avaya:cajun_p880:5.2.14 + cpe:/h:avaya:cajun_p550:4.3.5 + + CVE-2002-1229 + 2002-10-28T00:00:00.000-05:00 + 2008-09-10T15:14:05.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#482241 + + + BID + 5965 + + + XF + avaya-cajun-default-passwords(10374) + + + CONFIRM + http://support.avaya.com/japple/css/japple?PAGE=avaya.css.OpenPage&temp.template.name=Avaya_P580_P882_Undocumented + + + BUGTRAQ + 20021015 Undocumented account vulnerability in Avaya P550R/P580/P880/P882 + + Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-1230 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:05.853-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + MS + MS02-071 + + + MISC + http://www.packetstormsecurity.nl/filedesc/GetAd.c.html + + + XF + win-netdde-gain-privileges(10343) + + + MISC + http://getad.chat.ru/ + + + BID + 5927 + + + CIAC + N-027 + + + + + NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation." + + + + + + + + + + + + + + cpe:/a:caldera:unixware:7.1.1 + cpe:/o:caldera:openunix:8.0 + + CVE-2002-1231 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:05.930-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + openunix-unixware-rcp-dos(10425) + + + BID + 6025 + + + CALDERA + CSSA-2002-SCO.41 + + SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:secure_os:1.0::linux + cpe:/o:debian:debian_linux:2.2::ia-32 + cpe:/o:debian:debian_linux:3.0::sparc + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:3.0::arm + cpe:/o:debian:debian_linux:3.0::alpha + cpe:/o:debian:debian_linux:3.0::ppc + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:debian:debian_linux:3.0 + cpe:/o:debian:debian_linux:3.0::s-390 + cpe:/o:debian:debian_linux:3.0::mipsel + cpe:/o:redhat:linux:7.3::i386 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:debian:debian_linux:3.0::mips + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:debian:debian_linux:3.0::hppa + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:redhat:linux:6.2 + cpe:/o:redhat:linux:7.1 + cpe:/o:redhat:linux:7.2 + cpe:/o:redhat:linux:7.0 + cpe:/o:debian:debian_linux:3.0::ia-64 + cpe:/o:redhat:linux:7.3 + cpe:/o:debian:debian_linux:2.2 + cpe:/o:debian:debian_linux:2.2::powerpc + cpe:/o:debian:debian_linux:3.0::m68k + + CVE-2002-1232 + 2002-11-04T00:00:00.000-05:00 + 2008-09-05T16:30:06.500-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6016 + + + REDHAT + RHSA-2002:223 + + + DEBIAN + DSA-180 + + + BUGTRAQ + 20021028 GLSA: ypserv + + + XF + ypserv-map-memory-leak(10423) + + + REDHAT + RHSA-2003:229 + + + REDHAT + RHSA-2002:224 + + + MANDRAKE + MDKSA-2002:078 + + + HP + HPSBTL0210-074 + + + CONECTIVA + CLA-2002:539 + + + CALDERA + CSSA-2002-054.0 + + Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:apache:http_server:1.3.27 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.20::win32 + cpe:/a:apache:http_server:1.3.26::win32 + cpe:/a:apache:http_server:1.3.24::win32 + cpe:/a:apache:http_server:1.3.25::win32 + cpe:/a:apache:http_server:1.3.17::win32 + cpe:/a:apache:http_server:1.3.22::win32 + cpe:/a:apache:http_server:1.3.18::win32 + cpe:/a:apache:http_server:1.3.23::win32 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.19::win32 + + CVE-2002-1233 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:06.070-04:00 + + + 2.6 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5990 + + + BID + 5981 + + + XF + apache-htdigest-tmpfile-race(10413) + + + XF + apache-htpasswd-tmpfile-race(10412) + + + DEBIAN + DSA-195 + + + DEBIAN + DSA-188 + + + DEBIAN + DSA-187 + + + BUGTRAQ + 20021016 Apache 1.3.26 + + A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131. + + + CVE-2002-1234 + 2002-11-04T00:00:00.000-05:00 + 2008-09-10T15:14:07.320-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0180. Reason: This candidate is a an out-of-band assignment duplicate of CVE-2002-0180. Notes: All CVE users should reference CVE-2002-0180 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + cpe:/a:kth:kth_kerberos_5:0.5.1 + cpe:/a:kth:kth_kerberos_4:1.2.1 + cpe:/a:mit:kerberos:5-1.2.6 + + CVE-2002-1235 + 2002-11-04T00:00:00.000-05:00 + 2008-09-05T16:30:07.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2002-29 + + + CERT-VN + VU#875073 + + + BID + 6024 + + + DEBIAN + DSA-184 + + + BUGTRAQ + 20021023 MITKRB5-SA-2002-002: Buffer overflow in kadmind4 + + + REDHAT + RHSA-2002:242 + + + CONFIRM + http://www.pdc.kth.se/heimdal/ + + + MANDRAKE + MDKSA-2002:073 + + + XF + kerberos-kadmind-bo(10430) + + + DEBIAN + DSA-185 + + + DEBIAN + DSA-183 + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2002-002-kadm4.txt + + + CONFIRM + http://web.mit.edu/kerberos/www/advisories/2002-002-kadm4_attacksig.txt + + + BUGTRAQ + 20021027 Re: Buffer overflow in kadmind4 + + + BUGTRAQ + 20021028 GLSA: krb5 + + + BUGTRAQ + 20021026 Updated: MITKRB5-SA-2002-002: Buffer overflow in kadmind4 + + + CONECTIVA + CLA-2002:534 + + + BUGTRAQ + 20021027 KRB5-SORCERER2002-10-27 Security Update + + + NETBSD + NetBSD-SA2002-026 + + The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack. + + + + + + + + + + + + cpe:/h:linksys:befsr41:1.41 + cpe:/h:linksys:befsr41:1.42.7 + cpe:/h:linksys:befsr41:1.40.2 + cpe:/h:linksys:befsr41:1.42.3 + + CVE-2002-1236 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.idefense.com/advisory/10.31.02a.txt + + + XF + linksys-etherfast-gozila-dos(10514) + + + BID + 6086 + + + BUGTRAQ + 20021101 iDEFENSE Security Advisory 10.31.02a: Denial of Service Vulnerability in Linksys BEFSR41 EtherFast Cable/DSL Router + + + VULNWATCH + 20021101 iDEFENSE Security Advisory 10.31.02a: Denial of Service Vulnerability in Linksys BEFSR41 EtherFast Cable/DSL Router + + The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments. + + + + + + + + + cpe:/a:peter_sandvik:simple_web_server:0.5.1 + + CVE-2002-1238 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + simple-server-file-access(10563) + + + BID + 6145 + + + MISC + http://www.idefense.com/advisory/11.08.02a.txt + + + BUGTRAQ + 20021108 iDEFENSE Security Advisory 11.08.02a: File Disclosure Vulnerability in Simple Web Server + + + VULNWATCH + 20021108 iDEFENSE Security Advisory 11.08.02a: File Disclosure Vulnerability in Simple Web Server + + Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/. + + + + + + + + + cpe:/a:qnx:rtos:6.2.0 + + CVE-2002-1239 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.idefense.com/advisory/11.08.02b.txt + + + XF + qnx-rtos-gain-privileges(10564) + + + BID + 6146 + + + BUGTRAQ + 20021108 iDEFENSE Security Advisory 11.08.02b: Non-Explicit Path Vulnerability in QNX Neutrino RTOS + + + VULNWATCH + 20021108 iDEFENSE Security Advisory 11.08.02b: Non-Explicit Path Vulnerability in QNX Neutrino RTOS + + QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:5.6 + + CVE-2002-1242 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.idefense.com/advisory/10.31.02c.txt + + + BID + 6088 + + + OSVDB + 6244 + + + XF + phpnuke-accountmanager-sql-injection(10516) + + + BUGTRAQ + 20021101 iDEFENSE Security Advisory 10.31.02c: PHP-Nuke SQL Injection Vulnerability + + + VULNWATCH + 20021101 iDEFENSE Security Advisory 10.31.02c: PHP-Nuke SQL Injection Vulnerability + + SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php. + + + + + + + + + + + + cpe:/a:pablo_software_solutions:pablo_ftp_server:1.5 + cpe:/a:pablo_software_solutions:pablo_ftp_server:1.0 + cpe:/a:pablo_software_solutions:pablo_ftp_server:1.2 + cpe:/a:pablo_software_solutions:pablo_ftp_server:1.3 + + CVE-2002-1244 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021104 iDEFENSE Security Advisory 11.04.02a: Pablo FTP Server DoS Vulnerability + + + CONFIRM + http://www.pablovandermeer.nl/ftpserver.zip + + + XF + pablo-ftp-username-dos(10532) + + + BID + 6099 + + + OSVDB + 4996 + + + VULNWATCH + 20021104 iDEFENSE Security Advisory 11.04.02a: Pablo FTP Server DoS Vulnerability + + Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command. + + + + + + + + + cpe:/a:frank_mcingvale:luxman:0.41 + + CVE-2002-1245 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.710-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.idefense.com/advisory/11.06.02.txt + + + DEBIAN + DSA-189 + + + BUGTRAQ + 20021106 iDEFENSE Security Advisory 11.06.02: Non-Explicit Path Vulnerability in LuxMan + + + BID + 6113 + + + XF + luxman-maped-read-memory(10549) + + + VULNWATCH + 20021106 iDEFENSE Security Advisory 11.06.02: Non-Explicit Path Vulnerability in LuxMan + + Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:lisa:lisa:0.1.2 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:3.0.3a + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:2.0 + cpe:/o:kde:kde:3.0.4 + cpe:/o:kde:kde:2.1 + cpe:/a:kde:klisa:2.2.2 + cpe:/o:kde:kde:3.0 + cpe:/a:lisa:lisa:0.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1247 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:09.773-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6157 + + + DEBIAN + DSA-193 + + + BUGTRAQ + 20021111 iDEFENSE Security Advisory 11.11.02: Buffer Overflow in KDE resLISa + + + REDHAT + RHSA-2002:220 + + + XF + kde-kdenetwork-reslisa-bo(10592) + + + MISC + http://www.idefense.com/advisory/11.11.02.txt + + + CIAC + N-020 + + + VULNWATCH + 20021111 iDEFENSE Security Advisory 11.11.02: Buffer Overflow in KDE resLISa + + + MANDRAKE + MDKSA-2002:080 + + + BUGTRAQ + 20021114 GLSA: kdelibs + + + BUGTRAQ + 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities + + Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon. + + + + + + + + + + cpe:/a:northern_solutions:xeneo_web_server:2.1.0.0 + cpe:/a:northern_solutions:xeneo_web_server:2.0.759.6 + + CVE-2002-1248 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://www.idefense.com/advisory/11.04.02b.txt + + + XF + xeneo-php-dos(10534) + + + BID + 6098 + + + BUGTRAQ + 20021104 iDEFENSE Security Advisory 11.04.02b: Denial of Service Vulnerability in Xeneo Web Server + + Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI. + + + + + + + + + cpe:/a:abuse:abuse:2.00 + + CVE-2002-1250 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:09.913-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.idefense.com/advisory/11.01.02.txt + + + XF + abuse-net-command-bo(10519) + + + BID + 6094 + + + VULNWATCH + 20021101 iDEFENSE Security Advisory 11.01.02: Buffer Overflow Vulnerability in Abuse + + Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument. + + + + + + + + + cpe:/a:log2mail:log2mail:0.2.5.1 + + CVE-2002-1251 + 2002-11-12T00:00:00.000-05:00 + 2008-09-05T16:30:08.533-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-186 + + + XF + log2mail-log-file-bo(10527) + + + BID + 6089 + + Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message. + + + + + + + + + + + + + cpe:/a:peoplesoft:peopletools:8.17 + cpe:/a:peoplesoft:peopletools:8.16 + cpe:/a:peoplesoft:peopletools:8.18 + cpe:/a:peoplesoft:peopletools:8.15 + cpe:/a:peoplesoft:peopletools:8.14 + + CVE-2002-1252 + 2003-02-07T00:00:00.000-05:00 + 2008-09-10T15:14:10.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + peoplesoft-xxe-read-files(10520) + + + ISS + 20030120 PeopleSoft XML External Entities Vulnerability + + + BID + 6647 + + The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler. + + + + + + + + + cpe:/a:abuse:abuse:2.00 + + CVE-2002-1253 + 2002-11-12T00:00:00.000-05:00 + 2008-09-05T16:30:08.830-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.idefense.com/advisory/11.01.02.txt + + + XF + abuse-lisp-gain-privileges(11300) + + + VULNWATCH + 20021101 iDEFENSE Security Advisory 11.01.02: Buffer Overflow Vulnerability in Abuse + + Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files. + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1254 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:10.197-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + + BID + 6028 + + + MS + MS02-066 + + + XF + ie-cache-showmodaldialog-dom-access(10432) + + + XF + ie-cache-execcommand-dom-access(10439) + + + XF + ie-cache-getelementsbytagname-dom-access(10438) + + + XF + ie-cache-getelementsbyname-dom-access(10437) + + + XF + ie-cache-getelementbyid-dom-access(10436) + + + XF + ie-cache-elementfrompoint-dom-access(10435) + + + CIAC + N-018 + + + MISC + http://security.greymagic.com/adv/gm012-ie/ + + + BUGTRAQ + 20021022 Vulnerable cached objects in IE (9 advisories in 1) + + + + + + + + Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods." + + + + + + + + + + + cpe:/a:microsoft:outlook:2002:sp2 + cpe:/a:microsoft:outlook:2002:sp1 + cpe:/a:microsoft:outlook:2002 + + CVE-2002-1255 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:14:10.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-067 + + + XF + outlook-email-header-dos(10763) + + + BID + 6319 + + Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail." + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-1256 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:10.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS02-070 + + + XF + win-smb-policy-modification(10843) + + + BID + 6367 + + + + + The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_95::sr2 + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + + CVE-2002-1257 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:10.397-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MS + MS02-069 + + + BID + 6371 + + Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_95::sr2 + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + + CVE-2002-1258 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:10.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + MS + MS02-069 + + + + + Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error. + + + CVE-2002-1259 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:12.180-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1286. Reason: This candidate is a reservation duplicate of CVE-2002-1286. Notes: All CVE users should reference CVE-2002-1286 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_95::sr2 + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + + CVE-2002-1260 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:12.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + MS + MS02-069 + + + XF + msvm-jdbc-gain-access(10833) + + + BID + 6379 + + + CIAC + N-026 + + The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet. + + + CVE-2002-1261 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:12.523-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1292. Reason: This candidate is a reservation duplicate of CVE-2002-1292. Notes: All CVE users should reference CVE-2002-1292 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1262 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:10.580-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MS + MS02-068 + + + NTBUGTRAQ + 20021205 Notes on MS02-068, extensive downplaying of severity + + + NTBUGTRAQ + 20021125 Re: MS02-066 - fixes, gaps and incorrect statements + + + BUGTRAQ + 20021205 Notes on MS02-068, extensive downplaying of severity + + + BUGTRAQ + 20021125 RE: MS02-066 - fixes, gaps and incorrect statements + + Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. + + + CVE-2002-1263 + 2003-01-07T00:00:00.000-05:00 + 2008-09-10T15:14:12.837-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1295. Reason: This candidate is a reservation duplicate of CVE-2002-1295. Notes: All CVE users should reference CVE-2002-1295 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + cpe:/a:oracle:oracle9i:9.0.1.3 + cpe:/a:oracle:oracle9i:9.0.1.2 + cpe:/a:oracle:oracle9i:9.0.1 + cpe:/a:oracle:oracle9i:9.0.2 + cpe:/a:oracle:oracle9i:9.0 + cpe:/a:oracle:oracle9i:release_2_9.2.2 + cpe:/a:oracle:oracle9i:release_2_9.2.1 + + CVE-2002-1264 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:12.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + oracle-isqlplus-userid-bo(10524) + + + CONFIRM + http://technet.oracle.com/deploy/security/pdf/2002alert46rev1.pdf + + + BUGTRAQ + 20021104 Oracle iSQL*Plus buffer overflow vulnerability (#NISR04112002) + + + BID + 6085 + + + OSVDB + 4013 + + + VULNWATCH + 20021104 Oracle iSQL*Plus buffer overflow vulnerability (#NISR04112002) + + Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/a:gnu:glibc:2.1.1.6 + cpe:/a:gnu:glibc:2.1.3.10 + cpe:/a:gnu:glibc:2.0.2 + cpe:/a:gnu:glibc:2.0.1 + cpe:/a:gnu:glibc:2.0.4 + cpe:/a:gnu:glibc:2.0.3 + cpe:/a:gnu:glibc:2.0.6 + cpe:/a:gnu:glibc:2.0.5 + cpe:/a:gnu:glibc:2.2.1 + cpe:/a:gnu:glibc:2.2.2 + cpe:/a:gnu:glibc:2.2.3 + cpe:/a:gnu:glibc:2.2.4 + cpe:/o:apple:mac_os_x:10.1 + cpe:/a:gnu:glibc:2.1.2 + cpe:/a:gnu:glibc:2.1.3 + cpe:/o:apple:mac_os_x:10.0 + cpe:/a:gnu:glibc:2.1.1 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:gnu:glibc:2.3 + cpe:/o:sgi:irix:2.3.1 + cpe:/a:gnu:glibc:2.1 + cpe:/a:gnu:glibc:2.2 + cpe:/a:gnu:glibc:2.0 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:apple:mac_os_x:10.2.1 + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:apple:mac_os_x_server:10.2.1 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/o:sgi:irix:6.5.17m + cpe:/o:apple:mac_os_x:10.0.2 + cpe:/o:sgi:irix:6.5.15f + cpe:/o:apple:mac_os_x_server:10.2 + cpe:/a:gnu:glibc:2.2.5 + cpe:/o:apple:mac_os_x_server:10.0 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16f + cpe:/o:sgi:irix:6.5.16m + + CVE-2002-1265 + 2002-11-12T00:00:00.000-05:00 + 2008-09-05T16:30:11.063-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#266817 + + + BID + 6103 + + + XF + sun-rpc-libc-dos(10539) + + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + HP + HPSBUX01020 + + + SUNALERT + 51082 + + + SGI + 20021103-01-P + + + + + The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang). + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + + CVE-2002-1266 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:11.393-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + XF + macos-disk-image-privileges(10818) + + + OSVDB + 7057 + + Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File." + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + + CVE-2002-1267 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:11.547-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + XF + macos-cups-dos(10824) + + + OSVDB + 7058 + + Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible." + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + + CVE-2002-1268 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:11.690-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + XF + macos-iso9600-gain-privileges(10828) + + + OSVDB + 7059 + + Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD." + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + + CVE-2002-1269 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:11.847-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem. + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + + CVE-2002-1270 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:12.000-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://www.info.apple.com/usen/security/security_updates.html + + + XF + macos-mach-read-files(10829) + + + OSVDB + 7060 + + Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call. + + + + + + + + + + + + + + + cpe:/a:perl-mailtools:perl-mailtools:1.13 + cpe:/a:perl-mailtools:perl-mailtools:1.47 + cpe:/a:perl-mailtools:perl-mailtools:1.44 + cpe:/a:perl-mailtools:perl-mailtools:1.15 + cpe:/a:perl-mailtools:perl-mailtools:1.40 + cpe:/a:perl-mailtools:perl-mailtools:1.42 + cpe:/a:perl-mailtools:perl-mailtools:1.1401 + + CVE-2002-1271 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:13.447-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021106 GLSA: MailTools + + + XF + mail-mailer-command-execution(10548) + + + BID + 6104 + + + SUSE + SuSE-SA:2002:041 + + + MANDRAKE + MDKSA-2002:076 + + + DEBIAN + DSA-386 + + + BUGTRAQ + 20021108 [Security Announce] Re: MDKSA-2002:076 - perl-MailTools update + + The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx. + + + + + + + + + cpe:/o:alcatel:aos:5.1.1 + + CVE-2002-1272 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:13.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#181721 + + + CERT + CA-2002-32 + + + XF + alcatel-omniswitch-backdoor(10664) + + + BID + 6220 + + Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges. + + + + + + + + + + + + + + + cpe:/a:html2ps_project:html2ps:1.0:b3 + cpe:/a:html2ps_project:html2ps:1.0:b1 + cpe:/a:html2ps_project:html2ps:1.0:b6 + cpe:/a:html2ps_project:html2ps:1.0:b7 + cpe:/a:html2ps_project:html2ps:1.0:b4 + cpe:/a:html2ps_project:html2ps:1.0:b5 + cpe:/a:html2ps_project:html2ps:1.0:b2 + + CVE-2002-1275 + 2002-11-12T00:00:00.000-05:00 + 2012-10-11T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-192 + + + BID + 6079 + + + SUSE + SuSE-SA:2002:040 + + + XF + lprng-html2ps-command-execution(10526) + + Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input." + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.8 + + CVE-2002-1276 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:12.627-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:042 + + + CONFIRM + http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=167471 + + + BID + 7019 + + + XF + squirrelmail-striptags-phpself-xss(10634) + + + DEBIAN + DSA-191 + + An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks. + + + + + + + + + + + + + + + + + + + + cpe:/a:windowmaker:windowmaker:0.62.1 + cpe:/a:windowmaker:windowmaker:0.64 + cpe:/a:windowmaker:windowmaker:0.65 + cpe:/a:windowmaker:windowmaker:0.63.1 + cpe:/a:windowmaker:windowmaker:0.62 + cpe:/a:windowmaker:windowmaker:0.53 + cpe:/a:windowmaker:windowmaker:0.63 + cpe:/a:windowmaker:windowmaker:0.61.1 + cpe:/a:windowmaker:windowmaker:0.61 + cpe:/a:windowmaker:windowmaker:0.52.2 + cpe:/a:windowmaker:windowmaker:0.80 + cpe:/a:windowmaker:windowmaker:0.20.1.3 + + CVE-2002-1277 + 2002-11-12T00:00:00.000-05:00 + 2008-09-05T16:30:12.767-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6119 + + + REDHAT + RHSA-2003:009 + + + DEBIAN + DSA-190 + + + XF + window-maker-image-bo(10560) + + + REDHAT + RHSA-2003:043 + + + MANDRAKE + MDKSA-2002:085 + + + CONECTIVA + CLA-2002:548 + + Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer. + + + + + + + + + + cpe:/a:jacques_gelinas:linuxconf:1.2.5r3 + cpe:/a:jacques_gelinas:linuxconf:1.2.4r2 + + CVE-2002-1278 + 2002-11-12T00:00:00.000-05:00 + 2008-09-10T15:14:13.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + linuxconf-sendmail-mail-relay(10554) + + + BID + 6118 + + + OSVDB + 6066 + + + CONECTIVA + CLA-2002:544 + + The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email. + + + + + + + + + cpe:/a:masqmail:masqmail:0.1.16 + + CVE-2002-1279 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:13.993-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-194 + + + BID + 6164 + + + XF + masqmail-bo(10605) + + + CONFIRM + http://lists.masqmail.cx/pipermail/masqmail/2002-November/000041.html + + + CONFIRM + http://lists.masqmail.cx/pipermail/masqmail/2002-November/000040.html + + Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option). + + + + + + + + + cpe:/a:iss:realsecure_event_collector:6.5 + + CVE-2002-1280 + 2002-05-17T00:00:00.000-04:00 + 2008-09-10T15:14:14.320-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + MISC + http://www.isskk.co.jp/support/XPressUpdates/RS/RS65ECSR15RNj.html + + Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash). + + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:2.1.1 + cpe:/o:kde:kde:3.0.4 + cpe:/o:kde:kde:2.1.2 + cpe:/o:kde:kde:2.1 + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:2.2.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1281 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:13.437-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6182 + + + REDHAT + RHSA-2002:220 + + + CONFIRM + http://www.kde.org/info/security/advisory-20021111-1.txt + + + MANDRAKE + MDKSA-2002:079 + + + XF + kde-rlogin-command-execution(10602) + + + DEBIAN + DSA-204 + + + BUGTRAQ + 20021114 GLSA: kdelibs + + + BUGTRAQ + 20021112 KDE Security Advisory: rlogin.protocol and telnet.protocol URL KIO Vulnerability + + + CALDERA + CSSA-2003-012.0 + + Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL. + + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:2.1.1 + cpe:/o:kde:kde:3.0.4 + cpe:/o:kde:kde:2.1.2 + cpe:/o:kde:kde:2.1 + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:2.2.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1282 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:13.627-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6182 + + + REDHAT + RHSA-2002:220 + + + CONFIRM + http://www.kde.org/info/security/advisory-20021111-1.txt + + + MANDRAKE + MDKSA-2002:079 + + + XF + kde-telnet-command-execution(10603) + + + DEBIAN + DSA-204 + + + BUGTRAQ + 20021114 GLSA: kdelibs + + + BUGTRAQ + 20021112 KDE Security Advisory: rlogin.protocol and telnet.protocol URL KIO Vulnerability + + + CALDERA + CSSA-2003-012.0 + + Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL. + + + + + + + + + cpe:/a:novell:emframe:1.2.1 + + CVE-2002-1283 + 2002-11-29T00:00:00.000-05:00 + 2008-10-03T00:16:05.353-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963651 + + + XF + novell-imanager-dnattribute-dos(44969) + + + BID + 6154 + + + BUGTRAQ + 20021111 NOVL-2002-2963651 - iManager (eMFrame) Buffer Overflow + + Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute. + + + + + + + + + + + + + + cpe:/a:kgpg:kgpg:0.7 + cpe:/a:kgpg:kgpg:0.6 + cpe:/a:kgpg:kgpg:0.8.2 + cpe:/a:kgpg:kgpg:0.6.1 + cpe:/a:kgpg:kgpg:0.8 + cpe:/a:kgpg:kgpg:0.8.1 + + CVE-2002-1284 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:14.757-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021110 GLSA: kgpg + + + XF + kgpg-wizard-empty-password(10629) + + + CONFIRM + http://devel-home.kde.org/~kgpg/bug.html + + + BID + 6152 + + The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read. + + + + + + + + + + + + + + cpe:/o:suse:suse_linux:8.0 + cpe:/o:suse:suse_linux:8.1 + cpe:/o:suse:suse_linux:7.0 + cpe:/o:suse:suse_linux:7.1 + cpe:/o:suse:suse_linux:7.2 + cpe:/o:suse:suse_linux:7.3 + + CVE-2002-1285 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:14.837-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6077 + + + SUSE + SuSE-SA:2002:040 + + + XF + lprng-runlpr-gain-privileges(10525) + + runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1286 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:14.237-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#657625 + + + XF + msvm-java-applet-redirect(10579) + + + BID + 6142 + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1287 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:14.393-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6134 + + + XF + msvm-class-loader-bo(10580) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1288 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:14.533-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + BID + 6139 + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1289 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:14.673-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + BID + 6140 + + + XF + msvm-inativeservices-memory-access(10582) + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1290 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:14.813-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6132 + + + XF + msvm-inativeservices-clipboard-access(10583) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1291 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:15.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6138 + + + XF + msvm-codebase-read-files(10584) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1292 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:15.097-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#237777 + + + XF + msvm-ssm-restriction-bypass(10585) + + + BID + 6133 + + + MS + MS02-069 + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1293 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:15.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6137 + + + XF + msvm-cabcracker-load-archive(10586) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1294 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:15.377-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6135 + + + XF + msvm-html-object-dos(10587) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods. + + + + + + + + + cpe:/a:microsoft:java_virtual_machine:1.1 + + CVE-2002-1295 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:15.993-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6136 + + + MS + MS02-069 + + + XF + msvm-html-applet-dos(10588) + + + BUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + + NTBUGTRAQ + 20021108 Technical information about unpatched MS Java vulnerabilities + + The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability." + + + + + + + + + + + + + + + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1296 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:16.057-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#683673 + + + CONFIRM + http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fsalert/49131 + + + XF + solaris-priocntl-pcclname-modules(10717) + + + BID + 6262 + + + BUGTRAQ + 20021127 Solaris priocntl exploit + + + + + Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module. + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:2.1.1 + cpe:/o:kde:kde:2.1.2 + cpe:/o:kde:kde:2.1 + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:2.2.1 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1306 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:16.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.kde.org/info/security/advisory-20021111-2.txt + + + BUGTRAQ + 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities + + + REDHAT + RHSA-2002:220 + + + SUSE + SuSE-SA:2002:042 + + + MANDRAKE + MDKSA-2002:080 + + + XF + kde-kdenetwork-lan-bo(10598) + + + XF + kde-kdenetwork-lisa-bo(10597) + + + DEBIAN + DSA-214 + + + CIAC + N-020 + + + BUGTRAQ + 20021114 GLSA: kdelibs + + Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL. + + + + + + + + + + + cpe:/a:mhonarc:mhonarc:2.4.4 + cpe:/a:mhonarc:mhonarc:2.5.12 + cpe:/a:mhonarc:mhonarc:2.5.2 + + CVE-2002-1307 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:16.210-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.mhonarc.org/archive/cgi-bin/mesg.cgi?a=mhonarc-users&i=200210211713.g9LHDXE02256@mcguire.earlhood.com + + + DEBIAN + DSA-199 + + + XF + mhonarc-mime-header-xss(10666) + + + BID + 6204 + + + OSVDB + 7353 + + Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name. + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:mozilla:0.9.6 + cpe:/a:netscape:navigator:6.2 + cpe:/a:mozilla:mozilla:1.0.1 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:0.9.8 + cpe:/a:netscape:navigator:7.0 + cpe:/a:mozilla:mozilla:0.9.7 + cpe:/a:netscape:navigator:6.2.3 + cpe:/a:netscape:navigator:6.2.2 + cpe:/a:netscape:navigator:6.2.1 + cpe:/a:mozilla:mozilla:1.0 + cpe:/a:mozilla:mozilla:1.1 + + CVE-2002-1308 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:16.273-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + mozilla-netscape-jar-bo(10636) + + + BUGTRAQ + 20021114 Netscape/Mozilla: Exploitable heap corruption via jar: URI handler. + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=157646 + + + BID + 6185 + + + REDHAT + RHSA-2003:163 + + + REDHAT + RHSA-2003:162 + + Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression. + + + + + + + + + cpe:/a:macromedia:coldfusion:6.0 + + CVE-2002-1309 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:16.313-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021112 EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + + EEYE + AD20021112 + + + VULNWATCH + 20021119 Update: EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + + BUGTRAQ + 20021119 Update: EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name. + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + + CVE-2002-1310 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:16.423-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021112 EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + + EEYE + AD20021112 + + + VULNWATCH + 20021119 Update: EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + + XF + jrun-long-url-bo(10568) + + + BID + 6122 + + + BUGTRAQ + 20021119 Update: EEYE: Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities + + Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name. + + + + + + + + + + cpe:/a:double_precision_incorporated:courier_mta:0.37.3 + cpe:/a:double_precision_incorporated:courier_mta:0.40 + + CVE-2002-1311 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:16.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-197 + + + XF + courier-mta-insecure-permissions(10643) + + + BID + 6189 + + + BUGTRAQ + 20021119 GLSA: courier + + Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files. + + + + + + + + + + + + + + + + + + + + + cpe:/h:linksys:befsr41:1.43 + cpe:/h:linksys:befn2ps4:1.42.7 + cpe:/h:linksys:befsru31:1.43 + cpe:/h:linksys:befsru31:1.42.7 + cpe:/h:linksys:befsr81:2.42.7.1 + cpe:/h:linksys:hpro200:1.42.7 + cpe:/h:linksys:befsr11:1.43 + cpe:/h:linksys:befsr41:1.42.7 + cpe:/h:linksys:befvp41:1.42.7 + cpe:/h:linksys:befsr11:1.42.7 + cpe:/h:linksys:befw11s4:1.4.2.7 + cpe:/h:linksys:befsx41:1.42.7 + cpe:/h:linksys:befw11s4:1.4.3 + + CVE-2002-1312 + 2002-11-20T00:00:00.000-05:00 + 2008-09-05T16:30:16.737-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BID + 6208 + + + XF + linksys-etherfast-password-dos(10654) + + + BUGTRAQ + 20021202 CORE-20021005: Vulnerability Report For Linksys Devices + + + MISC + http://www1.corest.com/common/showdoc.php?idx=276&idxseccion=10 + + + BID + 6301 + + + IDEFENSE + 20021119 Denial of Service Vulnerability in Linksys Cable/DSL Routers + + Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remote management enabled allows remote attackers to cause a denial of service (router crash) via a long password. + + + + + + + + + cpe:/a:nullmailer:nullmailer:1.0rc5 + + CVE-2002-1313 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:14:16.617-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + nullmailer-nonexistent-user-dos(10649) + + + BID + 6193 + + + DEBIAN + DSA-198 + + nullmailer 1.00RC5 and earlier allows local users to cause a denial of service via an email to a local user that does not exist, which generates an error that causes nullmailer to stop sending mail to all users. + + + + + + + + + + + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1_sp2 + cpe:/a:iplanet:iplanet_web_server:4.1_sp3 + cpe:/a:iplanet:iplanet_web_server:4.1_sp1 + cpe:/a:iplanet:iplanet_web_server:4.1_sp6 + cpe:/a:iplanet:iplanet_web_server:4.1_sp7 + cpe:/a:iplanet:iplanet_web_server:4.1_sp4 + cpe:/a:iplanet:iplanet_web_server:4.1_sp5 + cpe:/a:iplanet:iplanet_web_server:4.1 + cpe:/a:iplanet:iplanet_web_server:4.1_sp8 + cpe:/a:iplanet:iplanet_web_server:4.1_sp9 + cpe:/a:iplanet:iplanet_web_server:4.1_sp10 + cpe:/a:iplanet:iplanet_web_server:4.1_sp11 + + CVE-2002-1315 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:17.047-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6202 + + + MISC + http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt + + + XF + iplanet-admin-log-xss(10692) + + + SUNALERT + 49475 + + + BUGTRAQ + 20021119 iPlanet WebServer, remote root compromise + + + VULNWATCH + 20021118 iPlanet WebServer, remote root compromise + + Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316). + + + + + + + + + + + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:4.1_sp2 + cpe:/a:iplanet:iplanet_web_server:4.1_sp3 + cpe:/a:iplanet:iplanet_web_server:4.1_sp1 + cpe:/a:iplanet:iplanet_web_server:4.1_sp6 + cpe:/a:iplanet:iplanet_web_server:4.1_sp7 + cpe:/a:iplanet:iplanet_web_server:4.1_sp4 + cpe:/a:iplanet:iplanet_web_server:4.1_sp5 + cpe:/a:iplanet:iplanet_web_server:4.1 + cpe:/a:iplanet:iplanet_web_server:4.1_sp8 + cpe:/a:iplanet:iplanet_web_server:4.1_sp9 + cpe:/a:iplanet:iplanet_web_server:4.1_sp10 + cpe:/a:iplanet:iplanet_web_server:4.1_sp11 + + CVE-2002-1316 + 2002-11-29T00:00:00.000-05:00 + 2008-09-05T16:30:17.220-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6203 + + + MISC + http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt + + + XF + iplanet-perl-command-execution(10693) + + + SUNALERT + 49475 + + + BUGTRAQ + 20021119 iPlanet WebServer, remote root compromise + + + VULNWATCH + 20021118 iPlanet WebServer, remote root compromise + + importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315). + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sgi:irix:6.5.13 + cpe:/a:xfree86_project:x11r6:3.3.3 + cpe:/a:xfree86_project:x11r6:3.3.2 + cpe:/o:hp:hp-ux:11.22 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/a:xfree86_project:x11r6:3.3.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/a:xfree86_project:x11r6:3.3.4 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:sun:solaris:2.5.1::ppc + cpe:/o:hp:hp-ux:10.24 + cpe:/o:sun:solaris:9.0:x86_update_2 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sun:solaris:8.0 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/a:xfree86_project:x11r6:3.3 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:10.10 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:hp:hp-ux:11.04 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1317 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:17.390-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + + + CERT + CA-2002-34 + + + CERT-VN + VU#312313 + + + BID + 6241 + + + XF + solaris-fsauto-execute-code(10375) + + + ISS + 20021125 Solaris fs.auto Remote Compromise Vulnerability + + + CONFIRM + http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/48879 + + + HP + HPSBUX0212-228 + + + CIAC + N-024 + + + BUGTRAQ + 20021125 ISS Security Brief: Solaris fs.auto Remote Compromise Vulnerability + + + SGI + 20021202-01-I + + + + + + + + + + + Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.18 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/a:samba:samba:2.2.2 + cpe:/a:samba:samba:2.2.3 + cpe:/a:samba:samba:2.2.4 + cpe:/a:samba:samba:2.2.5 + cpe:/a:samba:samba:2.2.6 + cpe:/a:hp:cifs-9000_server:a.01.08 + cpe:/a:hp:cifs-9000_server:a.01.09 + cpe:/a:hp:cifs-9000_server:a.01.08.01 + + CVE-2002-1318 + 2002-12-11T00:00:00.000-05:00 + 2011-03-07T21:09:58.173-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#958321 + + + BID + 6210 + + + REDHAT + RHSA-2002:266 + + + DEBIAN + DSA-200 + + + XF + samba-password-change-bo(10683) + + + CIAC + N-023 + + + CONFIRM + http://us1.samba.org/samba/whatsnew/samba-2.2.7.html + + + SUSE + SuSE-SA:2002:045 + + + MANDRAKE + MDKSA-2002:081 + + + CIAC + N-019 + + + SUNALERT + 53580 + + + BUGTRAQ + 20021129 [OpenPKG-SA-2002.012] OpenPKG Security Advisory (samba) + + + BUGTRAQ + 20021121 GLSA: samba + + + CONECTIVA + CLA-2002:550 + + + SGI + 20021204-01-I + + + + + Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.21 + cpe:/o:linux:linux_kernel:2.2.20 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.19 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:trustix:secure_linux:1.5 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:trustix:secure_linux:1.2 + cpe:/o:trustix:secure_linux:1.1 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + + CVE-2002-1319 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:17.813-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6115 + + + REDHAT + RHSA-2002:262 + + + BUGTRAQ + 20021111 i386 Linux kernel DoS + + + XF + linux-kernel-tf-dos(10576) + + + REDHAT + RHSA-2002:263 + + + REDHAT + RHSA-2002:264 + + + BUGTRAQ + 20021114 Re: i386 Linux kernel DoS + + + CONECTIVA + CLA-2002:553 + + The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs. + + + + + + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.10 + cpe:/a:university_of_washington:pine:4.30 + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:3.98 + cpe:/a:university_of_washington:pine:4.20 + cpe:/a:university_of_washington:pine:4.33 + cpe:/a:university_of_washington:pine:4.0.4 + cpe:/a:university_of_washington:pine:4.44 + cpe:/a:university_of_washington:pine:4.0.2 + + CVE-2002-1320 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:17.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6120 + + + REDHAT + RHSA-2002:271 + + + XF + pine-from-header-dos(10555) + + + BUGTRAQ + 20021107 Remote pine Denial of Service + + + REDHAT + RHSA-2002:270 + + + SUSE + SuSE-SA:2002:046 + + + ENGARDE + ESA-20021127-032 + + + MANDRAKE + MDKSA-2002:084 + + + BUGTRAQ + 20021202 GLSA: pine + + + CONECTIVA + CLA-2002:551 + + Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks ("). + + + + + + + + + + + + + cpe:/a:realnetworks:realplayer::g2 + cpe:/a:realnetworks:realplayer:6.0::win32 + cpe:/a:realnetworks:realone_player:2.0 + cpe:/a:realnetworks:realplayer:7.0::win32 + cpe:/a:realnetworks:realplayer:8.0::win32 + + CVE-2002-1321 + 2002-12-11T00:00:00.000-05:00 + 2011-03-07T21:09:58.377-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + realplayer-rtsp-filename-bo(10677) + + + BID + 6229 + + + BID + 6227 + + + CONFIRM + http://service.real.com/help/faq/security/bufferoverrun_player.html + + + BUGTRAQ + 20021122 Mulitple Buffer Overflow conditions in RealPlayer/RealOne (#NISR22112002) + + Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain "Now Playing" options on a downloaded file with a long filename. + + + + + + + + + + cpe:/a:rational_software:clearcase:4.1 + cpe:/a:rational_software:clearcase:2002-05-00 + + CVE-2002-1322 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:17.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021122 ClearCase DoS vulnerabilty + + + XF + clearcase-tcp-scan-dos(10675) + + + BID + 6228 + + + VULNWATCH + 20021122 ClearCase DoS vulnerabilty + + Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.21m + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5 + cpe:/o:redhat:enterprise_linux:2.1::workstation + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.19 + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.18 + cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:redhat:linux_advanced_workstation:2.1 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.19f + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.19m + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/a:safe.pm:safe.pm:2.0_7 + cpe:/o:sun:solaris:9.0::x86 + cpe:/o:sgi:irix:6.5.7 + cpe:/a:safe.pm:safe.pm:2.0_6 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.21f + cpe:/o:sun:solaris:8.0 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.17m + cpe:/o:sgi:irix:6.5.22 + cpe:/o:sgi:irix:6.5.20m + cpe:/o:redhat:enterprise_linux:2.1::enterprise_server + cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64 + cpe:/o:redhat:enterprise_linux:2.1::advanced_server + cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64 + cpe:/a:sun:linux:5.0.7 + cpe:/o:sgi:irix:6.5.18f + cpe:/o:sco:unixware:7.1.2 + cpe:/o:sco:unixware:7.1.3 + cpe:/o:sgi:irix:6.5.18m + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sgi:irix:6.5.20f + cpe:/o:sun:solaris:9.0::sparc + cpe:/o:sco:open_unix:8.0 + + CVE-2002-1323 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:18.470-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 6111 + + + DEBIAN + DSA-208 + + + CONFIRM + http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 + + + XF + safe-pm-bypass-restrictions(10574) + + + BUGTRAQ + 20021219 TSLSA-2002-0087 - perl + + + CONFIRM + http://bugs6.perl.org/rt2/Ticket/Display.html?id=17744 + + + REDHAT + RHSA-2003:257 + + + REDHAT + RHSA-2003:256 + + + OSVDB + 3814 + + + OSVDB + 2183 + + + BUGTRAQ + 20021220 GLSA: perl + + + BUGTRAQ + 20021216 [OpenPKG-SA-2002.014] OpenPKG Security Advisory (perl) + + + VULNWATCH + 20021105 Perl Safe.pm compartment reuse vuln + + + SGI + 20030606-01-A + + + SCO + SCOSA-2004.1 + + + CALDERA + CSSA-2004-007.0 + + + + + Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_me + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_95::sr2 + cpe:/o:microsoft:windows_98se + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_98::gold + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + + CVE-2002-1325 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:18.720-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-069 + + + BID + 6380 + + Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability." + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_xp::gold + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::sp1:64-bit + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + + CVE-2002-1327 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:18.133-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#591890 + + + CERT + CA-2002-37 + + + MS + MS02-072 + + + BUGTRAQ + 20021219 Foundstone Research Labs Advisory - Exploitable Windows XP Media Files + + + XF + winxp-windows-shell-bo(10892) + + + BID + 6427 + + Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise." + + + + + + + + + + + + + cpe:/a:bizdesign:imagefolio:2.26 + cpe:/a:bizdesign:imagefolio:2.23 + cpe:/a:bizdesign:imagefolio:2.24 + cpe:/a:bizdesign:imagefolio:3.0.1 + cpe:/a:bizdesign:imagefolio:2.27 + + CVE-2002-1334 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:18.257-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SECTRACK + 1005681 + + + XF + imagefolio-imagefolio-nphbuild-xss(10718) + + + BID + 6265 + + + BUGTRAQ + 20021127 Cross-site Scripting Vulnerability in ImageFolio Image Gallery Software + + Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi. + + + + + + + + + cpe:/a:w3m:w3m:0.3.2 + + CVE-2002-1335 + 2002-12-11T00:00:00.000-05:00 + 2008-09-05T16:30:19.267-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6793 + + + REDHAT + RHSA-2003:044 + + + XF + w3m-html-frame-xss(10842) + + + REDHAT + RHSA-2003:045 + + + OSVDB + 6981 + + + DEBIAN + DSA-251 + + + DEBIAN + DSA-250 + + + DEBIAN + DSA-249 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=124484 + + + CONFIRM + http://mi.med.tohoku.ac.jp/%7Esatodai/w3m-dev-en/200211.month/838.html + + + OPENPKG + OpenPKG-SA-2003.009 + + Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies. + + + + + + + + + + + + + cpe:/a:tightvnc:tightvnc:1.2.0 + cpe:/a:tightvnc:tightvnc:1.2.1 + cpe:/a:tightvnc:tightvnc:1.2.4 + cpe:/a:tightvnc:tightvnc:1.2.3 + cpe:/a:tightvnc:tightvnc:1.2.5 + + CVE-2002-1336 + 2002-12-11T00:00:00.000-05:00 + 2008-09-10T15:14:18.727-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + vnc-weak-authentication(5992) + + + CONFIRM + http://www.tightvnc.com/WhatsNew.txt + + + BUGTRAQ + 20020724 VNC authentication weakness + + + BID + 5296 + + + REDHAT + RHSA-2003:041 + + + REDHAT + RHSA-2002:287 + + + MANDRAKE + MDKSA-2003:022 + + + BUGTRAQ + 20020726 RE: VNC authentication weakness + + + CONECTIVA + CLA-2003:640 + + TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:windriver:platform_sa:1.0 + cpe:/a:sendmail:sendmail:3.0.1::nt + cpe:/a:sendmail:sendmail:3.0.2::nt + cpe:/o:sun:solaris:8.0 + cpe:/a:sendmail:sendmail:2.6::nt + cpe:/a:sendmail:sendmail_switch:3.0.2 + cpe:/a:sendmail:sendmail_switch:3.0.1 + cpe:/o:sun:solaris:7.0 + cpe:/a:sgi:freeware:1.0 + cpe:/a:sendmail:advanced_message_server:1.2 + cpe:/a:sendmail:advanced_message_server:1.3 + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/a:sendmail:sendmail:3.0::nt + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.6 + cpe:/o:windriver:bsdos:4.3.1 + cpe:/o:hp:hp-ux:11.0.4 + cpe:/o:sun:solaris:9.0::sparc + cpe:/o:sun:solaris:2.6::x86 + cpe:/a:sendmail:sendmail:5.59 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:gentoo:linux:1.4:rc2 + cpe:/o:gentoo:linux:1.4:rc1 + cpe:/o:windriver:bsdos:5.0 + cpe:/a:sendmail:sendmail:8.9.0 + cpe:/a:sendmail:sendmail:8.9.1 + cpe:/a:sendmail:sendmail:8.12:beta7 + cpe:/a:sendmail:sendmail:8.9.2 + cpe:/a:sendmail:sendmail:8.8.8 + cpe:/a:sendmail:sendmail:8.9.3 + cpe:/h:hp:alphaserver_sc + cpe:/o:sun:solaris:9.0::x86 + cpe:/a:sendmail:sendmail:8.12:beta5 + cpe:/a:sendmail:sendmail:2.6.1::nt + cpe:/o:windriver:bsdos:4.2 + cpe:/a:sendmail:sendmail:8.11.6 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:hp:hp-ux:11.11 + cpe:/a:sendmail:sendmail:8.11.2 + cpe:/a:sendmail:sendmail:8.11.3 + cpe:/o:hp:hp-ux:10.10 + cpe:/a:sendmail:sendmail:8.11.4 + cpe:/a:sendmail:sendmail:8.11.5 + cpe:/a:sendmail:sendmail_switch:2.1.1 + cpe:/a:sendmail:sendmail:5.61 + cpe:/a:sendmail:sendmail:8.11.0 + cpe:/a:sendmail:sendmail:8.11.1 + cpe:/a:sendmail:sendmail:8.12:beta10 + cpe:/a:sendmail:sendmail_switch:2.2.3 + cpe:/a:sendmail:sendmail:5.65 + cpe:/a:sendmail:sendmail_switch:2.1.4 + cpe:/a:sendmail:sendmail_switch:2.2.4 + cpe:/a:sendmail:sendmail_switch:2.1.3 + cpe:/a:sendmail:sendmail_switch:2.2.1 + cpe:/a:sendmail:sendmail_switch:2.1.2 + cpe:/a:sendmail:sendmail_switch:2.2.2 + cpe:/a:sendmail:sendmail:8.12.5 + cpe:/a:sendmail:sendmail:8.12.6 + cpe:/a:sendmail:sendmail:8.12.7 + cpe:/a:sendmail:sendmail:8.10 + cpe:/a:sendmail:sendmail_switch:3.0 + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.12.2 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/a:sendmail:sendmail:8.12.4 + cpe:/a:sendmail:sendmail:8.12:beta12 + cpe:/a:sendmail:sendmail_switch:2.1 + cpe:/a:sendmail:sendmail_switch:2.2 + cpe:/o:sun:solaris:8.0::x86 + cpe:/a:sendmail:sendmail:8.12.0 + cpe:/a:sendmail:sendmail:8.12:beta16 + cpe:/a:sendmail:sendmail:8.10.2 + cpe:/a:sendmail:sendmail:8.10.1 + + CVE-2002-1337 + 2003-03-07T00:00:00.000-05:00 + 2008-09-05T16:30:19.563-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT + CA-2003-07 + + + CERT-VN + VU#398025 + + + CONFIRM + http://www.sendmail.org/8.12.8.html + + + BID + 6991 + + + ISS + 20030303 Remote Sendmail Header Processing Vulnerability + + + REDHAT + RHSA-2003:227 + + + REDHAT + RHSA-2003:074 + + + REDHAT + RHSA-2003:073 + + + XF + sendmail-header-processing-bo(10748) + + + DEBIAN + DSA-257 + + + AIXAPAR + IY40502 + + + AIXAPAR + IY40501 + + + AIXAPAR + IY40500 + + + HP + HPSBUX0302-246 + + + BUGTRAQ + 20030304 GLSA: sendmail (200303-4) + + + BUGTRAQ + 20030303 Fwd: APPLE-SA-2003-03-03 sendmail + + + BUGTRAQ + 20030304 [LSD] Technical analysis of the remote sendmail vulnerability + + + BUGTRAQ + 20030303 sendmail 8.12.8 available + + + MANDRAKE + MDKSA-2003:028 + + + CONECTIVA + CLA-2003:571 + + + SGI + 20030301-01-P + + + CALDERA + CSSA-2003-SCO.5 + + + CALDERA + CSSA-2003-SCO.6 + + + NETBSD + NetBSD-SA2003-002 + + + + + Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. + + + + + + + + + cpe:/a:microsoft:office_web_components:2002 + + CVE-2002-1338 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:19.860-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#156123 + + + MISC + http://security.greymagic.com/adv/gm008-ie/ + + + XF + owc-chart-load-exist(8784) + + + BID + 4454 + + + BUGTRAQ + 20020408 Multiple local files detection issues with OWC in IE (GM#008-IE) + + The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files. + + + + + + + + + cpe:/a:microsoft:office_web_components:2002 + + CVE-2002-1339 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:14:18.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://security.greymagic.com/adv/gm008-ie/ + + + BUGTRAQ + 20020408 Multiple local files detection issues with OWC in IE (GM#008-IE) + + The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files. + + + + + + + + + cpe:/a:microsoft:office_web_components:2002 + + CVE-2002-1340 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:14:19.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://security.greymagic.com/adv/gm008-ie/ + + + BUGTRAQ + 20020408 Multiple local files detection issues with OWC in IE (GM#008-IE) + + The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception. + + + + + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.9 + cpe:/a:squirrelmail:squirrelmail:1.2.10 + cpe:/a:squirrelmail:squirrelmail:1.2.8 + cpe:/a:squirrelmail:squirrelmail:1.2.7 + cpe:/a:squirrelmail:squirrelmail:1.2.6 + + CVE-2002-1341 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:20.297-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6302 + + + REDHAT + RHSA-2003:042 + + + DEBIAN + DSA-220 + + + BUGTRAQ + 20021203 SquirrelMail v1.2.9 XSS bugs + + + MISC + http://f0kp.iplus.ru/bz/008.txt + + + XF + squirrelmail-readbody-xss(10754) + + + BUGTRAQ + 20021215 GLSA: squirrelmail + + + BUGTRAQ + 20021203 Re: SquirrelMail v1.2.9 XSS bugs + + Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters. + + + + + + + + + + + + cpe:/a:smb2www:smb2www:1998-04-27 + cpe:/a:smb2www:smb2www:1998-08-04 + cpe:/a:smb2www:smb2www:1998-07-27 + cpe:/a:smb2www:smb2www:1998-08-02 + + CVE-2002-1342 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:14:22.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-203 + + + BID + 6313 + + + XF + smb2www-command-execution(10768) + + Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands. + + + + + + + + + + + + + + + + cpe:/a:gnu:wget:1.8.2 + cpe:/a:gnu:wget:1.8.1 + cpe:/a:gnu:wget:1.7 + cpe:/a:gnu:wget:1.7.1 + cpe:/a:gnu:wget:1.6 + cpe:/a:gnu:wget:1.8 + cpe:/h:sun:cobalt_raq_xtr + cpe:/a:gnu:wget:1.5.3 + + CVE-2002-1344 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:20.593-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#210148 + + + BID + 6352 + + + REDHAT + RHSA-2002:229 + + + MANDRAKE + MDKSA-2002:086 + + + BUGTRAQ + 20021219 TSLSA-2002-0089 - wget + + + BID + 6360 + + + CALDERA + CSSA-2003.003.0 + + + REDHAT + RHSA-2002:256 + + + OPENPKG + OpenPKG-SA-2003.007 + + + XF + wget-ftp-filename-traversal(10820) + + + CIAC + N-022 + + + DEBIAN + DSA-209 + + + BUGTRAQ + 20021211 Directory Traversal Vulnerabilities in FTP Clients + + + CONECTIVA + CLSA-2002:552 + + + CONECTIVA + CLA-2002:552 + + + VULNWATCH + 20021210 Directory Traversal Vulnerabilities in FTP Clients + + + SCO + CSSA-2003-003.0 + + Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/a:ncftp_software:ncftp:3.0.3 + cpe:/o:sun:solaris:7.0::x86 + cpe:/a:ncftp_software:ncftp:3.0.4 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/a:ncftp_software:ncftp:3.0.0 + cpe:/a:ncftp_software:ncftp:3.0.1 + cpe:/a:ncftp_software:ncftp:3.0.2 + cpe:/a:ncftp_software:ncftp:3.1.3 + cpe:/a:ncftp_software:ncftp:3.1.2 + cpe:/a:ncftp_software:ncftp:3.1.4 + cpe:/a:ncftp_software:ncftp:3.1.1 + cpe:/a:ncftp_software:ncftp:3.1.0 + + CVE-2002-1345 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:22.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#210409 + + + BUGTRAQ + 20021211 Directory Traversal Vulnerabilities in FTP Clients + + + SGI + 20021205-01-A + + + BID + 6360 + + + XF + ftp-client-filename-traversal(10821) + + + VULNWATCH + 20021210 Directory Traversal Vulnerabilities in FTP Clients + + Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences. + + + + + + + + + cpe:/a:cyrus:sasl:2.1.9 + + CVE-2002-1347 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:20.987-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021209 Cyrus SASL library buffer overflows + + + REDHAT + RHSA-2002:283 + + + APPLE + APPLE-SA-2005-03-21 + + + XF + cyrus-sasl-logwriter-bo(10812) + + + XF + cyrus-sasl-saslauthd-bo(10811) + + + XF + cyrus-sasl-username-bo(10810) + + + BID + 6349 + + + BID + 6348 + + + BID + 6347 + + + GENTOO + 200212-10 + + + DEBIAN + DSA-215 + + + CONECTIVA + 000557 + + + SUSE + SuSE-SA:2002:048 + + Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string. + + + + + + + + + + + + + + + + + + + + cpe:/a:w3m:w3m:0.2.1 + cpe:/a:w3m:w3m:0.2.2 + cpe:/a:w3m:w3m:0.2.3 + cpe:/a:w3m:w3m:0.2.4 + cpe:/a:w3m:w3m:0.2.5 + cpe:/a:w3m:w3m:0.2.5.1 + cpe:/a:w3m:w3m:0.3 + cpe:/a:w3m:w3m:0.2 + cpe:/a:w3m:w3m:0.3.2.1 + cpe:/a:w3m:w3m:0.3.1 + cpe:/a:w3m:w3m:0.3.2.2 + cpe:/a:w3m:w3m:0.3.2 + + CVE-2002-1348 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:14:22.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:044 + + + XF + w3m-img-alt-xss(11266) + + + CONFIRM + http://sourceforge.net/project/shownotes.php?release_id=126233 + + + BID + 6794 + + + REDHAT + RHSA-2003:045 + + + DEBIAN + DSA-251 + + + DEBIAN + DSA-250 + + + DEBIAN + DSA-249 + + + BUGTRAQ + 20030217 GLSA: w3m + + w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies. + + + + + + + + + + + + cpe:/a:trend_micro:pc-cillin:2000 + cpe:/a:trend_micro:pc-cillin:2002 + cpe:/a:trend_micro:officescan:corporate_5.02 + cpe:/a:trend_micro:pc-cillin:2003 + + CVE-2002-1349 + 2002-12-18T00:00:00.000-05:00 + 2008-09-10T15:14:23.397-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#157961 + + + BUGTRAQ + 20021210 Unchecked buffer in PC-cillin + + + CONFIRM + http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=12982 + + + XF + pccillin-pop3trap-bo(10814) + + + MISC + http://www.texonet.com/advisories/TEXONET-20021210.txt + + + BID + 6350 + + Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3). + + + + + + + + + cpe:/a:lbl:tcpdump:3.6.2.2.2 + + CVE-2002-1350 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:21.437-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6213 + + + DEBIAN + DSA-206 + + + XF + tcpdump-sizeof-memory-corruption(10695) + + + BUGTRAQ + 20021219 TSLSA-2002-0084 - tcpdump + + + MLIST + [tcpdump-workers] 20011015 Bug in print-bgp.c? + + + REDHAT + RHSA-2003:214 + + + REDHAT + RHSA-2003:033 + + + REDHAT + RHSA-2003:032 + + + MANDRAKE + MDKSA-2003:027 + + + CALDERA + CSSA-2002-050.0 + + The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash). + + + + + + + + + cpe:/a:melange:melange_chat_system:1.10 + + CVE-2002-1351 + 2002-12-24T00:00:00.000-05:00 + 2008-09-05T16:30:21.580-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + melange-msgtext-chatinterpretdata-bo(10939) + + + BID + 6477 + + + SECTRACK + 1005831 + + + IDEFENSE + 20021216 Melange Chat System Remote Buffer Overflow + + Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request. + + + + + + + + + cpe:/a:per_magne_knutsen:cartman:1.04 + + CVE-2002-1352 + 2003-09-17T00:00:00.000-04:00 + 2008-09-10T15:14:23.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + SECTRACK + 1005829 + + Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter. + + + + + + + + + cpe:/a:intranet-server:localweb2000:2.1.0 + + CVE-2002-1353 + 2002-08-29T00:00:00.000-04:00 + 2008-09-05T16:30:21.843-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + localweb2k-userslst-plaintext-passwords(10948) + + + SECTRACK + 1005830 + + + IDEFENSE + 20021216 LocalWEB 2000 Insecure Password Storage + + LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst. + + + + + + + + + + + cpe:/a:typsoft:typsoft_ftp_server:0.97.1 + cpe:/a:typsoft:typsoft_ftp_server:0.95 + cpe:/a:typsoft:typsoft_ftp_server:0.99.8 + + CVE-2002-1354 + 2002-12-18T00:00:00.000-05:00 + 2008-09-05T16:30:21.987-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SECTRACK + 1005832 + + + XF + typsoft-ftp-directory-traversal(6165) + + Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command. + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.7 + + CVE-2002-1355 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:22.140-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2002:290 + + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00007.html + + + CONFIRM + http://www.ethereal.com/cgi-bin/viewcvs.cgi/ethereal/packet-bgp.c.diff?r1=1.68&r2=1.69 + + Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages. + + + + + + + + + cpe:/a:ethereal_group:ethereal:0.9.7 + + CVE-2002-1356 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:22.283-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:290 + + + CONFIRM + http://www.ethereal.com/appnotes/enpa-sa-00007.html + + + CONFIRM + http://www.ethereal.com/cgi-bin/viewcvs.cgi/ethereal/packet-lmp.c#rev1.13 + + Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:putty:putty:0.48 + cpe:/a:putty:putty:0.49 + cpe:/o:cisco:ios:12.1e + cpe:/a:netcomposite:shellguard_ssh:3.4.6 + cpe:/a:putty:putty:0.53 + cpe:/o:cisco:ios:12.2 + cpe:/a:fissh:ssh_client:1.0a_for_windows + cpe:/a:intersoft:securenetterm:5.4.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2s + cpe:/a:winscp:winscp:2.0.0 + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.1ea + cpe:/o:cisco:ios:12.0st + cpe:/a:pragma_systems:secureshell:2.0 + + CVE-2002-1357 + 2002-12-23T00:00:00.000-05:00 + 2009-03-04T00:14:08.030-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT-VN + VU#389665 + + + CERT + CA-2002-36 + + + XF + ssh-transport-length-bo(10868) + + + BID + 6405 + + + SECTRACK + 1005813 + + + SECTRACK + 1005812 + + + VULNWATCH + 20021216 R7-0009: Vulnerabilities in SSH2 Implementations from Multiple Vendors + + + + + Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:putty:putty:0.48 + cpe:/a:putty:putty:0.49 + cpe:/o:cisco:ios:12.1e + cpe:/a:netcomposite:shellguard_ssh:3.4.6 + cpe:/a:putty:putty:0.53 + cpe:/o:cisco:ios:12.2 + cpe:/a:fissh:ssh_client:1.0a_for_windows + cpe:/a:intersoft:securenetterm:5.4.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2s + cpe:/a:winscp:winscp:2.0.0 + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.1ea + cpe:/o:cisco:ios:12.0st + cpe:/a:pragma_systems:secureshell:2.0 + + CVE-2002-1358 + 2002-12-23T00:00:00.000-05:00 + 2009-03-04T00:14:08.233-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT + CA-2002-36 + + + SECTRACK + 1005813 + + + SECTRACK + 1005812 + + + VULNWATCH + 20021216 R7-0009: Vulnerabilities in SSH2 Implementations from Multiple Vendors + + + + + Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:putty:putty:0.48 + cpe:/a:putty:putty:0.49 + cpe:/o:cisco:ios:12.1e + cpe:/a:netcomposite:shellguard_ssh:3.4.6 + cpe:/a:putty:putty:0.53 + cpe:/o:cisco:ios:12.2 + cpe:/a:fissh:ssh_client:1.0a_for_windows + cpe:/a:intersoft:securenetterm:5.4.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2s + cpe:/a:winscp:winscp:2.0.0 + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.1ea + cpe:/o:cisco:ios:12.0st + cpe:/a:pragma_systems:secureshell:2.0 + + CVE-2002-1359 + 2002-12-23T00:00:00.000-05:00 + 2009-03-04T00:14:08.407-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT + CA-2002-36 + + + XF + ssh-transport-multiple-bo(10870) + + + BID + 6407 + + + SECTRACK + 1005813 + + + SECTRACK + 1005812 + + + VULNWATCH + 20021216 R7-0009: Vulnerabilities in SSH2 Implementations from Multiple Vendors + + + + + Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:putty:putty:0.48 + cpe:/a:putty:putty:0.49 + cpe:/o:cisco:ios:12.1e + cpe:/a:netcomposite:shellguard_ssh:3.4.6 + cpe:/a:putty:putty:0.53 + cpe:/o:cisco:ios:12.2 + cpe:/a:fissh:ssh_client:1.0a_for_windows + cpe:/a:intersoft:securenetterm:5.4.1 + cpe:/o:cisco:ios:12.0s + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2s + cpe:/a:winscp:winscp:2.0.0 + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.1ea + cpe:/o:cisco:ios:12.0st + cpe:/a:pragma_systems:secureshell:2.0 + + CVE-2002-1360 + 2002-12-23T00:00:00.000-05:00 + 2009-03-04T00:14:08.610-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + CERT + CA-2002-36 + + + SECTRACK + 1005813 + + + SECTRACK + 1005812 + + + VULNWATCH + 20021216 R7-0009: Vulnerabilities in SSH2 Implementations from Multiple Vendors + + + + + Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite. + + + + + + + + + cpe:/h:sun:cobalt_raq_4 + + CVE-2002-1361 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:24.320-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT + CA-2002-35 + + + CERT-VN + VU#810921 + + + XF + cobalt-shp-overflow-privileges(10776) + + + SUNALERT + 49377 + + + BUGTRAQ + 20021205 Cobalt RaQ4 Remote root exploit + + + BID + 6326 + + + CIAC + N-025 + + overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter. + + + + + + + + + + + + + + cpe:/a:matthew_smith:micq:0.4.6 + cpe:/a:matthew_smith:micq:0.4.9.2b + cpe:/a:matthew_smith:micq:0.4.9 + cpe:/a:matthew_smith:micq:0.4.9.4 + cpe:/a:matthew_smith:micq:0.4.9.3 + cpe:/a:matthew_smith:micq:0.4.3 + + CVE-2002-1362 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:24.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-211 + + + XF + micq-0xfe-dos(10872) + + + BID + 6392 + + + REDHAT + RHSA-2003:118 + + mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:greg_roelofs:libpng:1.0.8 + cpe:/a:greg_roelofs:libpng:1.0.14 + cpe:/a:greg_roelofs:libpng:1.0.7 + cpe:/a:greg_roelofs:libpng:1.0.6 + cpe:/a:greg_roelofs:libpng:1.0.5 + cpe:/a:greg_roelofs:libpng:1.2.2 + cpe:/a:greg_roelofs:libpng:1.2.1 + cpe:/a:greg_roelofs:libpng:1.0.11 + cpe:/a:greg_roelofs:libpng:1.2.0 + cpe:/a:greg_roelofs:libpng:1.0.12 + cpe:/a:greg_roelofs:libpng:1.0.9 + cpe:/a:greg_roelofs:libpng:1.0.13 + cpe:/a:greg_roelofs:libpng:1.2.4 + cpe:/a:greg_roelofs:libpng:1.2.3 + + CVE-2002-1363 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:24.570-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + DEBIAN + DSA-213 + + + XF + libpng-file-offset-bo(10925) + + + FEDORA + FLSA:1943 + + + BID + 6431 + + + REDHAT + RHSA-2004:402 + + + REDHAT + RHSA-2004:249 + + + REDHAT + RHSA-2003:157 + + + REDHAT + RHSA-2003:119 + + + REDHAT + RHSA-2003:007 + + + REDHAT + RHSA-2003:006 + + + SUSE + SUSE-SA:2003:0004 + + + MANDRAKE + MDKSA-2004:063 + + + MANDRAKE + MDKSA-2003:008 + + + + + + + + Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers. + + + + + + + + + + cpe:/a:ehud_gavron:tracesroute:6.1.1 + cpe:/a:ehud_gavron:tracesroute:6.0 + + CVE-2002-1364 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:24.647-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6166 + + + BUGTRAQ + 20021129 Exploit for traceroute-nanog overflow + + + XF + traceroute-nanog-getorigin-bo(10778) + + + SUSE + SuSE-SA:2002:043 + + + DEBIAN + DSA-254 + + Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:fetchmail:fetchmail:5.9.8 + cpe:/a:fetchmail:fetchmail:5.9.4 + cpe:/a:fetchmail:fetchmail:5.9.5 + cpe:/a:fetchmail:fetchmail:5.9.0 + cpe:/a:fetchmail:fetchmail:5.3.8 + cpe:/a:fetchmail:fetchmail:5.5.5 + cpe:/a:fetchmail:fetchmail:5.5.6 + cpe:/a:fetchmail:fetchmail:5.5.0 + cpe:/a:fetchmail:fetchmail:5.5.3 + cpe:/a:fetchmail:fetchmail:5.5.2 + cpe:/a:fetchmail:fetchmail:5.8.13 + cpe:/a:fetchmail:fetchmail:5.8.11 + cpe:/a:fetchmail:fetchmail:5.8.17 + cpe:/a:fetchmail:fetchmail:5.6.0 + cpe:/a:fetchmail:fetchmail:5.8.14 + cpe:/a:fetchmail:fetchmail:5.7.0 + cpe:/a:fetchmail:fetchmail:5.8.4 + cpe:/a:fetchmail:fetchmail:5.8.3 + cpe:/a:fetchmail:fetchmail:5.8.2 + cpe:/a:fetchmail:fetchmail:5.8.1 + cpe:/a:fetchmail:fetchmail:5.7.4 + cpe:/a:fetchmail:fetchmail:5.7.2 + cpe:/a:fetchmail:fetchmail:5.8.6 + cpe:/a:fetchmail:fetchmail:5.8.5 + cpe:/a:fetchmail:fetchmail:4.7.2 + cpe:/a:fetchmail:fetchmail:4.7.1 + cpe:/a:fetchmail:fetchmail:4.7.0 + cpe:/a:fetchmail:fetchmail:4.7.6 + cpe:/a:fetchmail:fetchmail:4.7.5 + cpe:/a:fetchmail:fetchmail:4.7.4 + cpe:/a:fetchmail:fetchmail:6.1.3 + cpe:/a:fetchmail:fetchmail:4.7.3 + cpe:/a:fetchmail:fetchmail:4.7.7 + cpe:/a:fetchmail:fetchmail:6.0.0 + cpe:/a:fetchmail:fetchmail:4.5.8 + cpe:/a:fetchmail:fetchmail:4.5.7 + cpe:/a:fetchmail:fetchmail:4.5.6 + cpe:/a:fetchmail:fetchmail:4.5.5 + cpe:/a:fetchmail:fetchmail:6.1.0 + cpe:/a:fetchmail:fetchmail:5.9.10 + cpe:/a:fetchmail:fetchmail:4.5.4 + cpe:/a:fetchmail:fetchmail:4.5.3 + cpe:/a:fetchmail:fetchmail:4.6.9 + cpe:/a:fetchmail:fetchmail:5.4.5 + cpe:/a:fetchmail:fetchmail:5.3.3 + cpe:/a:fetchmail:fetchmail:4.6.8 + cpe:/a:fetchmail:fetchmail:5.4.3 + cpe:/a:fetchmail:fetchmail:5.0.5 + cpe:/a:fetchmail:fetchmail:5.9.13 + cpe:/a:fetchmail:fetchmail:5.4.4 + cpe:/a:fetchmail:fetchmail:5.1.0 + cpe:/a:fetchmail:fetchmail:5.0.6 + cpe:/a:fetchmail:fetchmail:5.0.7 + cpe:/a:fetchmail:fetchmail:5.9.11 + cpe:/a:fetchmail:fetchmail:5.0.8 + cpe:/a:fetchmail:fetchmail:4.6.3 + cpe:/a:fetchmail:fetchmail:4.6.2 + cpe:/a:fetchmail:fetchmail:4.6.1 + cpe:/a:fetchmail:fetchmail:5.2.8 + cpe:/a:fetchmail:fetchmail:4.6.0 + cpe:/a:fetchmail:fetchmail:5.2.7 + cpe:/a:fetchmail:fetchmail:4.6.7 + cpe:/a:fetchmail:fetchmail:4.6.6 + cpe:/a:fetchmail:fetchmail:4.5.1 + cpe:/a:fetchmail:fetchmail:4.6.5 + cpe:/a:fetchmail:fetchmail:5.2.4 + cpe:/a:fetchmail:fetchmail:4.5.2 + cpe:/a:fetchmail:fetchmail:4.6.4 + cpe:/a:fetchmail:fetchmail:5.2.3 + cpe:/a:fetchmail:fetchmail:5.2.1 + cpe:/a:fetchmail:fetchmail:5.2.0 + cpe:/a:fetchmail:fetchmail:5.4.0 + cpe:/a:fetchmail:fetchmail:5.1.4 + cpe:/a:fetchmail:fetchmail:5.0.2 + cpe:/a:fetchmail:fetchmail:5.0.1 + cpe:/a:fetchmail:fetchmail:5.0.4 + cpe:/a:fetchmail:fetchmail:5.0.3 + cpe:/a:fetchmail:fetchmail:5.3.0 + cpe:/a:fetchmail:fetchmail:5.3.1 + cpe:/a:fetchmail:fetchmail:5.0.0 + cpe:/a:fetchmail:fetchmail:5.8 + + CVE-2002-1365 + 2002-12-23T00:00:00.000-05:00 + 2011-02-15T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + REDHAT + RHSA-2002:293 + + + BUGTRAQ + 20021213 Advisory 05/2002: Another Fetchmail Remote Vulnerability + + + XF + fetchmail-address-header-bo(10839) + + + BID + 6390 + + + REDHAT + RHSA-2003:155 + + + REDHAT + RHSA-2002:294 + + + MANDRAKE + MDKSA-2003:011 + + + DEBIAN + DSA-216 + + + MISC + http://security.e-matters.de/advisories/052002.html + + + BUGTRAQ + 20021215 GLSA: fetchmail + + + CONECTIVA + CLA-2002:554 + + + CALDERA + CSSA-2003-001.0 + + Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1366 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:24.790-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cups-certs-race-condition(10907) + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BID + 6435 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1367 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:24.853-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cups-udp-add-printers(10908) + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BID + 6436 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + CONECTIVA + CLSA-2003:702 + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1368 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:24.930-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cups-neg-memcpy-bo(10909) + + + BID + 6437 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + DEBIAN + DSA-232 + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + MANDRAKE + MDKSA-2003:001 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + CONECTIVA + CLSA-2003:702 + + + CALDERA + CSSA-2003-004.0 + + Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1369 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:25.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + cups-strncat-options-bo(10910) + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BID + 6438 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + CONECTIVA + CLSA-2003:702 + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack. + + + CVE-2002-1370 + 2005-05-02T00:00:00.000-04:00 + 2008-09-10T15:14:25.867-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1367. Reason: This CAN was originally assigned for the theft of root certificates in CUPS, but it was later deemed to be a legitimate result of exploiting a different vulnerability, CVE-2002-1367, so it is not a distinct vulnerability. Notes: All CVE users should reference CVE-2002-1367 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1371 + 2002-12-26T00:00:00.000-05:00 + 2011-03-07T21:10:02.283-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + cups-zero-width-images(10911) + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BID + 6439 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + CONECTIVA + CLSA-2003:702 + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1372 + 2002-12-26T00:00:00.000-05:00 + 2011-03-07T21:10:02.360-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + cups-file-descriptor-dos(10912) + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BID + 6440 + + + REDHAT + RHSA-2002:295 + + + SUSE + SuSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + CONECTIVA + CLSA-2003:702 + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:4.0.5a + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:mysql:mysql:4.0.2 + cpe:/a:mysql:mysql:4.0.3 + cpe:/a:mysql:mysql:4.0.0 + cpe:/a:mysql:mysql:3.23.53a + cpe:/a:mysql:mysql:4.0.1 + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.53 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.22.30 + cpe:/a:mysql:mysql:3.23.4 + + CVE-2002-1373 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:26.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6368 + + + REDHAT + RHSA-2002:288 + + + XF + mysql-comtabledump-dos(10846) + + + MISC + http://security.e-matters.de/advisories/042002.html + + + TRUSTIX + 2002-0086 + + + IMMUNIX + IMNX-2003-7+-008-01 + + + REDHAT + RHSA-2003:166 + + + REDHAT + RHSA-2002:289 + + + SUSE + SUSE-SA:2003:003 + + + MANDRAKE + MDKSA-2002:087 + + + DEBIAN + DSA-212 + + + GENTOO + 200212-2 + + + BUGTRAQ + 20021212 Advisory 04/2002: Multiple MySQL vulnerabilities + + + CONECTIVA + CLSA-2002:555 + + Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:4.0.5a + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp1 + cpe:/a:mysql:mysql:4.0.2 + cpe:/a:mysql:mysql:4.0.3 + cpe:/a:mysql:mysql:3.23.53a + cpe:/a:mysql:mysql:4.0.0 + cpe:/a:mysql:mysql:4.0.1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp3 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.53 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + cpe:/a:mysql:mysql:3.22.30 + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:3.4 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5 + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp2 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp3 + + CVE-2002-1374 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:25.500-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6373 + + + ENGARDE + ESA-20021213-033 + + + XF + mysql-comchangeuser-password-bypass(10847) + + + MISC + http://security.e-matters.de/advisories/042002.html + + + BUGTRAQ + 20021212 Advisory 04/2002: Multiple MySQL vulnerabilities + + + TRUSTIX + 2002-0086 + + + IMMUNIX + IMNX-2003-7+-008-01 + + + REDHAT + RHSA-2003:166 + + + REDHAT + RHSA-2002:289 + + + REDHAT + RHSA-2002:288 + + + SUSE + SUSE-SA:2003:003 + + + MANDRAKE + MDKSA-2002:087 + + + DEBIAN + DSA-212 + + + BUGTRAQ + 20021216 [OpenPKG-SA-2002.013] OpenPKG Security Advisory (mysql) + + + GENTOO + GLSA-200212-2 + + + CONECTIVA + CLSA-2002:555 + + The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:4.0.5a + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp1 + cpe:/a:mysql:mysql:4.0.2 + cpe:/a:mysql:mysql:4.0.3 + cpe:/a:mysql:mysql:3.23.53a + cpe:/a:mysql:mysql:4.0.0 + cpe:/a:mysql:mysql:4.0.1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp3 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.53 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + cpe:/a:mysql:mysql:3.22.30 + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:3.4 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5 + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp2 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp3 + + CVE-2002-1375 + 2002-12-23T00:00:00.000-05:00 + 2008-09-05T16:30:25.780-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6375 + + + ENGARDE + ESA-20021213-033 + + + XF + mysql-comchangeuser-password-bo(10848) + + + MISC + http://security.e-matters.de/advisories/042002.html + + + BUGTRAQ + 20021212 Advisory 04/2002: Multiple MySQL vulnerabilities + + + TRUSTIX + 2002-0086 + + + IMMUNIX + IMNX-2003-7+-008-01 + + + REDHAT + RHSA-2003:166 + + + REDHAT + RHSA-2002:289 + + + REDHAT + RHSA-2002:288 + + + SUSE + SUSE-SA:2003:003 + + + MANDRAKE + MDKSA-2002:087 + + + DEBIAN + DSA-212 + + + BUGTRAQ + 20021216 [OpenPKG-SA-2002.013] OpenPKG Security Advisory (mysql) + + + GENTOO + GLSA-200212-2 + + + CONECTIVA + CLSA-2002:555 + + The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:4.0.5a + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_fp1 + cpe:/a:mysql:mysql:4.0.2 + cpe:/a:mysql:mysql:4.0.3 + cpe:/a:mysql:mysql:3.23.53a + cpe:/a:mysql:mysql:4.0.0 + cpe:/a:mysql:mysql:4.0.1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_mp3 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.53 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + cpe:/a:mysql:mysql:3.22.30 + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:3.4 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5 + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp1 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp3 + cpe:/a:symantec_veritas:netbackup_advanced_reporter:4.5_mp2 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp2 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp1 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5 + cpe:/a:symantec_veritas:netbackup_global_data_manager:4.5_fp3 + + CVE-2002-1376 + 2002-12-23T00:00:00.000-05:00 + 2011-03-07T21:10:02.673-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6374 + + + BID + 6370 + + + ENGARDE + ESA-20021213-033 + + + XF + mysql-libmysqlclient-readonerow-bo(10850) + + + XF + mysql-libmysqlclient-readrows-bo(10849) + + + REDHAT + RHSA-2002:288 + + + DEBIAN + DSA-212 + + + MISC + http://security.e-matters.de/advisories/042002.html + + + BUGTRAQ + 20021219 TSLSA-2002-0086 - mysql + + + BUGTRAQ + 20021216 [OpenPKG-SA-2002.013] OpenPKG Security Advisory (mysql) + + + BUGTRAQ + 20021215 GLSA: mysql + + + BUGTRAQ + 20021212 Advisory 04/2002: Multiple MySQL vulnerabilities + + + CONECTIVA + CLSA-2002:555 + + + MANDRAKE + MDKSA-2002:087 + + libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + + + + + + + + + + cpe:/a:vim_development_group:vim:5.7 + cpe:/a:vim_development_group:vim:5.8 + cpe:/a:vim_development_group:vim:5.5 + cpe:/a:vim_development_group:vim:5.6 + cpe:/a:vim_development_group:vim:5.3 + cpe:/a:vim_development_group:vim:5.4 + cpe:/a:vim_development_group:vim:5.1 + cpe:/a:vim_development_group:vim:5.2 + cpe:/a:vim_development_group:vim:5.0 + cpe:/a:vim_development_group:vim:6.1 + cpe:/a:vim_development_group:vim:6.0 + + CVE-2002-1377 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:26.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + REDHAT + RHSA-2002:297 + + + MISC + http://www.guninski.com/vim1.html + + + XF + vim-modeline-command-execution(10835) + + + BID + 6384 + + + REDHAT + RHSA-2002:302 + + + MANDRAKE + MDKSA-2003:012 + + + SUNALERT + 55700 + + + BUGTRAQ + 20040331 OpenLinux: vim arbitrary commands execution through modelines + + + FULLDISC + 20021213 Some vim problems, yet still vim much better than windows + + + CONECTIVA + CLA-2004:812 + + vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt. + + + + + + + + + cpe:/a:openldap:openldap:2.2.0 + + CVE-2002-1378 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:26.697-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + REDHAT + RHSA-2003:040 + + + DEBIAN + DSA-227 + + + SUSE + SuSE-SA:2002:047 + + + XF + openldap-multiple-bo(10800) + + + TURBO + TLSA-2003-5 + + + BID + 6328 + + + GENTOO + 200212-12 + + + MANDRAKE + MDKSA-2003:006 + + + MISC + http://www.linuxsecurity.com/advisories/gentoo_advisory-2704.html + + + CIAC + N-043 + + + CONECTIVA + CLA-2002:556 + + Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests. + + + + + + + + + cpe:/a:openldap:openldap:2.2.0 + + CVE-2002-1379 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:26.757-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-227 + + + SUSE + SuSE-SA:2002:047 + + + MANDRAKE + MDKSA-2003:006 + + OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.2.9 + cpe:/o:linux:linux_kernel:2.2.21 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.8 + cpe:/o:linux:linux_kernel:2.2.20 + cpe:/o:linux:linux_kernel:2.2.11 + cpe:/o:linux:linux_kernel:2.2.7 + cpe:/o:linux:linux_kernel:2.2.23 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.2.6 + cpe:/o:linux:linux_kernel:2.2.22 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.2 + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.4 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.2.5 + cpe:/o:linux:linux_kernel:2.2.1 + + CVE-2002-1380 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:26.820-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6420 + + + XF + linux-protread-mmap-dos(10884) + + + TRUSTIX + 2002-0083 + + + REDHAT + RHSA-2003:088 + + + MANDRAKE + MDKSA-2003:039 + + + ENGARDE + ESA-20030318-009 + + + DEBIAN + DSA-336 + + Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface. + + + + + + + + + + + cpe:/a:university_of_cambridge:exim:4.10 + cpe:/a:university_of_cambridge:exim:3.36 + cpe:/a:university_of_cambridge:exim:3.35 + + CVE-2002-1381 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:26.897-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + GENTOO + GLSA-200212-5 + + + CONFIRM + http://groups.yahoo.com/group/exim-users/message/42358 + + + BUGTRAQ + 20021204 Local root vulnerability found in exim 4.x (and 3.x) + + + XF + exim-daemonc-format-string(10761) + + + BID + 6314 + + + MLIST + [Exim] 20021204 Minor security problem in both Exim 3 and 4 + + Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value. + + + + + + + + + + + + + + + cpe:/a:macromedia:flash_player:6.0.47.0 + cpe:/a:macromedia:flash_player:6.0 + cpe:/a:macromedia:flash_player:5.0_r50 + cpe:/a:macromedia:flash_player:6.0.29.0 + cpe:/a:macromedia:flash_player:5.0 + cpe:/a:macromedia:flash_player:6.0.40.0 + cpe:/a:macromedia:flash_player:4.0_r12 + + CVE-2002-1382 + 2002-12-23T00:00:00.000-05:00 + 2008-09-10T15:14:27.070-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20021217 Macromedia Shockwave Flash Malformed Header Overflow #2 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23569 + + + XF + flash-swf-bo(10861) + + + BID + 6383 + + + VULNWATCH + 20021217 Macromedia Shockwave Flash Malformed Header Overflow #2 + + Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.2.2 + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/o:apple:mac_os_x:10.2 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1383 + 2002-12-26T00:00:00.000-05:00 + 2008-09-10T15:14:27.147-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + REDHAT + RHSA-2002:295 + + + MISC + http://www.idefense.com/advisory/12.19.02.txt + + + BUGTRAQ + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + VULNWATCH + 20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS) + + + SUSE + SuSE-SA:2003:002 + + + CALDERA + CSSA-2003-004.0 + + Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:easy_software_products:cups:1.1.10 + cpe:/a:easy_software_products:cups:1.0.4 + cpe:/a:easy_software_products:cups:1.1.1 + cpe:/a:xpdf:xpdf:2.0 + cpe:/a:xpdf:xpdf:2.1 + cpe:/a:xpdf:xpdf:0.91 + cpe:/a:easy_software_products:cups:1.1.4 + cpe:/a:xpdf:xpdf:0.90 + cpe:/a:xpdf:xpdf:1.0a + cpe:/a:easy_software_products:cups:1.1.6 + cpe:/a:easy_software_products:cups:1.1.7 + cpe:/a:easy_software_products:cups:1.1.4_2 + cpe:/a:easy_software_products:cups:1.1.4_3 + cpe:/a:xpdf:xpdf:1.1 + cpe:/a:easy_software_products:cups:1.1.4_5 + cpe:/a:easy_software_products:cups:1.1.17 + cpe:/a:xpdf:xpdf:1.0 + cpe:/a:easy_software_products:cups:1.1.14 + cpe:/a:easy_software_products:cups:1.0.4_8 + cpe:/a:easy_software_products:cups:1.1.13 + + CVE-2002-1384 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:27.210-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.idefense.com/advisory/12.23.02.txt + + + GENTOO + GLSA-200301-1 + + + XF + pdftops-integer-overflow(10937) + + + BID + 6475 + + + REDHAT + RHSA-2003:216 + + + REDHAT + RHSA-2003:037 + + + REDHAT + RHSA-2002:307 + + + REDHAT + RHSA-2002:295 + + + SUSE + SUSE-SA:2003:002 + + + MANDRAKE + MDKSA-2003:002 + + + MANDRAKE + MDKSA-2003:001 + + + DEBIAN + DSA-232 + + + DEBIAN + DSA-226 + + + DEBIAN + DSA-222 + + Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf. + + + + + + + + + + + + cpe:/a:open_webmail:open_webmail:1.71 + cpe:/a:open_webmail:open_webmail:1.81 + cpe:/a:open_webmail:open_webmail:1.7 + cpe:/a:open_webmail:open_webmail:1.8 + + CVE-2002-1385 + 2002-12-26T00:00:00.000-05:00 + 2008-09-05T16:30:27.703-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://sourceforge.net/forum/forum.php?thread_id=782605&forum_id=108435 + + + BUGTRAQ + 20021219 [Fix] Openwebmail 1.71 remote root compromise + + + XF + open-webmail-command-execution(10904) + + + BID + 6425 + + + BUGTRAQ + 20021218 Openwebmail 1.71 remote root compromise + + openwebmail_init in Open WebMail 1.81 and earlier allows local users attackers to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed. + + + + + + + + + + + cpe:/a:ehud_gavron:tracesroute:6.1.1 + cpe:/a:ehud_gavron:tracesroute:6.0 + cpe:/a:ehud_gavron:tracesroute:6.1 + + CVE-2002-1386 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:27.477-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6274 + + + XF + traceroute-nanog-bo(10608) + + + DEBIAN + DSA-254 + + + BUGTRAQ + 20021128 TracerouteNG - never ending story + + Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument. + + + + + + + + + + + cpe:/a:ehud_gavron:tracesroute:6.1.1 + cpe:/a:ehud_gavron:tracesroute:6.0 + cpe:/a:ehud_gavron:tracesroute:6.1 + + CVE-2002-1387 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:27.540-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021128 TracerouteNG - never ending story + + The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument. + + + + + + + + + + + + + + + + cpe:/a:mhonarc:mhonarc:2.4.4 + cpe:/a:mhonarc:mhonarc:2.5.13 + cpe:/a:mhonarc:mhonarc:2.5.12 + cpe:/a:mhonarc:mhonarc:2.5.11 + cpe:/a:mhonarc:mhonarc:2.5.3 + cpe:/a:mhonarc:mhonarc:2.5.1 + cpe:/a:mhonarc:mhonarc:2.5 + cpe:/a:mhonarc:mhonarc:2.5.2 + + CVE-2002-1388 + 2003-01-02T00:00:00.000-05:00 + 2008-09-05T16:30:28.173-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6479 + + + CONFIRM + http://www.mhonarc.org/archive/cgi-bin/mesg.cgi?a=mhonarc-users&i=200212220120.gBM1K8502180@mcguire.earlhood.com + + + XF + mhonarc-m2htexthtml-filter-xss(10950) + + + DEBIAN + DSA-221 + + Cross-site scripting (XSS) vulnerability in MHonArc before 2.5.14 allows remote attackers to inject arbitrary HTML into web archive pages via HTML mail messages. + + + + + + + + + + cpe:/a:typespeed:typespeed:0.4.1 + cpe:/a:typespeed:typespeed:0.4 + + CVE-2002-1389 + 2003-01-02T00:00:00.000-05:00 + 2008-09-10T15:14:27.680-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-217 + + + XF + typespeed-command-line-bo(10936) + + + BID + 6485 + + Buffer overflow in typespeed 0.4.2 and earlier allows local users to gain privileges via long input. + + + + + + + + + + + + cpe:/a:geneweb:geneweb:4.05 + cpe:/a:geneweb:geneweb:4.07 + cpe:/a:geneweb:geneweb:4.06 + cpe:/a:geneweb:geneweb:4.08 + + CVE-2002-1390 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:27.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-223 + + + CONFIRM + http://cristal.inria.fr/~ddr/GeneWeb/en/version/4.09.html + + + XF + geneweb-absolute-information-disclosure(11021) + + + BID + 6549 + + The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL. + + + + + + + + + cpe:/a:gert_doering:mgetty:1.1.29 + + CVE-2002-1391 + 2003-01-17T00:00:00.000-05:00 + 2008-09-05T16:30:28.640-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://search.alphanet.ch/cgi-bin/search.cgi?msgid=20021125142338.E12094%40greenie.muc.de&max_results=1&type=long&domain=ml-mgetty + + + XF + mgetty-cndprogram-callername-bo(11072) + + + BID + 7303 + + + REDHAT + RHSA-2003:036 + + + REDHAT + RHSA-2003:008 + + + GENTOO + GLSA-200304-09 + + + CALDERA + CSSA-2003-021.0 + + Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long CallerName argument. + + + + + + + + + cpe:/a:gert_doering:mgetty:1.1.29 + + CVE-2002-1392 + 2003-01-17T00:00:00.000-05:00 + 2008-09-05T16:30:28.797-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://search.alphanet.ch/cgi-bin/search.cgi?msgid=20021125142338.E12094%40greenie.muc.de&max_results=1&type=long&domain=ml-mgetty + + + XF + mgetty-faxspool-worldwritable-directory(11070) + + + BID + 7302 + + + REDHAT + RHSA-2003:036 + + + REDHAT + RHSA-2003:008 + + + GENTOO + GLSA-200304-09 + + + CALDERA + CSSA-2003-021.0 + + faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:kde:kde:3.0.3a + cpe:/o:kde:kde:3.0.3 + cpe:/o:kde:kde:3.0.4 + cpe:/o:kde:kde:3.0.5 + cpe:/o:kde:kde:2.2.1 + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:2.0.1 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:2.0 + cpe:/o:kde:kde:2.1.1 + cpe:/o:kde:kde:2.1 + cpe:/o:kde:kde:2.1.2 + cpe:/o:kde:kde:3.0.2 + cpe:/o:kde:kde:3.0.1 + + CVE-2002-1393 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:29.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.kde.org/info/security/advisory-20021220-1.txt + + + DEBIAN + DSA-243 + + + BUGTRAQ + 20021222 GLSA: kde-3.0.x + + + DEBIAN + DSA-242 + + + DEBIAN + DSA-241 + + + DEBIAN + DSA-240 + + + DEBIAN + DSA-239 + + + DEBIAN + DSA-238 + + + DEBIAN + DSA-237 + + + DEBIAN + DSA-236 + + + DEBIAN + DSA-235 + + + DEBIAN + DSA-234 + + + BID + 6462 + + + REDHAT + RHSA-2003:003 + + + REDHAT + RHSA-2003:002 + + + MANDRAKE + MDKSA-2003:004 + + + BUGTRAQ + 20021221 KDE Security Advisory: Multiple vulnerabilities in KDE + + + CONECTIVA + CLA-2003:569 + + Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses. + + + + + + + + + + + + + + + + + + cpe:/a:apache:tomcat:4.1.10 + cpe:/a:apache:tomcat:4.1.3:beta + cpe:/a:apache:tomcat:4.1.9:beta + cpe:/a:apache:tomcat:4.0.0 + cpe:/a:apache:tomcat:4.0.1 + cpe:/a:apache:tomcat:4.0.2 + cpe:/a:apache:tomcat:4.1.0 + cpe:/a:apache:tomcat:4.0.3 + cpe:/a:apache:tomcat:4.0.4 + cpe:/a:apache:tomcat:4.0.5 + + CVE-2002-1394 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:29.617-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + GENTOO + GLSA-200210-001 + + + XF + tomcat-invoker-source-code(10376) + + + BID + 6562 + + + REDHAT + RHSA-2003:082 + + + REDHAT + RHSA-2003:075 + + + DEBIAN + DSA-225 + + + CONFIRM + http://marc.theaimsgroup.com/?l=tomcat-dev&m=103417249325526&w=2 + + + CONFIRM + http://issues.apache.org/bugzilla/show_bug.cgi?id=13365 + + Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148. + + + + + + + + + + cpe:/a:debian:internet_message:133-0 + cpe:/a:debian:internet_message:141-0 + + CVE-2002-1395 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:29.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-202 + + + BID + 6307 + + + REDHAT + RHSA-2003:039 + + + XF + im-immknmz-symlink(10767) + + + XF + im-impwagent-insecure-directory(10766) + + Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz. + + + + + + + + + + + + + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.2.3 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + + CVE-2002-1396 + 2003-01-17T00:00:00.000-05:00 + 2008-09-05T16:30:29.453-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6488 + + + CONFIRM + http://bugs.php.net/bug.php?id=20927 + + + XF + php-wordwrap-bo(10944) + + + BUGTRAQ + 20021227 Buffer overflow in PHP "wordwrap" function + + + GENTOO + 200301-8 + + + REDHAT + RHSA-2003:017 + + + SUSE + SuSE-SA:2003:0009 + + + MANDRAKE + MDKSA-2003:019 + + + ENGARDE + ESA-20030219-003 + + Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code. + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1397 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:30.820-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020819 @(#) Mordred Labs advisory 0x0001: Buffer overflow in PostgreSQL + + + XF + postgresql-cashwords-bo(9891) + + + BID + 5497 + + + REDHAT + RHSA-2003:001 + + + CONECTIVA + CLA-2002:524 + + + MISC + http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/cash.c.diff?r1=1.51&r2=1.52 + + Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. + + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1398 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:30.977-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + SUSE + SuSE-SA:2002:038 + + + DEBIAN + DSA-165 + + + BUGTRAQ + 20020819 Re: @(#) Mordred Labs advisory 0x0001: Buffer overflow in PostgreSQL + + + CONFIRM + http://archives.postgresql.org/pgsql-announce/2002-08/msg00004.php + + + REDHAT + RHSA-2003:001 + + + CONFIRM + http://marc.theaimsgroup.com/?l=postgresql-announce&m=103062536330644 + + + BUGTRAQ + 20020826 GLSA: PostgreSQL + + + BUGTRAQ + 20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release + + + BUGTRAQ + 20020821 Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in PostgreSQL + + Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input." + + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1399 + 2003-01-17T00:00:00.000-05:00 + 2008-09-05T16:30:29.970-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MISC + http://archives.postgresql.org/pgsql-hackers/2002-08/msg00713.php + + + MISC + http://archives.postgresql.org/pgsql-hackers/2002-08/msg00708.php + + + BUGTRAQ + 20020819 Re: @(#) Mordred Labs advisory 0x0001: Buffer overflow in PostgreSQL + + Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2). + + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1400 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:31.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + SUSE + SuSE-SA:2002:038 + + + BUGTRAQ + 20020820 @(#)Mordred Labs advisory 0x0003: Buffer overflow in PostgreSQL + + + CONFIRM + http://archives.postgresql.org/pgsql-announce/2002-08/msg00004.php + + + REDHAT + RHSA-2003:001 + + + MANDRAKE + MDKSA-2002:062 + + + CONFIRM + http://marc.theaimsgroup.com/?l=postgresql-announce&m=103062536330644 + + + BUGTRAQ + 20020826 GLSA: PostgreSQL + + + BUGTRAQ + 20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release + + + CONECTIVA + CLA-2002:524 + + Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. + + + + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.2.3 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.2.2 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.2 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1401 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T00:00:00.000-04:00 + + + 6.5 + NETWORK + LOW + SINGLE_INSTANCE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + DEBIAN + DSA-165 + + + REDHAT + RHSA-2003:001 + + + CONECTIVA + CLA-2002:524 + + + MISC + http://archives.postgresql.org/pgsql-hackers/2002-08/msg02081.php + + + MISC + http://archives.postgresql.org/pgsql-hackers/2002-08/msg02047.php + + Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. + + + + + + + + + + + + + + + + cpe:/a:postgresql:postgresql:6.5.3 + cpe:/a:postgresql:postgresql:6.3.2 + cpe:/a:postgresql:postgresql:7.0.3 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.1.1 + cpe:/a:postgresql:postgresql:7.1.2 + cpe:/a:postgresql:postgresql:7.1.3 + cpe:/a:postgresql:postgresql:7.1 + + CVE-2002-1402 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:31.257-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + DEBIAN + DSA-165 + + + MLIST + [pgsql-announce] 20020824 PostgreSQL 7.2.2: Security Release + + + REDHAT + RHSA-2003:001 + + + MANDRAKE + MDKSA-2002:062 + + + BUGTRAQ + 20020826 GLSA: PostgreSQL + + + BUGTRAQ + 20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release + + + CONECTIVA + CLA-2002:524 + + Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + cpe:/a:phystech:dhcpcd:1.3.17_pl2 + cpe:/a:phystech:dhcpcd:1.3.22_pl1 + + CVE-2002-1403 + 2003-01-17T00:00:00.000-05:00 + 2008-09-10T15:14:31.337-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + DEBIAN + DSA-219 + + + GENTOO + GLSA-200301-3 + + + XF + dhcpcd-info-execute-commands(10663) + + + BID + 6200 + + + MANDRAKE + MDKSA-2003:003 + + + CONECTIVA + CLA-2002:549 + + dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that are fed from a dhcpd .info script into a .exe script. + + + CVE-2002-1404 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:14:31.883-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1348. Reason: This candidate is a reservation duplicate of CVE-2002-1348. Notes: All CVE users should reference CVE-2002-1348 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + cpe:/a:university_of_kansas:lynx:2.8.3_rel1 + cpe:/a:university_of_kansas:lynx:2.8.3 + cpe:/a:university_of_kansas:lynx:2.8.4 + cpe:/a:university_of_kansas:lynx:2.8.2_rel1 + cpe:/a:elinks:elinks:0.2.4 + cpe:/a:links:links:0.96 + cpe:/a:university_of_kansas:lynx:2.8.4_rel1 + cpe:/a:elinks:elinks:0.3.2 + cpe:/a:university_of_kansas:lynx:2.8.5_dev8 + + CVE-2002-1405 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:14:31.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + lynx-crlf-injection(9887) + + + DEBIAN + DSA-210 + + + BUGTRAQ + 20020822 Lynx CRLF Injection, part two + + + BUGTRAQ + 20020819 Lynx CRLF Injection + + + TRUSTIX + 2002-0085 + + + BID + 5499 + + + REDHAT + RHSA-2003:030 + + + REDHAT + RHSA-2003:029 + + + MANDRAKE + MDKSA-2003:023 + + + CALDERA + CSSA-2002-049.0 + + CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters. + + + + + + + + + cpe:/o:hp:hp-ux:11.04 + + CVE-2002-1406 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:31.127-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5454 + + + XF + hp-vvos-passwd(9847) + + + HP + HPSBUX0208-210 + + Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior." + + + + + + + + + cpe:/a:adam_megacz:tinyssl:1.0.2 + + CVE-2002-1407 + 2003-04-11T00:00:00.000-04:00 + 2011-03-07T21:10:05.767-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5410 + + + BUGTRAQ + 20020805 IE SSL Vulnerability + + + BUGTRAQ + 20020810 TinySSL Vendor Statement: Basic Constraints Vulnerability + + + XF + ssl-ca-certificate-spoofing(9776) + + TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. + + + + + + + + + + + + + + cpe:/a:hp:openview_emanate_snmp_agent:14.2 + cpe:/o:hp:vvos:11.04 + + CVE-2002-1408 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:31.437-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5428 + + + XF + hp-emanate-default-snmp(9814) + + + HP + HPSBUX0208-208 + + Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name. + + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:11.04 + + CVE-2002-1409 + 2003-04-11T00:00:00.000-04:00 + 2009-03-04T00:14:15.563-05:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + BID + 5425 + + + XF + hp-ptrace-dos(9818) + + + HP + HPSBUX0208-206 + + + + + ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state." + + + + + + + + + + cpe:/a:ben_chivers:ben_chivers_guestbook:1.0 + cpe:/a:easy_scripts_archive:easy_guestbook:1.0 + + CVE-2002-1410 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:31.750-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5341 + + + BUGTRAQ + 20020727 Easy Guestbook Vulnerabilities + + + XF + easy-guestbook-gain-access(9697) + + Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. + + + + + + + + + cpe:/a:duma:photo_gallery_system:0.99.4 + + CVE-2002-1411 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:31.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5081 + + + XF + dpgs-dotdot-directory-traversal(9414) + + + BUGTRAQ + 20020622 DPGS allows any file to be overwritten + + Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter. + + + + + + + + + cpe:/a:gallery_project:gallery:1.3.1 + + CVE-2002-1412 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.063-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + DEBIAN + DSA-138 + + + BUGTRAQ + 20020801 code injection in gallery + + + CONFIRM + http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=50&mode=thread&order=0&thold=0 + + + XF + gallery-basedir-execute-commands(9737) + + + BID + 5375 + + Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script. + + + + + + + + + cpe:/o:novell:netware:6.0:sp2 + + CVE-2002-1413 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.220-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#746251 + + + BID + 5541 + + + XF + netware-rconj-no-password(9928) + + + BUGTRAQ + 20020821 NOVL-2002-2963349 - Rconag6 Secure IP Login Vulnerability - NW6SP2 + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963349 + + RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection. + + + + + + + + + + + + + + cpe:/a:inter7:qmailadmin:1.0.5 + cpe:/a:inter7:qmailadmin:1.0.4 + cpe:/a:inter7:qmailadmin:1.0.3 + cpe:/a:inter7:qmailadmin:1.0.2 + cpe:/a:inter7:qmailadmin:1.0.1 + cpe:/a:inter7:qmailadmin:1.0 + + CVE-2002-1414 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.377-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5404 + + + CONFIRM + http://www.inter7.com/qmailadmin/ChangeLog + + + VULN-DEV + 20020806 qmailadmin SUID buffer overflow + + + BUGTRAQ + 20020724 Re: qmailadmin SUID buffer overflow + + + XF + qmailadmin-templatedir-bo(9786) + + Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable. + + + + + + + + + cpe:/a:webeasymail:webeasymail:3.4.2.2 + + CVE-2002-1415 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5518 + + + XF + webeasymail-smtp-service-dos(9924) + + + BUGTRAQ + 20020820 Advisory: DoS in WebEasyMail +more possible? + + Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests. + + + + + + + + + cpe:/a:webeasymail:webeasymail:3.4.2.2 + + CVE-2002-1416 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5519 + + + XF + webeasymail-pop3-bruteforce(9925) + + + BUGTRAQ + 20020820 Advisory: DoS in WebEasyMail +more possible? + + The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks. + + + + + + + + + + + + + + + + cpe:/a:novell:small_business_suite:5.1 + cpe:/a:novell:small_business_suite:6.0 + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1417 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:32.890-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5523 + + + XF + novell-netbasic-directory-traversal(9910) + + + BUGTRAQ + 20020820 NOVL-2002-2963297 - NetBasic Buffer Overflow + Scripting Vulnerability + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963297 + + Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator. + + + + + + + + + + + + + + + + cpe:/a:novell:small_business_suite:5.1 + cpe:/a:novell:small_business_suite:6.0 + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1418 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.047-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5524 + + + XF + novell-netbasic-interpreter-bo(9911) + + + BUGTRAQ + 20020820 NOVL-2002-2963297 - NetBasic Buffer Overflow + Scripting Vulnerability + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963297 + + Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name. + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + + CVE-2002-1419 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.203-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + irix-origin-bypass-filtering(9868) + + + SGI + 20020805-01-I + + + BID + 5467 + + The upgrade of IRIX on Origin 3000 to 6.5.13 through 6.5.16 changes the MAC address of the system, which could modify intended access restrictions that are based on a MAC address. + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + + CVE-2002-1420 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.360-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#259787 + + + BID + 5442 + + + XF + openbsd-select-bo(9809) + + + BUGTRAQ + 20020812 OpenBSD Security Advisory: Select Boundary Condition (fwd) + + + OSVDB + 7554 + + Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation. + + + + + + + + + + + cpe:/a:ilia_alshanetsky:fudforum:1.2.8 + cpe:/a:ilia_alshanetsky:fudforum:2.0.2 + cpe:/a:ilia_alshanetsky:fudforum:1.9.8 + + CVE-2002-1421 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.517-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5500 + + + XF + fudforum-sql-injection(9912) + + + BUGTRAQ + 20020818 FUDforum file access and SQL Injection + + + VULNWATCH + 20020818 FUDforum file access and SQL Injection + + SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php. + + + + + + + + + + + cpe:/a:ilia_alshanetsky:fudforum:1.2.8 + cpe:/a:ilia_alshanetsky:fudforum:2.0.2 + cpe:/a:ilia_alshanetsky:fudforum:1.9.8 + + CVE-2002-1422 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.673-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5502 + + + XF + fudforum-admnbrowse-modify-files(9901) + + + BUGTRAQ + 20020818 FUDforum file access and SQL Injection + + + VULNWATCH + 20020818 FUDforum file access and SQL Injection + + admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. + + + + + + + + + + + cpe:/a:ilia_alshanetsky:fudforum:1.2.8 + cpe:/a:ilia_alshanetsky:fudforum:2.0.2 + cpe:/a:ilia_alshanetsky:fudforum:1.9.8 + + CVE-2002-1423 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5501 + + + XF + fudforum-tmpview-download-files(9896) + + + BUGTRAQ + 20020818 FUDforum file access and SQL Injection + + + VULNWATCH + 20020818 FUDforum file access and SQL Injection + + tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter. + + + + + + + + + cpe:/a:john_g._myers:mpack:1.5 + + CVE-2002-1424 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:33.983-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5385 + + + XF + munpack-mime-bo(9747) + + + DEBIAN + DSA-141 + + Buffer overflow in munpack in mpack 1.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + cpe:/a:john_g._myers:mpack:1.5 + + CVE-2002-1425 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.140-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5386 + + + XF + munpack-dotdot-directory-traversal(9748) + + + DEBIAN + DSA-141 + + Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted. + + + + + + + + + cpe:/h:hp:procurve_switch_4000m:c.07.23 + + CVE-2002-1426 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.297-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5336 + + + MISC + http://www.phenoelit.de/stuff/HP_ProCurve.txt + + + XF + hp-procurve-snmp-write-dos(9708) + + + BUGTRAQ + 20020727 Phenoelit Advisory 0815 ++ /+ HP ProCurve + + HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow. + + + + + + + + + + cpe:/a:easy_scripts_archive:easy_homepage_creator:1.0 + cpe:/a:easy_scripts_archive:advanced_easy_homepage_creator:1.0 + + CVE-2002-1427 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.437-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020727 Easy Homepage Creator Vulnerability + + + BID + 5340 + + + XF + easy-homepage-gain-access(9696) + + The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users. + + + + + + + + + cpe:/a:dotproject:dotproject:0.2.1.5 + + CVE-2002-1428 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.593-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5347 + + + XF + dotproject-admin-access(9720) + + + BUGTRAQ + 20020728 php dotProject by pass authentication + + index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1. + + + + + + + + + cpe:/a:endity.com:shoutbox:1.2 + + CVE-2002-1429 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5354 + + + BUGTRAQ + 20020729 Code injection Vulnerability in endity.com + + + XF + shoutbox-site-html-injection(9739) + + + MISC + http://endity.com/board/index.php?act=ST&f=3&t=68&s=363128162825b2d7fcf60c9cd2a292fe + + Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter. + + + + + + + + + cpe:/a:synthetic_reality:sympoll:1.2 + + CVE-2002-1430 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:34.890-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5360 + + + XF + sympoll-php-view-files(9723) + + + CONFIRM + http://www.ralusp.net/downloads/sympoll/changelog.txt + + + BUGTRAQ + 20020730 [ADVISORY]: Arbitrary file disclosure vulnerability in Sympoll 1.2 + + Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters. + + + + + + + + + cpe:/h:belkin:f5d5230-4_4-port_cable_dsl_gateway_router:1.20.000 + + CVE-2002-1431 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.030-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4982 + + + XF + belkin-incorrect-ip(9324) + + + BUGTRAQ + 20020609 Problem with IP reporting - Belkin Cable/DSL router + + Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server. + + + + + + + + + + + + + + + cpe:/a:coxco_support:a-cart:2.0 + cpe:/a:coxco_support:salescart-std + cpe:/a:coxco_support:midicart_asp_maxi + cpe:/a:coxco_support:metacart:2.sql + cpe:/a:coxco_support:midicart_asp + cpe:/a:coxco_support:salescart-pro + cpe:/a:coxco_support:midicart_asp_plus + + CVE-2002-1432 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + XF + shopping-cart-database-access(9816) + + + BUGTRAQ + 20020807 MidiCart Shopping Cart Software database vulnerability + + + BID + 5438 + + MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database. + + + + + + + + + cpe:/a:kerio:kerio_mailserver:5.0 + + CVE-2002-1433 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.360-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + kerio-mailserver-syn-dos(9904) + + + BUGTRAQ + 20020819 Kerio Mail Server Multiple Security Vulnerabilities + + + BID + 5505 + + Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services. + + + + + + + + + + + cpe:/a:kerio:kerio_mailserver:5.1 + cpe:/a:kerio:kerio_mailserver:5.0 + cpe:/a:kerio:kerio_mailserver:5.1.1 + + CVE-2002-1434 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.500-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + kerio-webserver-webmail-xss(9905) + + + BUGTRAQ + 20020819 Kerio Mail Server Multiple Security Vulnerabilities + + + BID + 5507 + + Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs. + + + + + + + + + + + + + + + + + + cpe:/a:achievo:achievo:0.8.1 + cpe:/a:achievo:achievo:0.8.0 + cpe:/a:achievo:achievo:0.8.0_rc2 + cpe:/a:achievo:achievo:0.9.0 + cpe:/a:achievo:achievo:0.7.3 + cpe:/a:achievo:achievo:0.7.2 + cpe:/a:achievo:achievo:0.9.1 + cpe:/a:achievo:achievo:0.7.1 + cpe:/a:achievo:achievo:0.8.0_rc1 + cpe:/a:achievo:achievo:0.7.0 + + CVE-2002-1435 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.657-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5552 + + + XF + achievo-php-execute-code(9947) + + + BUGTRAQ + 20020822 Arbitrary code execution problem in Achievo + + + CONFIRM + http://www.achievo.org/lists/2002/Aug/msg00092.html + + class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config_atkroot parameter that points to the code. + + + + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + cpe:/o:novell:netware:5.1:sp4 + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1436 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.827-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5520 + + + XF + netware-perl-code-execution(9916) + + + BUGTRAQ + 20020820 NOVL-2002-2963307 - PERL Handler Vulnerability + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963307 + + The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request. + + + + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + cpe:/o:novell:netware:5.1:sp4 + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1437 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:35.983-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5522 + + + XF + netware-perl-directory-traversal(9915) + + + BUGTRAQ + 20020820 NOVL-2002-2963307 - PERL Handler Vulnerability + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963307 + + Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences. + + + + + + + + + + + + cpe:/o:novell:netware:6.0:sp1 + cpe:/o:novell:netware:5.1:sp4 + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1438 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.140-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5521 + + + XF + netware-perl-information-disclosure(9917) + + + BUGTRAQ + 20020820 NOVL-2002-2963307 - PERL Handler Vulnerability + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2963307 + + The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option. + + + + + + + + + + + + + + + + cpe:/o:hp:vvos:11.04 + cpe:/a:hp:virtualvault:4.6 + cpe:/a:hp:virtualvault:4.0 + cpe:/a:hp:virtualvault:4.5 + + CVE-2002-1439 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.297-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5459 + + + XF + hp-vvos-tga-corruption(9846) + + + HP + HPSBUX0208-211 + + Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files. + + + + + + + + + cpe:/h:gateway:gs-400 + + CVE-2002-1440 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.467-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5472 + + + XF + gateway-gs400-default-password(9864) + + + BUGTRAQ + 20020814 Trivial root compromise in Gateway GS-400 NAS Servers + + The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges. + + + + + + + + + cpe:/a:tomahawk_technologies:steelarrow:4.1 + + CVE-2002-1441 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.610-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.steelarrow.com/ + + + BID + 5496 + + + BID + 5495 + + + BID + 5494 + + + BID + 4860 + + + MISC + http://www.nextgenss.com/vna/tom-saro.txt + + + MISC + http://www.nextgenss.com/advisories/steel-arrow-bo.txt + + + XF + steelarrow-chunked-aro-bo(9890) + + + XF + steelarrow-long-aro-bo(9889) + + + XF + steelarrow-userident-bo(9888) + + + BUGTRAQ + 20020819 Multiple Buffer Overflow vulnerabilities in SteelArrow (#NISR19082002B) + + + VULNWATCH + 20020819 Multiple Buffer Overflow vulnerabilities in SteelArrow (#NISR19082002B) + + Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:google:toolbar:1.1.41 + cpe:/a:google:toolbar:1.1.44 + cpe:/a:google:toolbar:1.1.53 + cpe:/a:google:toolbar:1.1.45 + cpe:/a:google:toolbar:1.1.54 + cpe:/a:google:toolbar:1.1.42 + cpe:/a:google:toolbar:1.1.55 + cpe:/a:google:toolbar:1.1.43 + cpe:/a:google:toolbar:1.1.56 + cpe:/a:google:toolbar:1.1.58 + cpe:/a:google:toolbar:1.1.49 + cpe:/a:google:toolbar:1.1.57 + cpe:/a:google:toolbar:1.1.48 + cpe:/a:google:toolbar:1.1.47 + + CVE-2002-1442 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.767-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5424 + + + BUGTRAQ + 20020808 Exploiting the Google toolbar (GM#001-MC) + + + MISC + http://sec.greymagic.com/adv/gm001-mc/ + + + NTBUGTRAQ + 20020808 Exploiting the Google toolbar (GM#001-MC) + + The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:google:toolbar:1.1.41 + cpe:/a:google:toolbar:1.1.44 + cpe:/a:google:toolbar:1.1.53 + cpe:/a:google:toolbar:1.1.45 + cpe:/a:google:toolbar:1.1.54 + cpe:/a:google:toolbar:1.1.42 + cpe:/a:google:toolbar:1.1.55 + cpe:/a:google:toolbar:1.1.43 + cpe:/a:google:toolbar:1.1.56 + cpe:/a:google:toolbar:1.1.58 + cpe:/a:google:toolbar:1.1.49 + cpe:/a:google:toolbar:1.1.57 + cpe:/a:google:toolbar:1.1.48 + cpe:/a:google:toolbar:1.1.47 + + CVE-2002-1443 + 2003-04-11T00:00:00.000-04:00 + 2008-09-05T16:30:36.953-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5426 + + + BUGTRAQ + 20020808 Exploiting the Google toolbar (GM#001-MC) + + + CONFIRM + http://toolbar.google.com/whatsnew.php3 + + + MISC + http://sec.greymagic.com/adv/gm001-mc/ + + + XF + google-toolbar-keypress-monitoring(10054) + + + NTBUGTRAQ + 20020808 Exploiting the Google toolbar (GM#001-MC) + + The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + cpe:/a:google:toolbar:1.1.60 + + CVE-2002-1444 + 2002-08-15T00:00:00.000-04:00 + 2008-09-05T16:30:37.127-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + MISC + http://www.sztolnia.pl/hack/googIE/googIE.html + + + BID + 5477 + + + XF + ie-google-toolbar-dos(9883) + + + BUGTRAQ + 20020815 IE [with Google Toolbar installed] crash + + The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function. + + + + + + + + + cpe:/a:w3c:cern_httpd:3.0 + + CVE-2002-1445 + 2002-08-12T00:00:00.000-04:00 + 2008-09-05T16:30:37.267-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BID + 5447 + + + XF + cern-proxy-xss(9834) + + + BUGTRAQ + 20020811 CERN Proxy Server: Cross-Site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page. + + + + + + + + + cpe:/a:ncipher:pkcs_11_library:1.2.0 + + CVE-2002-1446 + 2002-08-01T00:00:00.000-04:00 + 2008-09-05T16:30:37.407-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CONFIRM + http://www.ncipher.com/support/advisories/advisory5_c_verify.html + + + BID + 5498 + + + XF + ncipher-cverify-improper-verification(9895) + + + BUGTRAQ + 20020819 nCipher Advisory #5: C_Verify validates incorrect symmetric signatures + + The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages. + + + + + + + + + cpe:/a:cisco:vpn_client:3.5.1 + + CVE-2002-1447 + 2002-05-28T00:00:00.000-04:00 + 2008-09-05T16:30:37.530-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://sec.angrypacket.com/advisories/0002_AP.vpnclient.txt + + + BID + 5056 + + + XF + ciscovpn-profile-name-bo(9376) + + + CISCO + 20020619 Buffer Overflow in UNIX VPN Client + + + BUGTRAQ + 20020619 [AP] Cisco vpnclient buffer overflow + + Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument. + + + + + + + + + + + cpe:/h:avaya:cajun_m770-atm + cpe:/h:avaya:cajun_p330 + cpe:/h:avaya:cajun_p130 + + CVE-2002-1448 + 2002-07-08T00:00:00.000-04:00 + 2008-09-05T16:30:37.670-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://support.avaya.com/security/Unauthorized_SNMP/index.jhtml + + + BID + 5396 + + + XF + avaya-cajun-default-snmp(9769) + + + BUGTRAQ + 20020805 SNMP vulnerability in AVAYA Cajun firmware + + An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges. + + + + + + + + + cpe:/a:frederic_tyndiuk:eupload:1.0 + + CVE-2002-1449 + 2002-07-31T00:00:00.000-04:00 + 2008-09-10T15:14:41.180-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020730 Bug in Eupload + + + XF + eupload-passwordtxt-overwrite-files(9733) + + + BID + 5369 + + eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt. + + + + + + + + + cpe:/a:ibm:u2_universe + + CVE-2002-1450 + 2002-07-31T00:00:00.000-04:00 + 2008-09-05T16:30:37.983-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + XF + ibm-universe-invalid-query-dos(9736) + + + BUGTRAQ + 20020731 TZ Advisores - Buffer Overflow in IBM U2 UniVerse ODBC + + IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow. + + + + + + + + + + cpe:/a:desiderata_software:blazix:1.2.1 + cpe:/a:desiderata_software:blazix:1.2 + + CVE-2002-1451 + 2002-08-24T00:00:00.000-04:00 + 2008-09-05T16:30:38.140-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BID + 5567 + + + BID + 5566 + + + XF + blazix-unauth-file-access(9952) + + + BUGTRAQ + 20020824 Blazix 1.2 jsp view and free protected folder access + + Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character. + + + + + + + + + cpe:/a:mywebserver:mywebserver:1.0.2 + + CVE-2002-1452 + 2002-08-14T00:00:00.000-04:00 + 2008-09-05T16:30:38.327-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BID + 5469 + + + XF + mywebserver-search-bo(9859) + + + VULNWATCH + 20020814 new bugs in MyWebServer + + + BUGTRAQ + 20020814 new bugs in MyWebServer + + Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. + + + + + + + + + cpe:/a:mywebserver:mywebserver:1.0.2 + + CVE-2002-1453 + 2002-08-14T00:00:00.000-04:00 + 2008-09-05T16:30:38.500-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + BID + 5470 + + + XF + mywebserver-long-http-xss(9861) + + + VULNWATCH + 20020814 new bugs in MyWebServer + + + BUGTRAQ + 20020814 new bugs in MyWebServer + + Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message. + + + + + + + + + cpe:/a:mywebserver:mywebserver:1.0.2 + + CVE-2002-1454 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:38.670-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5471 + + + XF + mywebserver-invalid-path-disclosure(9862) + + + BUGTRAQ + 20020814 new bugs in MyWebServer + + + VULNWATCH + 20020814 new bugs in MyWebServer + + MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message. + + + + + + + + + cpe:/a:omnicron:omnihttpd + + CVE-2002-1455 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:38.813-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20020825 More OmniHTTPd Problems + + + BUGTRAQ + 20020825 OmniHTTPd test.shtml Cross-Site Scripting Issue + + + BUGTRAQ + 20020825 OmniHTTPd test.php Cross-Site Scripting Issue + + Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe. + + + + + + + + + + + cpe:/a:khaled_mardam-bey:mirc:6.0 + cpe:/a:khaled_mardam-bey:mirc:6.0.1 + cpe:/a:khaled_mardam-bey:mirc:6.0.2 + + CVE-2002-1456 + 2003-06-09T00:00:00.000-04:00 + 2008-09-10T15:14:41.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + NTBUGTRAQ + 20020827 uuuppz.com - Advisory 002 - mIRC $asctime overflow + + + BUGTRAQ + 20020827 uuuppz.com - Advisory 002 - mIRC $asctime overflow + + + VULNWATCH + 20020827 uuuppz.com - Advisory 002 - mIRC $asctime overflow + + + MISC + http://www.mirc.co.uk/whatsnew.txt + + + BID + 5576 + + Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. + + + + + + + + + cpe:/a:leszek_krupinski:l-forum:2.4.0 + + CVE-2002-1457 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.077-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5468 + + + XF + lforum-search-sql-injection(9837) + + + VULNWATCH + 20020813 L-Forum Vulnerability - SQL Injection + + SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter. + + + + + + + + + cpe:/a:leszek_krupinski:l-forum:2.4.0 + + CVE-2002-1458 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.233-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5462 + + + XF + lforum-html-message-xss(9838) + + + MISC + http://sourceforge.net/tracker/download.php?group_id=53716&atid=471343&file_id=26687&aid=579278 + + + BUGTRAQ + 20020813 L-Forum XSS and upload spoofing + + Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body. + + + + + + + + + cpe:/a:leszek_krupinski:l-forum:2.4.0 + + CVE-2002-1459 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.373-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5462 + + + XF + lforum-html-message-xss(9838) + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=579278&group_id=53716&atid=471343 + + + CONFIRM + http://sourceforge.net/tracker/download.php?group_id=53716&atid=471343&file_id=26687&aid=579278 + + + BUGTRAQ + 20020813 L-Forum XSS and upload spoofing + + Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject. + + + + + + + + + cpe:/a:leszek_krupinski:l-forum:2.4.0 + + CVE-2002-1460 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.530-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5463 + + + XF + lforum-upload-read-files(9839) + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=579278&group_id=53716&atid=471343 + + + CONFIRM + http://sourceforge.net/tracker/download.php?group_id=53716&atid=471343&file_id=26687&aid=579278 + + + BUGTRAQ + 20020813 L-Forum XSS and upload spoofing + + L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. + + + + + + + + + cpe:/a:webscriptworld:web_shop_manager:1.1 + + CVE-2002-1461 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.670-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5474 + + + MISC + http://www.securiteam.com/securitynews/5KP0G0080E.html + + + XF + webshop-manager-execute-commands(9817) + + + BUGTRAQ + 20020815 Web Shop Manager Security Vulnerability + + Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box. + + + + + + + + + + cpe:/a:organicphp:php-affiliate:1.1 + cpe:/a:organicphp:php-affiliate:1.0 + + CVE-2002-1462 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.827-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5482 + + + XF + phpaffiliate-details-account-access(9858) + + + BUGTRAQ + 20020815 Input validation attack in php-affiliate-v1.0 + + details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:symantec:velociraptor:model_1100 + cpe:/a:symantec:velociraptor:model_1000 + cpe:/h:symantec:gateway_security:5300 + cpe:/a:symantec:velociraptor:model_1300 + cpe:/h:symantec:gateway_security:5110 + cpe:/a:symantec:enterprise_firewall:7.0 + cpe:/h:symantec:gateway_security:5200 + cpe:/a:symantec:raptor_firewall:6.5.3 + cpe:/a:symantec:velociraptor:model_700 + cpe:/a:symantec:enterprise_firewall:6.5.2 + cpe:/a:symantec:velociraptor:model_1200 + cpe:/a:symantec:velociraptor:model_500 + cpe:/a:symantec:raptor_firewall:6.5 + + CVE-2002-1463 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:39.967-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html + + + BUGTRAQ + 20020802 Security Advisory: Raptor Firewall Weak ISN Vulnerability + + + XF + symantec-tcp-seq-predict(12836) + + + BID + 5387 + + + OSVDB + 855 + + Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections. + + + + + + + + + cpe:/a:cafelog:b2:2.6pre4 + + CVE-2002-1464 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.157-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + + BID + 5455 + + + XF + b2-gpc-xss(9835) + + + VULNWATCH + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable. + + + + + + + + + cpe:/a:cafelog:b2:0.6pre2 + + CVE-2002-1465 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.297-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5456 + + + BUGTRAQ + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + + VULNWATCH + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + + XF + b2-tableposts-sql-injection(9836) + + SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. + + + + + + + + + cpe:/a:cafelog:b2:2.06pre4 + + CVE-2002-1466 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.453-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + + VULNWATCH + 20020813 Multiple Vulnerabilities in CafeLog Weblog Package + + CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. + + + + + + + + + + + + cpe:/a:macromedia:flash_player:6.0 + cpe:/a:macromedia:flash_player:6.0.29.0 + cpe:/a:macromedia:shockwave:8.0 + cpe:/a:macromedia:flash_player:6.0.40.0 + + CVE-2002-1467 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.610-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5429 + + + XF + flash-same-domain-disclosure(9797) + + + BUGTRAQ + 20020808 Macromedia Flash plugin can read local files + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23294 + + Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file). + + + + + + + + + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-1468 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.767-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + AIXAPAR + IY31997 + + + BID + 5885 + + Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root. + + + + + + + + + + cpe:/a:scponly:scponly:2.3 + cpe:/a:scponly:scponly:2.4 + + CVE-2002-1469 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:40.907-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5526 + + + XF + scponly-ssh-env-upload(9913) + + + BUGTRAQ + 20020820 vulnerabilities in scponly + + + CONFIRM + http://www.sublimation.org/scponly/ + + scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs. + + + + + + + + + cpe:/a:nullsoft:shoutcast_server:1.8.9 + + CVE-2002-1470 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:41.063-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5414 + + + BUGTRAQ + 20020806 Fate Research Labs Advisory: Retrieve SHOUTcast Admin Password Through GET / + + + XF + shoutcast-scservlog-world-readable(9775) + + SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file. + + + + + + + + + + + + + + cpe:/a:ximian:evolution:1.0.7 + cpe:/a:ximian:evolution:1.0.6 + cpe:/a:ximian:evolution:1.0.8 + cpe:/a:ximian:evolution:1.0.3 + cpe:/a:ximian:evolution:1.0.4 + cpe:/a:ximian:evolution:1.0.5 + + CVE-2002-1471 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:41.203-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + evolution-camel-certificate-mitm(10292) + + + BUGTRAQ + 20021003 SSL certificate validation problems in Ximian Evolution + + + BID + 5875 + + The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack. + + + + + + + + + + cpe:/a:xfree86_project:x11r6:4.2.0 + cpe:/a:xfree86_project:x11r6:4.1.0 + + CVE-2002-1472 + 2003-03-03T00:00:00.000-05:00 + 2008-09-05T16:30:41.407-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5735 + + + XF + xfree86-x11-program-execution(10137) + + + SUSE + SuSE-SA:2002:032 + + + REDHAT + RHSA-2003:067 + + + REDHAT + RHSA-2003:066 + + + OSVDB + 11922 + + + CONECTIVA + CLA-2002:529 + + Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module. + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + + CVE-2002-1473 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:41.577-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + hp-lp-dos(9992) + + + HP + HPSBUX0208-213 + + Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code. + + + + + + + + + + + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1474 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:41.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + COMPAQ + SSRT-547 + + Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service. + + + + + + + + + + + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1475 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:41.873-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + COMPAQ + SSRT-547 + + Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service. + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.6:beta + + CVE-2002-1476 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.030-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5724 + + + XF + netbsd-libc-setlocale-bo(10159) + + + OSVDB + 7565 + + + NETBSD + NetBSD-SA2002-012 + + Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh. + + + + + + + + + + + + + + + + + + cpe:/a:the_cacti_group:cacti:0.6.8 + cpe:/a:the_cacti_group:cacti:0.6 + cpe:/a:the_cacti_group:cacti:0.6.1 + cpe:/a:the_cacti_group:cacti:0.6.2 + cpe:/a:the_cacti_group:cacti:0.6.3 + cpe:/a:the_cacti_group:cacti:0.5 + cpe:/a:the_cacti_group:cacti:0.6.4 + cpe:/a:the_cacti_group:cacti:0.6.5 + cpe:/a:the_cacti_group:cacti:0.6.6 + cpe:/a:the_cacti_group:cacti:0.6.7 + + CVE-2002-1477 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.187-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + cacti-graph-label-commands(10048) + + + DEBIAN + DSA-164 + + + BUGTRAQ + 20020903 Cacti security issues + + + MISC + http://www.knights-of-the-routing-table.org/advisories/krt_001_20020903_cacti.txt + + + BID + 5627 + + graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. + + + + + + + + + + + + + + + + + + cpe:/a:the_cacti_group:cacti:0.6.8 + cpe:/a:the_cacti_group:cacti:0.6 + cpe:/a:the_cacti_group:cacti:0.6.1 + cpe:/a:the_cacti_group:cacti:0.6.2 + cpe:/a:the_cacti_group:cacti:0.6.3 + cpe:/a:the_cacti_group:cacti:0.5 + cpe:/a:the_cacti_group:cacti:0.6.4 + cpe:/a:the_cacti_group:cacti:0.6.5 + cpe:/a:the_cacti_group:cacti:0.6.6 + cpe:/a:the_cacti_group:cacti:0.6.7 + + CVE-2002-1478 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.360-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5630 + + + XF + cacti-console-mode-commands(10050) + + + BUGTRAQ + 20020903 Cacti security issues + + + MISC + http://www.knights-of-the-routing-table.org/advisories/krt_001_20020903_cacti.txt + + + DEBIAN + DSA-164 + + Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. + + + + + + + + + + + + + + + + + + cpe:/a:the_cacti_group:cacti:0.6.8 + cpe:/a:the_cacti_group:cacti:0.6 + cpe:/a:the_cacti_group:cacti:0.6.1 + cpe:/a:the_cacti_group:cacti:0.6.2 + cpe:/a:the_cacti_group:cacti:0.6.3 + cpe:/a:the_cacti_group:cacti:0.5 + cpe:/a:the_cacti_group:cacti:0.6.4 + cpe:/a:the_cacti_group:cacti:0.6.5 + cpe:/a:the_cacti_group:cacti:0.6.6 + cpe:/a:the_cacti_group:cacti:0.6.7 + + CVE-2002-1479 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.530-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5628 + + + XF + cacti-config-world-readable(10049) + + + BUGTRAQ + 20020903 Cacti security issues + + + MISC + http://www.knights-of-the-routing-table.org/advisories/krt_001_20020903_cacti.txt + + Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges. + + + + + + + + + cpe:/a:phpgb:phpgb:1.10 + + CVE-2002-1480 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.703-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5676 + + + XF + phpgb-entry-deletion-xss(10060) + + + BUGTRAQ + 20020909 phpGB: cross site scripting bug + + Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry. + + + + + + + + + + cpe:/a:phpgb:phpgb:1.20 + cpe:/a:phpgb:phpgb:1.10 + + CVE-2002-1481 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:42.843-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5679 + + + XF + phpgb-savesettings-unauth-access(10065) + + + BUGTRAQ + 20020909 phpGB: DoS and executing_arbitrary_commands + + savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php. + + + + + + + + + + + cpe:/a:phpgb:phpgb:1.20 + cpe:/a:phpgb:phpgb:1.10 + cpe:/a:phpgb:phpgb:1.30 + + CVE-2002-1482 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:43.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5673 + + + XF + phpgb-login-sql-injection(10068) + + + BUGTRAQ + 20020909 phpGB: DoS and executing_arbitrary_commands + + SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry. + + + + + + + + + + cpe:/a:db4web:db4web:3.6 + cpe:/a:db4web:db4web:3.4 + + CVE-2002-1483 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:43.157-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + db4web-db4webc-directory-traversal(10123) + + + BID + 5723 + + + CONFIRM + http://www.db4web.de/download/homepage/hotfix/readme_en.txt + + + VULNWATCH + 20020919 Advisory: File disclosure in DB4Web + + + BUGTRAQ + 20020917 Advisory: File disclosure in DB4Web + + db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot). + + + + + + + + + + cpe:/a:db4web:db4web:3.6 + cpe:/a:db4web:db4web:3.4 + + CVE-2002-1484 + 2003-04-22T00:00:00.000-04:00 + 2008-09-05T16:30:43.313-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5725 + + + XF + db4web-tcp-portscan(10136) + + + VULNWATCH + 20020919 Advisory: TCP-Connection risk in DB4Web + + + BUGTRAQ + 20020917 Advisory: TCP-Connection risk in DB4Web + + DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message. + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.73 + cpe:/a:cerulean_studios:trillian:0.74 + + CVE-2002-1485 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:43.453-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5783 + + + BUGTRAQ + 20020923 Trillian Remote DoS Attack - AIM + + The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C". + + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.725 + cpe:/a:cerulean_studios:trillian:0.73 + cpe:/a:cerulean_studios:trillian:0.74 + + CVE-2002-1486 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:43.610-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5777 + + + BUGTRAQ + 20020920 Yet Another. Trillian 'JOIN' Overflow. + + + BID + 5769 + + + BID + 5765 + + + XF + trillian-irc-server-bo(10163) + + + XF + trillian-raw221-bo(10151) + + + XF + trillian-irc-join-bo(10150) + + + NTBUGTRAQ + 20020914 Trillian .74 and below, ident flaw. + + + BUGTRAQ + 20020922 *sigh* Trillian multiple DoS + + + BUGTRAQ + 20020921 And Again. Trillian 'raw 221' Overflow. + + + NTBUGTRAQ + 20020919 Trillian .73 & .74 "PRIVMSG" Overflow. + + Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server. + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.74 + + CVE-2002-1487 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:43.767-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5775 + + + XF + trillian-irc-raw-dos(10161) + + + BUGTRAQ + 20020922 *sigh* Trillian multiple DoS + + The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367. + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.74 + + CVE-2002-1488 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:43.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5776 + + + XF + trillian-part-message-dos(10162) + + + BUGTRAQ + 20020922 *sigh* Trillian multiple DoS + + The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in. + + + + + + + + + cpe:/a:planetdns:planetweb:1.14 + + CVE-2002-1489 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.047-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + planetweb-long-url-bo(10124) + + + BID + 5710 + + + XF + planetweb-long-url-bo(10391) + + + BUGTRAQ + 20021017 New buffer overflow in plaetDNS + + + BUGTRAQ + 20020914 Planet Web Software Buffer Overflow + + Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1::arm32 + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:netbsd:netbsd:1.4::arm32 + cpe:/o:netbsd:netbsd:1.4.1::sh3 + cpe:/o:netbsd:netbsd:1.4::sparc + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.4.1::sparc + cpe:/o:netbsd:netbsd:1.5::x86 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.4::x86 + cpe:/o:netbsd:netbsd:1.4.1::alpha + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.1::x86 + cpe:/o:netbsd:netbsd:1.4.2::alpha + cpe:/o:netbsd:netbsd:1.6:beta + cpe:/o:netbsd:netbsd:1.4::alpha + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.5::sh3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2002-1490 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.187-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5722 + + + XF + netbsd-tiocsctty-ioctl-bo(10115) + + + OSVDB + 7566 + + + NETBSD + NetBSD-SA2002-007 + + NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and sets the counter to zero, which frees memory that is still in use by other processes. + + + + + + + + + + cpe:/a:cisco:vpn_5000_client:5.1.2::macos + cpe:/a:cisco:vpn_5000_client:5.2.1::macos + + CVE-2002-1491 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.390-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5736 + + + XF + cisco-vpn5000-defaultconnection-password(10129) + + + CISCO + 20020918 Cisco VPN 5000 Client Multiple Vulnerabilities + + + OSVDB + 7041 + + The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges. + + + + + + + + + + cpe:/a:cisco:vpn_5000_client:5.2.7::solaris + cpe:/a:cisco:vpn_5000_client:5.2.6::linux + + CVE-2002-1492 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.547-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5734 + + + XF + cisco-vpn5000-binary-bo(10131) + + + CISCO + 20020918 Cisco VPN 5000 Client Multiple Vulnerabilities + + Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel. + + + + + + + + + cpe:/a:lycos:htmlgear_guestgear + + CVE-2002-1493 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.687-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5728 + + + VULNWATCH + 20020926 [VulnWatch] BugTraq ID: 5728 + + + BUGTRAQ + 20020914 Lycos HTMLGear Guestbook Script Injection Vulnerability + + + XF + guestgear-img-xss(12235) + + Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag. + + + + + + + + + cpe:/a:aestiva:html_os:2.4 + + CVE-2002-1494 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.843-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5618 + + + XF + aestiva-htmlos-cgi-xss(10029) + + + BUGTRAQ + 20020903 Cross-Site Scripting in Aestiva's HTML/OS + + Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message. + + + + + + + + + + + cpe:/a:rudi_benkovic:jawmail:1.0.1 + cpe:/a:rudi_benkovic:jawmail:1.0_rc1 + cpe:/a:rudi_benkovic:jawmail:1.0 + + CVE-2002-1495 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:44.983-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5771 + + + XF + jawmail-mail-message-xss(10152) + + + BUGTRAQ + 20020922 JAWmail XSS + + Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver. + + + + + + + + + cpe:/a:nulllogic:null_httpd:0.5.0 + + CVE-2002-1496 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.140-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5774 + + + XF + null-httpd-contentlength-bo(10160) + + + CONFIRM + http://freshmeat.net/releases/97910/ + + + BUGTRAQ + 20020922 remote exploitable heap overflow in Null HTTPd 0.5.0 + + Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header. + + + + + + + + + cpe:/a:nulllogic:null_httpd:0.5.0 + + CVE-2002-1497 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.280-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://freshmeat.net/releases/97910/ + + + XF + null-httpd-xss(10004) + + + BID + 5603 + + Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response. + + + + + + + + + cpe:/a:trevor_lee:swserver:2.2 + + CVE-2002-1498 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5590 + + + XF + swserver-encoded-directory-traversal(9981) + + + BUGTRAQ + 20020828 SWServer 2.2 directory traversal bug + + Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "\" characters. + + + + + + + + + + + cpe:/a:factosystem:factosystem_weblog:1.0_beta + cpe:/a:factosystem:factosystem_weblog:0.9b + cpe:/a:factosystem:factosystem_weblog:1.1_beta + + CVE-2002-1499 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5600 + + + XF + factosystem-asp-sql-injection(10000) + + + BUGTRAQ + 20020831 FactoSystem CMS Contains Multiple Vulnerabilities + + + VULNWATCH + 20020830 FactoSystem CMS Contains Multiple Vulnerabilities + + + MISC + http://sourceforge.net/tracker/index.php?func=detail&aid=602711&group_id=12668&atid=112668 + + Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.4.1::arm32 + cpe:/o:netbsd:netbsd:1.4.2::arm32 + cpe:/o:netbsd:netbsd:1.4::arm32 + cpe:/o:netbsd:netbsd:1.4.1::sh3 + cpe:/o:netbsd:netbsd:1.4::sparc + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.4.2::sparc + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.4.1::sparc + cpe:/o:netbsd:netbsd:1.5::x86 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.4::x86 + cpe:/o:netbsd:netbsd:1.4.1::alpha + cpe:/o:netbsd:netbsd:1.4.2::x86 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.1::x86 + cpe:/o:netbsd:netbsd:1.4.2::alpha + cpe:/o:netbsd:netbsd:1.4::alpha + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.5::sh3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + + CVE-2002-1500 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.733-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5727 + + + XF + netbsd-fdset-bo(10114) + + + NETBSD + NetBSD-SA2002-014 + + Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET(). + + + + + + + + + + cpe:/h:enterasys:smartswitch_ssr8000:e8.2.0.0 + cpe:/h:enterasys:smartswitch_ssr8000:e8.3.0.4 + + CVE-2002-1501 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:45.937-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5703 + + + XF + smartswitch-portscan-dos(10096) + + + BUGTRAQ + 20020913 Scan against Enterasys SSR8000 crash the system + + + MISC + http://www.enterasys.com/support/techtips/tk0659-9.html + + The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078. + + + + + + + + + + cpe:/a:dave_brul:xbreaky:0.0.3 + cpe:/a:dave_brul:xbreaky:0.0.4 + + CVE-2002-1502 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.077-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5700 + + + CONFIRM + http://xbreaky.sourceforge.net/ + + + XF + xbreaky-breakyhighscores-symlink(10078) + + + BUGTRAQ + 20020912 xbreaky symlink vulnerability + + Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:afd:afd:1.2.10 + cpe:/a:afd:afd:1.2.11 + cpe:/a:afd:afd:1.2 + cpe:/a:afd:afd:1.2.14 + cpe:/a:afd:afd:1.2.12 + cpe:/a:afd:afd:1.2.13 + cpe:/a:afd:afd:1.2.2 + cpe:/a:afd:afd:1.2.1 + cpe:/a:afd:afd:1.2.8 + cpe:/a:afd:afd:1.2.7 + cpe:/a:afd:afd:1.2.9 + cpe:/a:afd:afd:1.2.4 + cpe:/a:afd:afd:1.2.3 + cpe:/a:afd:afd:1.2.6 + cpe:/a:afd:afd:1.2.5 + + CVE-2002-1503 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.233-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5626 + + + XF + afd-multiple-binaries-bo(10036) + + + BUGTRAQ + 20020904 AFD 1.2.14 multiple local root compromises + + + CONFIRM + http://www.dwd.de/AFD/txt/CHANGES + + Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc. + + + + + + + + + cpe:/a:radiobird_software:webserver_4_everyone:1.22 + + CVE-2002-1504 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + webserver-4everyone-directory-traversal(10051) + + + BUGTRAQ + 20020905 advisory + + Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL. + + + + + + + + + + + + cpe:/a:woltlab:burning_board:2.0_rc1 + cpe:/a:woltlab:burning_board:2.0_beta_5 + cpe:/a:woltlab:burning_board:2.0_beta_3 + cpe:/a:woltlab:burning_board:2.0_beta_4 + + CVE-2002-1505 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.563-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020908 sql injection vulnerability in WBB 2.0 RC1 and below + + + BID + 5675 + + + XF + wbb-board-sql-injection(10069) + + SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:jacques_gelinas:linuxconf:1.2.1r8 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r6 + cpe:/a:jacques_gelinas:linuxconf:1.27 + cpe:/a:jacques_gelinas:linuxconf:1.28 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r7 + cpe:/a:jacques_gelinas:linuxconf:1.1.6r10 + cpe:/a:jacques_gelinas:linuxconf:1.1.7 + cpe:/a:jacques_gelinas:linuxconf:1.1.8 + cpe:/a:jacques_gelinas:linuxconf:1.2r2 + cpe:/a:jacques_gelinas:linuxconf:1.2r1 + cpe:/a:jacques_gelinas:linuxconf:1.2.4r5 + cpe:/a:jacques_gelinas:linuxconf:1.2.4r4 + cpe:/a:jacques_gelinas:linuxconf:1.2 + cpe:/a:jacques_gelinas:linuxconf:1.2.3 + cpe:/a:jacques_gelinas:linuxconf:1.2.4 + cpe:/a:jacques_gelinas:linuxconf:1.2.1 + cpe:/a:jacques_gelinas:linuxconf:1.2.2 + cpe:/a:jacques_gelinas:linuxconf:1.2.3r1 + cpe:/a:jacques_gelinas:linuxconf:1.2.3r2 + cpe:/a:jacques_gelinas:linuxconf:1.2.4r2 + cpe:/a:jacques_gelinas:linuxconf:1.27r3 + cpe:/a:jacques_gelinas:linuxconf:1.28r3 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r1 + cpe:/a:jacques_gelinas:linuxconf:1.1.9r1 + cpe:/a:jacques_gelinas:linuxconf:1.1.9r2 + cpe:/a:jacques_gelinas:linuxconf:1.28r2 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r3 + cpe:/a:jacques_gelinas:linuxconf:1.28r1 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r2 + cpe:/a:jacques_gelinas:linuxconf:1.27r5 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r5 + cpe:/a:jacques_gelinas:linuxconf:1.27r4 + cpe:/a:jacques_gelinas:linuxconf:1.2.1r4 + + CVE-2002-1506 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.717-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5585 + + + XF + linuxconf-linuxconflang-env-bo(9980) + + + BUGTRAQ + 20020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflow + + + VULNWATCH + 20020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflow + + + MISC + http://www.solucorp.qc.ca/changes.hc?projet=linuxconf&version=1.28r4 + + Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated. + + + + + + + + + cpe:/a:epic_games:unreal_tournament_server:2003 + + CVE-2002-1507 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:46.953-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + ut-console-dos(10128) + + + VULNWATCH + 20020917 Fw: [ut2003bugs] remote denial of service in ut2003 demo + + Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777. + + + + + + + + + cpe:/a:openldap:openldap:2.2.0 + + CVE-2002-1508 + 2003-02-19T00:00:00.000-05:00 + 2008-09-10T15:14:48.147-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:040 + + + DEBIAN + DSA-227 + + + SUSE + SuSE-SA:2002:047 + + + XF + openldap-acl-slapd-bo(11288) + + + MANDRAKE + MDKSA-2003:006 + + slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests. + + + + + + + + + + + + cpe:/o:redhat:linux:8.0 + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:redhat:linux:7.3 + cpe:/o:redhat:linux:7.2 + + CVE-2002-1509 + 2003-03-03T00:00:00.000-05:00 + 2008-09-10T15:14:48.210-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=75418 + + + REDHAT + RHSA-2003:058 + + + REDHAT + RHSA-2003:057 + + + MANDRAKE + MDKSA-2003:026 + + A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email. + + + + + + + + + cpe:/a:xfree86_project:x11r6 + + CVE-2002-1510 + 2003-03-03T00:00:00.000-05:00 + 2008-09-05T16:30:47.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + xfree86-xdm-unauth-access(11389) + + + MISC + http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/xsrc/xfree/xc/programs/Xserver/hw/xfree86/CHANGELOG + + + REDHAT + RHSA-2003:065 + + + REDHAT + RHSA-2003:064 + + + SUNALERT + 55602 + + + CONECTIVA + CLA-2002:533 + + xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist. + + + + + + + + + + + + + + + + + + + cpe:/a:att:vnc:3.3.5 + cpe:/a:att:vnc:3.3.3r2 + cpe:/a:att:vnc:3.3.4 + cpe:/a:att:vnc:3.3.3 + cpe:/a:att:vnc:3.3.6 + cpe:/a:tightvnc:tightvnc:1.2.0 + cpe:/a:tightvnc:tightvnc:1.2.2 + cpe:/a:tightvnc:tightvnc:1.2.1 + cpe:/a:tightvnc:tightvnc:1.2.4 + cpe:/a:tightvnc:tightvnc:1.2.3 + cpe:/a:tightvnc:tightvnc:1.2.5 + + CVE-2002-1511 + 2003-03-03T00:00:00.000-05:00 + 2008-09-10T15:14:48.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:041 + + + XF + vnc-rand-weak-cookie(11384) + + + CONFIRM + http://changelogs.credativ.org/debian/pool/main/v/vnc/vnc_3.3.6-3/changelog + + + BID + 6905 + + + REDHAT + RHSA-2003:068 + + + MANDRAKE + MDKSA-2003:022 + + + SUNALERT + 56161 + + + GENTOO + 200302-15 + + + CONECTIVA + CLSA-2003:640 + + The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies. + + + + + + + + + cpe:/a:tolis_group:bru:17.0 + + CVE-2002-1512 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:47.717-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5708 + + + XF + bru-xbru-race-condition(10101) + + + BUGTRAQ + 20020912 Race condition in BRU Workstation 17.0 + + xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file. + + + + + + + + + + + + cpe:/o:compaq:tcp-ip_services:5.3::openvms + cpe:/o:compaq:tcp-ip_services:5.1::openvms + cpe:/o:compaq:tcp-ip_services:4.2::openvms + cpe:/o:compaq:tcp-ip_services:5.0a::openvms + + CVE-2002-1513 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:47.873-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5790 + + + XF + openvms-pop-gain-privileges(10236) + + + BUGTRAQ + 20020927 OpenVMS POP server local vulnerability + + + BUGTRAQ + 20021001 [security bulletin] SSRT2371 HP OpenVMS Potential POP server local vulnerability (fwd) + + + COMPAQ + SSRT2371 + + The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges. + + + + + + + + + + + + cpe:/a:borland_software:interbase:6.0 + cpe:/a:borland_software:interbase:6.5 + cpe:/a:borland_software:interbase:4.0 + cpe:/a:borland_software:interbase:5.0 + + CVE-2002-1514 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:48.030-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5805 + + + XF + interbase-gdslockmgr-bo(10196) + + + BUGTRAQ + 20020925 Borland Interbase local root exploit + + gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file. + + + + + + + + + cpe:/a:coolforum:coolforum:0.5_beta + + CVE-2002-1515 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:48.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5973 + + + XF + coolforum-avatar-view-php(10237) + + + BUGTRAQ + 20021012 CoolForum v 0.5 beta shows content of PHP files + + + CONFIRM + http://www.coolforum.net/index.php?p=dlcoolforum + + + VULNWATCH + 20021001 [VulnWatch] CoolForum v 0.5 beta shows content of PHP files + + Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.17m + + CVE-2002-1516 + 2003-04-02T00:00:00.000-05:00 + 2008-09-10T15:14:49.243-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + irix-rpcbind-w-symlink(10272) + + + CIAC + N-004 + + + BID + 5889 + + + SGI + 20020903-01-P + + rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/a:sgi:freeware:1.0 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.17m + + CVE-2002-1517 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:48.530-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5897 + + + XF + irix-fsr-efs-symlink(10275) + + + CIAC + N-004 + + + OSVDB + 8579 + + + SGI + 20021103-02-P + + + SGI + 20021103-01-P + + + SGI + 20020903-02-P + + + SGI + 20020903-01-P + + fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.17m + + CVE-2002-1518 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:48.733-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5893 + + + XF + irix-mv-directory-insecure(10276) + + + CIAC + N-004 + + + OSVDB + 8580 + + + SGI + 20020903-01-P + + mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories. + + + + + + + + + + + + + + + + + cpe:/h:rapidstream:rapidstream:500 + cpe:/h:watchguard:firebox:v100 + cpe:/h:rapidstream:rapidstream:4000 + cpe:/h:rapidstream:rapidstream:2000 + cpe:/h:rapidstream:rapidstream:6000 + cpe:/h:watchguard:firebox:v60 + cpe:/h:watchguard:firebox:v10 + cpe:/h:watchguard:firebox:v80 + cpe:/h:rapidstream:rapidstream:8000 + + CVE-2002-1519 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:48.937-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5814 + + + XF + firebox-vclass-cli-format-string(10217) + + + OSVDB + 4924 + + + BUGTRAQ + 20020927 Software Update Available for Legacy RapidStream Appliances and WatchGuard Firebox Vclass appliances + + + BUGTRAQ + 20020926 Watchguard firewall appliances security issues + + Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter. + + + + + + + + + + + + + + + + + cpe:/h:rapidstream:rapidstream:500 + cpe:/h:watchguard:firebox:v100 + cpe:/h:rapidstream:rapidstream:4000 + cpe:/h:rapidstream:rapidstream:2000 + cpe:/h:rapidstream:rapidstream:6000 + cpe:/h:watchguard:firebox:v60 + cpe:/h:watchguard:firebox:v10 + cpe:/h:watchguard:firebox:v80 + cpe:/h:rapidstream:rapidstream:8000 + + CVE-2002-1520 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.093-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5815 + + + XF + firebox-vclass-cli-admin-privileges(10218) + + + OSVDB + 4831 + + + BUGTRAQ + 20020927 Software Update Available for Legacy RapidStream Appliances and WatchGuard Firebox Vclass appliances + + + BUGTRAQ + 20020926 Watchguard firewall appliances security issues + + The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges. + + + + + + + + + cpe:/a:mdg_computer_services:web_server_4d:3.6 + + CVE-2002-1521 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.263-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5803 + + + XF + webserver-4d-plaintext-passwords(10198) + + + VULNWATCH + 20020925 [SecurityOffice] Webserver 4D v3.6 Weak Password Preservation Vulnerability + + Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges. + + + + + + + + + + + + cpe:/a:cooolsoft:powerftp:2.03 + cpe:/a:cooolsoft:powerftp:2.10 + cpe:/a:cooolsoft:powerftp:2.24 + cpe:/a:cooolsoft:powerftp:2.23 + + CVE-2002-1522 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5899 + + + XF + powerftp-long-username-dos(10286) + + + BUGTRAQ + 20021005 Vulnerabilitie in PowerFTP server + + + BUGTRAQ + 20021012 Coolsoft PowerFTP <= v2.24 Denial of Service (Linux Source) + + Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument. + + + + + + + + + cpe:/a:daniel_arenz:mini_server:2.1.6 + + CVE-2002-1523 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + mini-server-directory-traversal(10366) + + + CONFIRM + http://www.da-home.de/miniserver/update.html + + + BUGTRAQ + 20021013 Directory traversal in Daniel Arenz' Mini Server + + Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) ..\ (dot-dot backslash) sequences. + + + + + + + + + cpe:/a:nullsoft:winamp:3.0 + + CVE-2002-1524 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.733-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5832 + + + XF + winamp-xml-parser-bo(10228) + + + BUGTRAQ + 20020929 IIL Advisory: Winamp 3 (1.0.0.488) XML parser buffer overflow vulnerability + + Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag. + + + + + + + + + + cpe:/a:sun:sunone_starter_kit:2.0 + cpe:/a:astaware:searchdisc:3.1 + + CVE-2002-1525 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:49.873-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5828 + + + XF + sunone-starterkit-search-traversal(10225) + + + BUGTRAQ + 20020929 [LoWNOISE] "Get Knowledge" SunONE Starter Kit - Sun Microsystems/Astaware + + Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017. + + + + + + + + + cpe:/a:emumail:emu_webmail:5.0 + + CVE-2002-1526 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:50.030-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULNWATCH + 20020926 [VulnWatch] EMU Webmail 5.0 XSS vuln, and webroot path disclosure + + + BID + 5824 + + + XF + emu-webmail-address-xss(10205) + + Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field. + + + + + + + + + cpe:/a:emumail:emu_webmail:5.0 + + CVE-2002-1527 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:50.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + VULNWATCH + 20020926 [VulnWatch] EMU Webmail 5.0 XSS vuln, and webroot path disclosure + + + BID + 5823 + + + XF + emu-webmail-path-disclosure(10204) + + + XF + emu-webmail-address-xss(10205) + + emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message. + + + + + + + + + cpe:/a:mondosoft:mondosearch:4.4 + + CVE-2002-1528 + 2003-04-02T00:00:00.000-05:00 + 2008-09-05T16:30:50.327-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5941 + + + XF + mondosearch-url-souce-disclosure(10350) + + + BUGTRAQ + 20021010 MondoSearch show the source of all files + + MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter. + + + + + + + + + + + cpe:/a:surfcontrol:superscout_email_filter:3.5.1 + cpe:/a:surfcontrol:superscout_email_filter:4.0::smtp + cpe:/a:surfcontrol:superscout_email_filter:3.5 + + CVE-2002-1529 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:50.467-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5928 + + + XF + superscout-emailfilter-error-xss(10319) + + + BUGTRAQ + 20021008 Four Vulnerabilities in SurfControl's SuperScout Email Filter Administrative Server + + Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter. + + + + + + + + + + + cpe:/a:surfcontrol:superscout_email_filter:3.5.1 + cpe:/a:surfcontrol:superscout_email_filter:4.0::smtp + cpe:/a:surfcontrol:superscout_email_filter:3.5 + + CVE-2002-1530 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:50.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5929 + + + XF + superscout-emailfilter-plaintext-passwords(10320) + + + BUGTRAQ + 20021008 Four Vulnerabilities in SurfControl's SuperScout Email Filter Administrative Server + + The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form. + + + + + + + + + + + cpe:/a:surfcontrol:superscout_email_filter:3.5.1 + cpe:/a:surfcontrol:superscout_email_filter:4.0::smtp + cpe:/a:surfcontrol:superscout_email_filter:3.5 + + CVE-2002-1531 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:50.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5930 + + + XF + superscout-emailfilter-content-dos(10321) + + + BUGTRAQ + 20021008 Four Vulnerabilities in SurfControl's SuperScout Email Filter Administrative Server + + The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter. + + + + + + + + + + + cpe:/a:surfcontrol:superscout_email_filter:3.5.1 + cpe:/a:surfcontrol:superscout_email_filter:4.0::smtp + cpe:/a:surfcontrol:superscout_email_filter:3.5 + + CVE-2002-1532 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:50.937-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5931 + + + XF + superscout-emailfilter-get-dos(10322) + + + BUGTRAQ + 20021008 Four Vulnerabilities in SurfControl's SuperScout Email Filter Administrative Server + + The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it. + + + + + + + + + cpe:/a:jetty:jetty:4.1.0_rc4 + + CVE-2002-1533 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.077-04:00 + + + 5.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5821 + + + XF + jetty-http-xss(10219) + + + BUGTRAQ + 20020928 Jetty jsp/servlet engine xss / uname disclosure vuln + + Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a). + + + + + + + + + + + + cpe:/a:macromedia:flash_player:6.0.47.0 + cpe:/a:macromedia:flash_player:6.0 + cpe:/a:macromedia:flash_player:6.0.29.0 + cpe:/a:macromedia:flash_player:6.0.40.0 + + CVE-2002-1534 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.250-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5904 + + + XF + flash-xml-read-files(10297) + + + BUGTRAQ + 20021006 Flash player can read local files + + Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share. + + + + + + + + + + + cpe:/a:symantec:raptor_firewall:6.5.3 + cpe:/a:symantec:enterprise_firewall:6.5.2 + cpe:/a:symantec:raptor_firewall:6.5 + + CVE-2002-1535 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.407-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021014 Symantec Enterprise Firewall Secure Webserver info leak + + + BID + 5959 + + + XF + simple-webserver-topology-disclosure(10363) + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11a.html + + Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present. + + + + + + + + + cpe:/a:hans_persson:molly:0.5 + + CVE-2002-1536 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.607-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6007 + + + BUGTRAQ + 20021018 SCAN Associates Advisory: Molly 0.5 - Remote Command Execution + + + XF + molly-host-execute-commands(10397) + + + VULNWATCH + 20021018 SCAN Associates Advisory: Molly 0.5 - Remote Command Execution + + Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl. + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0.0 + + CVE-2002-1537 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.763-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6056 + + + XF + phpbb-adminugauth-admin-privileges(10489) + + + BUGTRAQ + 20021027 Privilege Escalation Vulnerability In phpBB 2.0.0 + + + OSVDB + 4284 + + admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u". + + + + + + + + + cpe:/a:acuma:acusend:4.0 + + CVE-2002-1538 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:51.907-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + acusend-unauthorized-file-access(10473) + + + BID + 6048 + + + BUGTRAQ + 20021025 Sec-Tec advisory 24.10.02 Unauthorised file acces in Acuma + + Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable. + + + + + + + + + + + + cpe:/a:alt-n:mdaemon:6.0.5 + cpe:/a:alt-n:mdaemon:6.0.6 + cpe:/a:alt-n:mdaemon:6.0.7 + cpe:/a:alt-n:mdaemon:6.0 + + CVE-2002-1539 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.060-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6053 + + + XF + mdaemon-dele-uidl-dos(10488) + + + BUGTRAQ + 20021027 MDaemon SMTP/POP/IMAP server DoS + + Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments. + + + + + + + + + + + cpe:/a:symantec:norton_antivirus:corporate_7.5 + cpe:/a:symantec:norton_antivirus:corporate_7.6 + cpe:/a:symantec:norton_antivirus:corporate_7.51 + + CVE-2002-1540 + 2003-03-31T00:00:00.000-05:00 + 2008-09-10T15:14:51.070-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + nav-winhlp32-gain-privileges(10475) + + + OSVDB + 6258 + + + BUGTRAQ + 20021025 RE: DH team: Norton Antivirus Corporate Edition Privilege Escalation, http://online.securityfocus.com/archive/1/296979/2002-10-22/2002-10-28/0 + + + BUGTRAQ + 20021024 DH team: Norton Antivirus Corporate Edition Privilege Escalation + + The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.0 + + CVE-2002-1541 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.357-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6044 + + + XF + badblue-protected-file-access(10466) + + + VULNWATCH + 20021024 [SecurityOffice] BadBlue Web Server v1.7 Protected File Access Vulnerability + + BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash). + + + + + + + + + cpe:/a:solarwinds:tftp_server:5.0.55_standard + + CVE-2002-1542 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.513-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6043 + + + XF + tftp-udp-datagram-bo(10462) + + + VULNWATCH + 20021024 TFTP Server DoS + + + BUGTRAQ + 20021024 TFTP Server DoS + + SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow. + + + + + + + + + + + + + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.3 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.6 + + CVE-2002-1543 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.670-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6036 + + + XF + trek-keyboard-input-bo(10458) + + + OSVDB + 7570 + + + NETBSD + NetBSD-SA2002-025 + + Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input. + + + + + + + + + cpe:/a:cooolsoft:personal_ftp_server:2.24 + + CVE-2002-1544 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.827-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021010 more silly bugs in cooolsoft 'personal ftp server' + + Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get. + + + + + + + + + cpe:/a:cooolsoft:personal_ftp_server:2.24 + + CVE-2002-1545 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:52.967-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BUGTRAQ + 20021010 more silly bugs in cooolsoft 'personal ftp server' + + CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. + + + + + + + + + cpe:/a:brs:webweaver:1.0.1 + + CVE-2002-1546 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.123-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.securityoffice.net/articles/webweaver/ + + + BID + 6041 + + + XF + brs-webweaver-file-access(10467) + + + VULNWATCH + 20021024 [SecurityOffice] BRS WebWeaver Web Server v1.01 Protected File Access Vulnerability + + BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence. + + + + + + + + + cpe:/o:juniper:netscreen_screenos:4.0.0r6 + + CVE-2002-1547 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CERT-VN + VU#930161 + + + CONFIRM + http://www.netscreen.com/support/alerts/11_06_02.html + + + XF + netscreen-ssh-dos(10528) + + + BUGTRAQ + 20021101 Netscreen SSH1 CRC32 Compensation Denial of service + + + OSVDB + 4376 + + + VULNWATCH + 20021101 (Correction) Netscreen SSH1 CRC32 Compensation Denial of service + + + VULNWATCH + 20021101 Netscreen SSH1 CRC32 Compensation Denial of service + + + BUGTRAQ + 20021101 (Correction) Netscreen SSH1 CRC32 Compensation Denial of service + + Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CVE-2001-0144. + + + + + + + + + + + + + + cpe:/o:ibm:aix:4.3.0 + cpe:/a:ibm:autofs + + CVE-2002-1548 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.407-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + AIXAPAR + IY31934 + + Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called." + + + + + + + + + cpe:/a:light_httpd:light_httpd:0.1 + + CVE-2002-1549 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6162 + + + XF + light-httpd-bo(10607) + + + BUGTRAQ + 20021112 Remote Buffer Overflow vulnerability in Light HTTPd + + Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1550 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.703-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + AIXAPAR + IY34617 + + + BID + 8802 + + dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1551 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:53.857-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + AIXAPAR + IY34670 + + Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code. + + + + + + + + + + + + cpe:/a:novell:edirectory:85.24 + cpe:/a:novell:edirectory:8.6.2 + cpe:/a:novell:edirectory:85.20 + cpe:/a:novell:edirectory:85.30 + + CVE-2002-1552 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.013-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6163 + + + BUGTRAQ + 20021112 NOVL-2002-2963827 - Remote Manager Security Issue - NW5.1 + + + BUGTRAQ + 20021112 NOVL-2002-2963767 - Remote Manager Security Issue - eDir 8.6.2 + + + XF + novell-edirectory-expired-accounts(10604) + + Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager. + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1553 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.157-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6076 + + + XF + cisco-ons-ftp-no-account(10505) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist. + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1554 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.310-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6078 + + + XF + cisco-ons-plaintext-accounts(10506) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup. + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1555 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.453-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6081 + + + XF + cisco-ons-snmp-public(10507) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information. + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1556 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.623-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6084 + + + XF + cisco-ons-corba-dos(10508) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR). + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1557 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.780-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6082 + + + XF + cisco-ons-http-dos(10509) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character. + + + + + + + + + + + + + + + + cpe:/o:cisco:ons_15454_optical_transport_platform:3.1.0 + cpe:/o:cisco:ons_15327:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.3 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.0 + cpe:/o:cisco:ons_15454_optical_transport_platform:3.2.0 + cpe:/o:cisco:ons_15327:3.0 + cpe:/o:cisco:ons_15327:3.2 + cpe:/o:cisco:ons_15327:3.1 + + CVE-2002-1558 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:54.953-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6083 + + + XF + cisco-ons-default-vsworks-account(10510) + + + CISCO + 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities + + Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet. + + + + + + + + + cpe:/a:research_systems_inc.:ion_script:1.4 + + CVE-2002-1559 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:55.123-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6091 + + + XF + ion-ionp-view-files(10518) + + + BUGTRAQ + 20021101 Re: ion-p.exe allows Remote File Retrieving + + + BUGTRAQ + 20021101 ion-p.exe allows Remote File Retrieving + + Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter. + + + + + + + + + cpe:/a:martin_bauer:gbook:1.4 + + CVE-2002-1560 + 2003-03-31T00:00:00.000-05:00 + 2008-09-05T16:30:55.263-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20021022 gBook + + + BID + 6033 + + + XF + gbook-mysql-admin-access(10455) + + index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:terminal_server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:64-bit + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000_terminal_services + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_nt:4.0::workstation + + CVE-2002-1561 + 2003-04-02T00:00:00.000-05:00 + 2008-09-10T15:14:53.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + + CERT-VN + VU#261537 + + + BID + 6005 + + + BUGTRAQ + 20021018 [Immunity, Inc.]Vulnerability: RPC Service DoS (port 135/tcp) onWindows 2000 SP3 + + + MS + MS03-010 + + + + + The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference. + + + + + + + + + cpe:/a:acme_labs:thttpd + + CVE-2002-1562 + 2003-05-12T00:00:00.000-04:00 + 2008-09-05T16:30:55.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://news.php.net/article.php?group=php.cvs&article=15698 + + + CONFIRM + http://marc.theaimsgroup.com/?l=thttpd&m=103609565110472&w=2 + + + DEBIAN + DSA-396 + + + CONECTIVA + CLA-2003:777 + + Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. + + + + + + + + + cpe:/a:stunnel:stunnel:4.04 + + CVE-2002-1563 + 2003-05-12T00:00:00.000-04:00 + 2008-09-05T16:30:55.873-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + REDHAT + RHSA-2003:221 + + + MISC + http://marc.theaimsgroup.com/?l=stunnel-users&m=103600188215117&w=2 + + + REDHAT + RHSA-2003:223 + + + ENGARDE + ESA-20030806-020 + + + BUGTRAQ + 20030112 SIGCHLD problem in Stunnel + + + BID + 6592 + + + TRUSTIX + 2003-0030 + + + CONECTIVA + CLA-2003:736 + + stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter. + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-1564 + 2003-06-09T00:00:00.000-04:00 + 2008-09-05T16:30:56.013-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + MS + MS02-023 + + Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability. + + + + + + + + + cpe:/a:immunix:immunix:7 + + CVE-2002-1565 + 2003-06-16T00:00:00.000-04:00 + 2008-09-05T16:30:56.170-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + DEBIAN + DSA-209 + + + BUGTRAQ + 20030604 Immunix Secured OS 7+ wget update + + + XF + wget-url-filename-bo(10851) + + + REDHAT + RHSA-2003:372 + + + CONECTIVA + CLA-2003:716 + + + SCO + CSSA-2003-003.0 + + + SGI + 20040202-01-U + + Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL. + + + + + + + + + + + cpe:/a:netris:netris:0.4 + cpe:/a:netris:netris:0.5 + cpe:/a:netris:netris:0.3 + + CVE-2002-1566 + 2003-08-27T00:00:00.000-04:00 + 2008-09-05T16:30:56.310-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + XF + netris-remote-bo(10081) + + + BID + 5680 + + + VULN-DEV + 20020909 netris-0.5. + + netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (crash) via a long string to port 9284. + + + + + + + + + cpe:/a:apache:tomcat:4.1.0 + + CVE-2002-1567 + 2003-10-06T00:00:00.000-04:00 + 2008-09-05T16:30:56.467-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + VULN-DEV + 20020821 Apache Tomcat 4.1 Cross-Site Scripting Vulnerability + + + CONFIRM + http://tomcat.apache.org/security-4.html + + Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script. + + + + + + + + + cpe:/a:openssl:openssl:0.9.6e + + CVE-2002-1568 + 2003-11-17T00:00:00.000-05:00 + 2008-09-05T16:30:56.607-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + CONFIRM + http://cvs.openssl.org/chngview?cn=7659 + + + MISC + http://www.ebitech.sk/patrik/SA/SA-20031002.txt + + + BUGTRAQ + 20031002 New OpenSSL remote vulnerability (issue date 2003/10/02) + + OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:gv:gv:3.0.4 + cpe:/a:gv:gv:3.4.3 + cpe:/a:gv:gv:3.5.8 + cpe:/a:gv:gv:3.2.4 + cpe:/a:ghostview:ghostview:1.5 + cpe:/a:gv:gv:3.4.2 + cpe:/a:gv:gv:3.0.0 + cpe:/a:gv:gv:2.7b5 + cpe:/a:ghostview:ghostview:1.4.1 + cpe:/a:gv:gv:2.9.4 + cpe:/a:gv:gv:3.5.3 + cpe:/a:ghostview:ghostview:1.4 + cpe:/a:gv:gv:2.7b2 + cpe:/a:gv:gv:3.5.2 + cpe:/a:ghostview:ghostview:1.3 + cpe:/a:gv:gv:2.7b1 + cpe:/a:gv:gv:2.7b4 + cpe:/a:gv:gv:2.7b3 + cpe:/a:gv:gv:3.1.6 + cpe:/a:gv:gv:2.7.6 + cpe:/a:gv:gv:3.1.4 + cpe:/a:gv:gv:3.4.12 + + CVE-2002-1569 + 2003-11-17T00:00:00.000-05:00 + 2008-09-05T16:30:56.763-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + gv-system-execute-commands(10231) + + + BID + 5840 + + + MISC + http://www.epita.fr/~bevand_m/asa/asa-0000 + + + BUGTRAQ + 20021003 GLSA: gv + + + BUGTRAQ + 20021001 ASA-0000: GV Execution of Arbitrary Shell Commands + + gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file. + + + + + + + + + cpe:/a:ucd-snmp:ucd-snmp:4.2.3 + + CVE-2002-1570 + 2003-11-03T00:00:00.000-05:00 + 2008-09-05T16:30:56.953-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + netsnmp-snmpnetstat-heap-overflow(7776) + + + BID + 3780 + + + BUGTRAQ + 20020103 Heap overflow in snmpnetstat + + + CONECTIVA + CLA-2003:696 + + Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18:pre4 + cpe:/o:linux:linux_kernel:2.4.18::x86 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.18:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre3 + cpe:/o:linux:linux_kernel:2.4.0:test11 + cpe:/o:linux:linux_kernel:2.4.0:test12 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.18:pre5 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.18:pre8 + cpe:/o:linux:linux_kernel:2.4.0:test10 + cpe:/o:linux:linux_kernel:2.4.18:pre7 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.0:test9 + cpe:/o:linux:linux_kernel:2.4.0:test8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.19 + cpe:/o:linux:linux_kernel:2.4.0:test4 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.0:test5 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.0:test6 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.0:test7 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.0:test2 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0:test3 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.0:test1 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.18:pre1 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.18:pre2 + + CVE-2002-1571 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:30:57.107-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-24T08:58:00.000-05:00 + + + + MLIST + [linux-kernel] 20020417 Re: SSE related security hole + + + MLIST + [linux-kernel] 20020417 SSE related security hole + + + MLIST + [linux-kernel] 20020422 Re: SSE related security hole + + + MLIST + [linux-kernel] 20020418 Re: SSE related security hole + + + CONFIRM + http://linux.bkbits.net:8080/linux-2.4/diffs/arch/i386/kernel/i387.c@1.6 + + The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18:pre4 + cpe:/o:linux:linux_kernel:2.4.18::x86 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.18:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre3 + cpe:/o:linux:linux_kernel:2.4.0:test11 + cpe:/o:linux:linux_kernel:2.4.0:test12 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.18:pre5 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.18:pre8 + cpe:/o:linux:linux_kernel:2.4.0:test10 + cpe:/o:linux:linux_kernel:2.4.18:pre7 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.0:test9 + cpe:/o:linux:linux_kernel:2.4.0:test8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.19 + cpe:/o:linux:linux_kernel:2.4.0:test4 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.0:test5 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.0:test6 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.0:test7 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.0:test2 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0:test3 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.0:test1 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.18:pre1 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.18:pre2 + + CVE-2002-1572 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:30:57.407-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-01-30T08:54:00.000-05:00 + + + + REDHAT + RHSA-2002:206 + + + REDHAT + RHSA-2002:205 + + + CONFIRM + http://linux.bkbits.net:8080/linux-2.4/cset@3d6badc0mxsPaOTT_GuPVxCp1_ormw + + Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18:pre4 + cpe:/o:linux:linux_kernel:2.4.18::x86 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.18:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre3 + cpe:/o:linux:linux_kernel:2.4.0:test11 + cpe:/o:linux:linux_kernel:2.4.0:test12 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.18:pre5 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.18:pre8 + cpe:/o:linux:linux_kernel:2.4.0:test10 + cpe:/o:linux:linux_kernel:2.4.18:pre7 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.0:test9 + cpe:/o:linux:linux_kernel:2.4.0:test8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.19 + cpe:/o:linux:linux_kernel:2.4.0:test4 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.0:test5 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.0:test6 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.0:test7 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.0:test2 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0:test3 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.0:test1 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.18:pre1 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.18:pre2 + + CVE-2002-1573 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:30:57.657-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-01-30T08:55:00.000-05:00 + + + + REDHAT + RHSA-2002:206 + + + REDHAT + RHSA-2002:205 + + + CONFIRM + http://linux.bkbits.net:8080/linux-2.4/cset@3d6aadcbBIDX67Zl6zZnVKRcsilCVQ + + Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling." + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.18:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre6 + cpe:/o:linux:linux_kernel:2.4.18:pre3 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.18:pre5 + cpe:/o:linux:linux_kernel:2.4.18:pre8 + cpe:/o:linux:linux_kernel:2.4.18:pre7 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.18:pre1 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.18:pre2 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + + CVE-2002-1574 + 2004-03-03T00:00:00.000-05:00 + 2008-09-05T16:30:57.920-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5985 + + + REDHAT + RHSA-2004:044 + + + XF + linux-ixj-root-privileges(10417) + + + REDHAT + RHSA-2004:106 + + + REDHAT + RHSA-2002:206 + + + REDHAT + RHSA-2002:205 + + + CIAC + N-096 + + Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors. + + + + + + + + + cpe:/a:mit:cgiemail:1.6 + + CVE-2002-1575 + 2004-03-03T00:00:00.000-05:00 + 2008-09-05T16:30:58.123-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 5013 + + + DEBIAN + DSA-437 + + + XF + cgiemail-open-mail-relay(9361) + + + BUGTRAQ + 20020614 Another cgiemail bug + + + BUGTRAQ + 20031003 patch for vulnerability in cgiemail + + cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message. + + + + + + + + + cpe:/a:sap:sap_db:7.3.00 + + CVE-2002-1576 + 2004-04-15T00:00:00.000-04:00 + 2008-09-05T16:30:58.280-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + sap-db-lserversrv-symlink(10762) + + + BID + 6316 + + + CONFIRM + http://www.sapdb.org/sap_db_alert.htm + + + BUGTRAQ + 20021204 SAP database local root via symlink + + lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program. + + + + + + + + + cpe:/a:sap:sap_r_3:2.0b_to_4.6d + + CVE-2002-1577 + 2004-04-15T00:00:00.000-04:00 + 2008-09-05T16:30:58.420-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sap-r3-default-account(9964) + + + BUGTRAQ + 20020825 SAP R/3 default password vulnerability + + SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts. + + + + + + + + + cpe:/a:sap:sap_r_3 + + CVE-2002-1578 + 2004-04-15T00:00:00.000-04:00 + 2008-09-05T16:30:58.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + XF + sap-db-data-access(8972) + + + BID + 4613 + + + BUGTRAQ + 20020427 SAP R/3 on Oracle: vulnerable Default Installation + + The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected. + + + + + + + + + + + + + cpe:/a:sap:sapgui:4.6::windows + cpe:/a:sap:sapgui:4.6c::windows + cpe:/a:sap:sapgui:4.6d::windows + cpe:/a:sap:sapgui:4.6a::windows + cpe:/a:sap:sapgui:4.6b::windows + + CVE-2002-1579 + 2004-04-15T00:00:00.000-04:00 + 2008-09-05T16:30:58.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 3972 + + + XF + sapgui-invalid-connect-dos(8007) + + + BUGTRAQ + 20020128 Sapgui 4.6D for Windows + + SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error. + + + + + + + + + + + + + + cpe:/a:carnegie_mellon_university:cyrus_imap_server:1.5.19 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.0.12 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.1.10 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.1.9 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:1.4 + cpe:/a:carnegie_mellon_university:cyrus_imap_server:2.0.16 + + CVE-2002-1580 + 2004-06-14T00:00:00.000-04:00 + 2008-09-05T16:30:58.873-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#740169 + + + XF + cyrus-imap-preauth-bo(10744) + + + BID + 6298 + + + BUGTRAQ + 20021202 pre-login buffer overflow in Cyrus IMAP server + + + DEBIAN + DSA-215 + + + CONECTIVA + CLA-2002:557 + + + CONFIRM + http://asg.web.cmu.edu/cyrus/download/imapd/changes.html + + + CONECTIVA + 000557 + + Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mailreader.com:mailreader.com:2.3.29 + cpe:/a:mailreader.com:mailreader.com:2.3.21 + cpe:/a:mailreader.com:mailreader.com:2.3.22 + cpe:/a:mailreader.com:mailreader.com:2.3.23 + cpe:/a:mailreader.com:mailreader.com:2.3.24 + cpe:/o:debian:debian_linux:3.0 + cpe:/a:mailreader.com:mailreader.com:2.3.25 + cpe:/a:mailreader.com:mailreader.com:2.3.26 + cpe:/a:mailreader.com:mailreader.com:2.3.27 + cpe:/a:mailreader.com:mailreader.com:2.3.28 + cpe:/a:mailreader.com:mailreader.com:2.3.20 + cpe:/a:mailreader.com:mailreader.com:2.3.31 + cpe:/a:mailreader.com:mailreader.com:2.3.30 + + CVE-2002-1581 + 2004-12-06T00:00:00.000-05:00 + 2011-03-07T21:10:29.080-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + + BID + 6055 + + + BUGTRAQ + 20021028 SCAN Associates Advisory : Multiple vurnerabilities on mailreader.com + + + XF + mailreader-dotdot-directory-traversal(10490) + + + DEBIAN + DSA-534 + + + MISC + http://mailreader.com/download/ChangeLog + + Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter. + + + + + + + + + + cpe:/a:mailreader.com:mailreader.com:2.3.31 + cpe:/a:mailreader.com:mailreader.com:2.3.30 + + CVE-2002-1582 + 2004-12-06T00:00:00.000-05:00 + 2008-09-05T16:30:59.217-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6058 + + + BUGTRAQ + 20021028 SCAN Associates Advisory : Multiple vurnerabilities on mailreader.com + + + XF + mailreader-compose-command-execution(10491) + + + CONFIRM + http://www.mailreader.com/download/ChangeLog + + compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi. + + + + + + + + + + + + + cpe:/a:ibm:db2_universal_database:7.0::linux + cpe:/a:ibm:db2_universal_database:7.1::linux + cpe:/a:ibm:db2_universal_database:6.0 + cpe:/a:ibm:db2_universal_database:7.2::linux + cpe:/a:ibm:db2_universal_database:8.2::windows + + CVE-2002-1583 + 2004-09-28T00:00:00.000-04:00 + 2008-09-05T16:30:59.357-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2004-01-01T00:00:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + IBM + MSS-OAR-E01-2002:318.1 + + + BID + 4817 + + + XF + ibm-db2-db2ckpw-bo(9078) + + Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.19 + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.18 + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.8m + cpe:/o:sgi:irix:6.5.4m + cpe:/o:sgi:irix:6.5.8f + cpe:/o:sgi:irix:6.5.4f + cpe:/o:sun:solaris:7.0 + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.9m + cpe:/o:sgi:irix:6.5.5m + cpe:/o:sgi:irix:6.5.18f + cpe:/o:sgi:irix:6.5.18m + cpe:/o:sgi:irix:6.5.9f + cpe:/o:sgi:irix:6.5.5f + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.2f + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.2m + cpe:/o:sgi:irix:6.5.6m + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.6f + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.10m + cpe:/o:sgi:irix:6.5.17m + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sgi:irix:6.5.15f + cpe:/o:sun:solaris:2.6 + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.3m + cpe:/o:sgi:irix:6.5.7m + cpe:/o:sgi:irix:6.5.16f + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.3f + cpe:/o:sgi:irix:6.5.7f + + CVE-2002-1584 + 2002-12-27T00:00:00.000-05:00 + 2008-09-10T15:15:00.337-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#518057 + + + SGI + 20030402-01-P + + + XF + solaris-authdes-gain-privileges(10935) + + + SUNALERT + 46944 + + + SECTRACK + 1005934 + + + BID + 6484 + + Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges. + + + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1585 + 2002-11-08T00:00:00.000-05:00 + 2008-09-10T15:15:00.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SUNALERT + 48601 + + + XF + solaris-tcp-interface-dos(10600) + + + BID + 6147 + + Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic. + + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-1586 + 2002-12-03T00:00:00.000-05:00 + 2008-09-10T15:15:00.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SUNALERT + 48267 + + + XF + solaris-null-pointer-dos(10769) + + + SECTRACK + 1005742 + + + BID + 6309 + + Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2002-1587 + 2002-12-04T00:00:00.000-05:00 + 2008-09-10T15:15:00.557-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SUNALERT + 46867 + + + XF + solaris-libthread-dos(11146) + + + BID + 6318 + + The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex. + + + + + + + + + + + cpe:/a:sun:openwindows:3.6.2 + cpe:/a:sun:openwindows:3.6.1 + cpe:/a:sun:openwindows:3.6 + + CVE-2002-1588 + 2002-11-29T00:00:00.000-05:00 + 2008-09-10T15:15:00.617-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SUNALERT + 48216 + + + XF + openwindows-mailtool-dos(10732) + + + BID + 6279 + + Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment. + + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-1589 + 2002-10-24T00:00:00.000-04:00 + 2008-09-10T15:15:00.680-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + SUNALERT + 48067 + + + XF + solaris-kmem-flags-dos(10496) + + + BID + 6080 + + Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic). + + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-1590 + 2002-10-29T00:00:00.000-05:00 + 2008-09-10T15:15:00.757-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + + SUNALERT + 48320 + + + XF + solaris-wbem-files-insecure(10495) + + + BID + 6061 + + + CIAC + N-010 + + The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service. + + + + + + + + + cpe:/a:aol:instant_messenger:4.7.2480 + + CVE-2002-1591 + 2002-04-08T00:00:00.000-04:00 + 2008-09-05T16:31:00.733-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#744139 + + + MISC + http://www.instantmessagingplanet.com/security/article.php/10818_1014151 + + + MISC + http://www.informationweek.com/story/IWK20010927S0021 + + AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions. + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.35 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:2.0.28 + + CVE-2002-1592 + 2002-05-06T00:00:00.000-04:00 + 2008-09-05T16:31:00.873-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#165803 + + + BID + 5256 + + + XF + apache-aplogrerror-path-disclosure(9623) + + + CONFIRM + http://www.apache.org/dist/httpd/CHANGES_2.0 + + The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:2.0.38 + cpe:/a:apache:http_server:2.0.37 + cpe:/a:apache:http_server:2.0.36 + cpe:/a:apache:http_server:2.0.35 + cpe:/a:apache:http_server:2.0.32 + cpe:/a:apache:http_server:2.0.39 + cpe:/a:apache:http_server:2.0 + cpe:/a:apache:http_server:2.0.41 + cpe:/a:apache:http_server:2.0.28 + cpe:/a:apache:http_server:2.0.40 + + CVE-2002-1593 + 2002-09-25T00:00:00.000-04:00 + 2008-09-05T16:31:01.030-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#406121 + + + XF + apache-mod-dav-dos(10208) + + + BID + 5816 + + + CONFIRM + http://www.apache.org/dist/httpd/CHANGES_2.0 + + + SECTRACK + 1005285 + + mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module. + + + + + + + + + + cpe:/a:grpck:grpck + cpe:/a:pwck:pwck + + CVE-2002-1594 + 2002-01-02T00:00:00.000-05:00 + 2008-09-05T16:31:01.187-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#877811 + + + CERT-VN + VU#121891 + + + XF + pwck-command-line-bo(7859) + + + XF + grpck-command-line-bo(7857) + + + MISC + http://publib.boulder.ibm.com/infocenter/pseries/topic/com.ibm.aix.doc/cmds/aixcmds2/grpck.htm + + + VULNWATCH + 20020102 blackshell3: multiple pwck/grpck vulnerabilities + + + VULN-DEV + 20020102 Re: [VulnWatch] blackshell3: multiple pwck/grpck vulnerabilities + + Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument. + + + + + + + + + + + + cpe:/o:cisco:sn_5420_storage_router:1.1%282%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%285%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%284%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%283%29 + + CVE-2002-1595 + 2002-01-09T00:00:00.000-05:00 + 2008-09-05T16:31:01.343-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#833459 + + + BID + 3832 + + + CISCO + 20020109 Multiple Vulnerabilities in Cisco SN 5420 Storage Routers + + + XF + cisco-sn-view-configuration(7828) + + Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization. + + + + + + + + + + + + cpe:/o:cisco:sn_5420_storage_router:1.1%282%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%285%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%284%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%283%29 + + CVE-2002-1596 + 2002-01-09T00:00:00.000-05:00 + 2008-09-05T16:31:01.483-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#968187 + + + BID + 3834 + + + CISCO + 20020109 Multiple Vulnerabilities in Cisco SN 5420 Storage Routers + + + XF + cisco-sn-http-dos(7829) + + Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers. + + + + + + + + + + + + cpe:/o:cisco:sn_5420_storage_router:1.1%282%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%285%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%284%29 + cpe:/o:cisco:sn_5420_storage_router:1.1%283%29 + + CVE-2002-1597 + 2002-01-09T00:00:00.000-05:00 + 2008-09-05T16:31:01.640-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#855195 + + + BID + 3833 + + + CISCO + 20020109 Multiple Vulnerabilities in Cisco SN 5420 Storage Routers + + + XF + cisco-sn-fragment-dos(7830) + + Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface. + + + + + + + + + cpe:/a:ca:mlink:6.5 + + CVE-2002-1598 + 2002-04-05T00:00:00.000-05:00 + 2008-09-05T16:31:01.843-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#772915 + + + CERT-VN + VU#544995 + + + XF + ca-mlink-bo(8776) + + + BID + 4441 + + + BID + 4440 + + + BUGTRAQ + 20020405 Re: CA security contact + + + CONFIRM + ftp://ftp.ca.com/pub/unicenter/mlink/mlink.13/MLINK13.README + + Buffer overflows in Computer Associates MLink (CA-MLink) 6.5 and earlier may allow local users to execute arbitrary code via long command line arguments to (1) mlclear or (2) mllock. + + + + + + + + + + + + + + + + + cpe:/a:daniel_barron:dansguardian:2.2.2.9.1 + cpe:/a:daniel_barron:dansguardian:2.2.2.7.1 + cpe:/a:daniel_barron:dansguardian:2_2.2.4 + cpe:/a:daniel_barron:dansguardian:2_2.2.5 + cpe:/a:daniel_barron:dansguardian:2_2.2.6 + cpe:/a:daniel_barron:dansguardian:2_2.2.7 + cpe:/a:daniel_barron:dansguardian:2_2.2.8 + cpe:/a:daniel_barron:dansguardian:2_2.2.9 + cpe:/a:daniel_barron:dansguardian:2_2.2.10 + + CVE-2002-1599 + 2002-07-23T00:00:00.000-04:00 + 2008-09-05T16:31:01.983-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#940203 + + + BID + 5291 + + + CONFIRM + http://dansguardian.org/?page=history + + + XF + dansguardian-url-bypass-filtering(9681) + + + CONFIRM + http://dansguardian.org/?page=knownbugs + + DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs. + + + + + + + + + + + cpe:/a:mike_spice:my_classifieds:1.2 + cpe:/a:mike_spice:my_classifieds:1.1 + cpe:/a:mike_spice:my_classifieds:1.0 + + CVE-2002-1600 + 2002-01-09T00:00:00.000-05:00 + 2008-09-10T15:15:02.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#181907 + + + SECTRACK + 1003255 + + + BID + 3855 + + + XF + myclassifieds-gain-privileges(7967) + + Directory traversal vulnerability in Mike Spice's My Classifieds (classifieds.cgi) before 1.3 allows remote attackers to overwrite arbitrary files via the category parameter. + + + + + + + + + + + cpe:/a:adobe:photodeluxe:3.1 + cpe:/a:adobe:photodeluxe:4.0 + cpe:/a:adobe:photodeluxe:3.0 + + CVE-2002-1601 + 2002-02-09T00:00:00.000-05:00 + 2008-09-05T16:31:02.297-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.kb.cert.org/vuls/id/AAMN-56LQ2J + + + CERT-VN + VU#116875 + + + XF + adobe-photodeluxe-execute-java(8210) + + + BID + 4106 + + The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page. + + + + + + + + + + + + + cpe:/a:gnu:screen:3.9.8 + cpe:/a:gnu:screen:3.9.9 + cpe:/a:gnu:screen:3.9.4 + cpe:/a:gnu:screen:3.9.11 + cpe:/a:gnu:screen:3.9.10 + + CVE-2002-1602 + 2002-04-23T00:00:00.000-04:00 + 2008-09-05T16:31:02.450-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#524227 + + + XF + screen-braille-module-bo(8929) + + + BID + 4578 + + + BUGTRAQ + 20020420 ALERT! ALERT! ALERT! ALERT! ALERT! hehehehe ;Pppppp + + Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code. + + + + + + + + + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:2.1.2 + cpe:/a:goahead_software:goahead_webserver:2.1.1 + cpe:/a:goahead_software:goahead_webserver:2.1.7 + cpe:/a:goahead_software:goahead_webserver:2.1.3 + cpe:/a:goahead_software:goahead_webserver:2.0 + cpe:/a:goahead_software:goahead_webserver:2.1.4 + cpe:/a:goahead_software:goahead_webserver:2.1 + cpe:/a:goahead_software:goahead_webserver:2.1.5 + cpe:/a:goahead_software:goahead_webserver:2.1.6 + + CVE-2002-1603 + 2002-02-13T00:00:00.000-05:00 + 2009-02-10T00:22:32.983-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#975041 + + + CERT-VN + VU#124059 + + + XF + goahead-script-source-disclosure(10885) + + + BID + 9239 + + + MISC + http://www.procheckup.com/PDFs/ProCheckUp_Vulns_2002.pdf + + + CONFIRM + http://www.kb.cert.org/vuls/id/RGII-7MWKZ3 + + + SECTRACK + 1005820 + + + CONFIRM + http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729 + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#bug-with-urls-like-asp + + + MISC + http://aluigi.altervista.org/adv/goahead-adv3.txt + + + OSVDB + 13295 + + GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1604 + 2002-09-02T00:00:00.000-04:00 + 2011-03-07T21:10:31.127-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#846307 + + + CERT-VN + VU#592515 + + + CERT-VN + VU#584243 + + + CERT-VN + VU#567963 + + + CERT-VN + VU#531355 + + + CERT-VN + VU#448987 + + + CERT-VN + VU#437899 + + + CERT-VN + VU#416427 + + + CERT-VN + VU#158499 + + + XF + tru64-multiple-binaries-bo(10016) + + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_nlspath.txt + + + BUGTRAQ + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + + BID + 5647 + + + HP + SSRT2275 + + Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1605 + 2002-09-02T00:00:00.000-04:00 + 2011-03-07T21:10:31.220-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#693803 + + + CERT-VN + VU#584243 + + + CERT-VN + VU#569987 + + + XF + tru64-multiple-binaries-bo(10016) + + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_xkb.txt + + + FULLDISC + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + + HP + SSRT2275 + + Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variable to (1) dxpause, (2) dxconsole, or (3) dtsession. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1606 + 2002-08-30T00:00:00.000-04:00 + 2011-03-07T21:10:31.313-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#965097 + + + CERT-VN + VU#955065 + + + CERT-VN + VU#651377 + + + CERT-VN + VU#557481 + + + CERT-VN + VU#293305 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2260 + + Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain privileges via (1) lpc, (2) lpd, (3) lpq, (4) lpr, or (5) lprm. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1607 + 2002-08-31T00:00:00.000-04:00 + 2011-03-07T21:10:31.393-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#706817 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2277 + + Buffer overflow in ypmatch in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1608 + 2002-08-31T00:00:00.000-04:00 + 2011-03-07T21:10:31.487-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#629289 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2261 + + Buffer overflow in traceroute in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1609 + 2002-08-30T00:00:00.000-04:00 + 2011-03-07T21:10:31.563-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#602009 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT0796U + + Buffer overflow in binmail in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1610 + 2002-08-30T00:00:00.000-04:00 + 2008-09-05T16:31:03.780-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + + CERT-VN + VU#612833 + + + HP + SSRT2229 + + + XF + tru64-ping-dos(10014) + + + BID + 5599 + + Unknown vulnerability in ping in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to cause a denial of service. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1611 + 2002-08-30T00:00:00.000-04:00 + 2011-03-07T21:10:31.737-05:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-09T00:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#115731 + + + CONFIRM + http://ftp.support.compaq.com.au/pub/patches/Digital_UNIX/v5.1a/patch_kit/Tru64_UNIX_V5.1A/doc/txt/OSFPAT00131500520.txt + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2191 + + Buffer overflow in quot in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1612 + 2002-09-13T00:00:00.000-04:00 + 2011-03-07T21:10:31.813-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:46:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#408771 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2193 + + + CONFIRM + http://ftp.support.compaq.com.au/pub/patches/Digital_UNIX/v5.1a/patch_kit/Tru64_UNIX_V5.1A/doc/txt/OSFPAT00131500520.txt + + Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1613 + 2002-09-10T00:00:00.000-04:00 + 2011-03-07T21:10:31.907-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:43:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#173977 + + + XF + tru64-multiple-binaries-bo(10016) + + + HP + SSRT2256 + + Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1614 + 2002-09-09T00:00:00.000-04:00 + 2011-03-07T21:10:32.000-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:34:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#435611 + + + XF + tru64-multiple-binaries-bo(10016) + + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + HP + SSRT2275 + + + BUGTRAQ + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at. + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.22 + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1615 + 2002-09-13T00:00:00.000-04:00 + 2008-09-05T16:31:04.623-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:28:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#506441 + + + XF + tru64-multiple-binaries-bo(10016) + + Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader. + + + + + + + + + + + + + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1af + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1616 + 2002-08-01T00:00:00.000-04:00 + 2011-03-07T21:10:32.187-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:25:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#193347 + + + CERT-VN + VU#671627 + + + CERT-VN + VU#177067 + + + CERT-VN + VU#137555 + + + XF + tru64-chfn-bo(10614) + + + BID + 5382 + + + BID + 5381 + + + BID + 5380 + + + XF + tru64-dxchpwd-bo(11620) + + + BID + 5379 + + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_su.txt + + + HP + SSRT2259 + + + FULLDISC + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc. + + + + + + + + + cpe:/o:hp:tru64:5.1b_pk2_bl22 + + CVE-2002-1617 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:10:37.470-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:17:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BUGTRAQ + 20020902 Happy Labor Day from Snosoft + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dxterm.txt + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtterm.txt + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtprintinfo.txt + + + MISC + http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtaction.txt + + + FULLDISC + 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification + + Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm. + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:11.04 + cpe:/a:hp:jfs:3.1 + + CVE-2002-1618 + 2002-10-16T00:00:00.000-04:00 + 2009-03-04T00:14:47.140-05:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T11:06:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + + CERT-VN + VU#248337 + + + XF + hp-onlinejfs-improper-security(10399) + + + BID + 5979 + + + HP + HPSBUX0210-223 + + + + + JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems. + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-1619 + 2002-03-08T00:00:00.000-05:00 + 2008-09-05T16:31:05.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-19T10:55:00.000-04:00 + + + + CERT-VN + VU#152955 + + + XF + aix-fc-client-bo(10127) + + + AIXAPAR + IY27310 + + Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump). + + + + + + + + + + + cpe:/a:ibm:aix_parallel_systems_support_programs:3.2 + cpe:/a:ibm:aix_parallel_systems_support_programs:3.4 + cpe:/a:ibm:aix_parallel_systems_support_programs:3.1.1 + + CVE-2002-1620 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:31:05.390-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-19T10:40:00.000-04:00 + + + + CERT-VN + VU#640827 + + + XF + aix-pssp-information-disclosure(10671) + + Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection. + + + + + + + + + + + + + cpe:/o:ibm:aix:4.3 + cpe:/o:ibm:aix:5.1 + cpe:/o:ibm:aix:4.3.1 + cpe:/o:ibm:aix:4.3.2 + cpe:/o:ibm:aix:4.3.3 + + CVE-2002-1621 + 2002-04-22T00:00:00.000-04:00 + 2008-09-05T16:31:05.547-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-19T10:14:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#209363 + + + CONFIRM + http://www.kb.cert.org/vuls/id/SVIM-59FJVF + + + AIXAPAR + IY28698 + + + AIXAPAR + IY26503 + + Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code. + + + + + + + + + cpe:/o:ibm:aix:4.3 + + CVE-2002-1622 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:05.700-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T22:30:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#273779 + + + XF + aix-rpc-datatype-bo(10112) + + + AIXAPAR + IY28706 + + Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type." + + + + + + + + + + cpe:/a:checkpoint:vpn-1_firewall-1:4.1 + cpe:/a:checkpoint:vpn-1_firewall-1:4.0 + + CVE-2002-1623 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:10:37.970-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-18T22:22:00.000-04:00 + + + + CERT-VN + VU#886601 + + + XF + fw1-ike-username-enumeration(10034) + + + BID + 5607 + + + BUGTRAQ + 20020903 SecuRemote usernames can be guessed or sniffed using IKE exchange + + + MISC + http://www.securiteam.com/securitynews/5TP040U8AW.html + + + MISC + http://www.nta-monitor.com/news/checkpoint.htm + + + CONFIRM + http://www.checkpoint.com/techsupport/alerts/ike.html + + + BUGTRAQ + 20020911 RE: SecuRemote usernames can be guessed or sniffed using IKE + + + BUGTRAQ + 20020905 RE: SecuRemote usernames can be guessed or sniffed using IKE exchange + + + FULLDISC + 20020903 Check Point statement on use of IKE Aggressive Mode + + The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ibm:lotus_domino:5.0.1 + cpe:/a:ibm:lotus_domino:5.0.2 + cpe:/a:ibm:lotus_domino:5.0.4::solaris + cpe:/a:ibm:lotus_domino:5.0.7a + cpe:/a:ibm:lotus_domino:5.0 + cpe:/a:ibm:lotus_domino:5.0.6a + cpe:/a:ibm:lotus_domino:5.0.7::solaris + cpe:/a:ibm:lotus_domino:5.0.9a + cpe:/a:ibm:lotus_domino:5.0.4a + cpe:/a:ibm:lotus_domino:5.0.6 + cpe:/a:ibm:lotus_domino:5.0.5 + cpe:/a:ibm:lotus_domino:5.0.3 + cpe:/a:ibm:lotus_domino:5.0.9 + cpe:/a:ibm:lotus_domino:5.0.8 + + CVE-2002-1624 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.013-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-18T22:09:00.000-04:00 + + + + CERT-VN + VU#772563 + + + BID + 6646 + + + XF + lotus-domino-authentication-bo(11058) + + + SECTRACK + 1004052 + + Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters. + + + + + + + + + cpe:/a:macromedia:flash_player:6.0 + + CVE-2002-1625 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.187-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-18T22:00:00.000-04:00 + + + + CERT-VN + VU#128491 + + + XF + flash-activex-plugin-dos(8925) + + + BID + 4567 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=22796&Method=Full&Title=Macromedia%20Flash%20Player%206%20Streaming%20Issue&Cache=False + + Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed. + + + + + + + + + + + + + cpe:/a:mike_spice:my_calendar:1.0 + cpe:/a:mike_spice:my_calendar:1.2 + cpe:/a:mike_spice:my_calendar:1.1 + cpe:/a:mike_spice:my_calendar:1.4 + cpe:/a:mike_spice:my_calendar:1.3 + + CVE-2002-1626 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.343-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-18T21:49:00.000-04:00 + + + + CERT-VN + VU#806091 + + + XF + mycalendar-gain-privileges(7966) + + + BID + 3856 + + + SECTRACK + 1003256 + + Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL. + + + + + + + + + cpe:/a:mike_spice:quiz_me:0.5 + + CVE-2002-1627 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.497-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-18T21:46:00.000-04:00 + + + + CERT-VN + VU#318835 + + + XF + quizme-gain-privileges(7970) + + + BID + 3857 + + + SECTRACK + 1003254 + + Directory traversal vulnerability in quiz.cgi for Mike Spice Quiz Me! before 0.6 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the quiz parameter. + + + + + + + + + + + cpe:/a:mike_spice:mikes_vote_cgi:1.2 + cpe:/a:mike_spice:mikes_vote_cgi:1.0 + cpe:/a:mike_spice:mikes_vote_cgi:1.1 + + CVE-2002-1628 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.637-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-18T21:43:00.000-04:00 + + + + CERT-VN + VU#250107 + + + XF + vote-cgi-gain-privileges(7971) + + + BID + 3854 + + Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type parameter. + + + + + + + + + + + + + cpe:/h:multi-tech:proxyserver:mtpsr2:201 + cpe:/h:multi-tech:proxyserver:mtpsr1:202st + cpe:/h:multi-tech:proxyserver:mtpsr3:200 + cpe:/h:multi-tech:proxyserver:mtpsr1:100 + cpe:/h:multi-tech:proxyserver:mtpsr1:120 + + CVE-2002-1629 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.797-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-18T21:36:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#495705 + + + BID + 7203 + + + BUGTRAQ + 20021210 MTPSR1-120 Firewall Proxy configuration software + + + XF + proxyserver-mtpsr1120-telnet-access(10845) + + Multi-Tech ProxyServer products MTPSR1-100, MTPSR1-120, MTPSR1-202ST, MTPSR2-201, and MTPSR3-200 ship with a null password, which allows remote attackers to gain administrative privileges via Telnet or HTTP. + + + + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:application_server:9.0.2.0.0 + cpe:/a:oracle:application_server:9.0.2.0.1 + + CVE-2002-1630 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:06.950-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T20:12:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#717827 + + + CONFIRM + http://www.kb.cert.org/vuls/id/SVIM-576QLZ + + + XF + oracle-appserver-sendmail-sample(8664) + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BID + 6556 + + + CONFIRM + http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf + + The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails. + + + + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:application_server:9.0.2.0.0 + cpe:/a:oracle:application_server:9.0.2.0.1 + + CVE-2002-1631 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T20:03:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#717827 + + + CONFIRM + http://www.kb.cert.org/vuls/id/SVIM-576QLZ + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BID + 6556 + + + CONFIRM + http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf + + SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter. + + + + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:application_server:1.0.2 + cpe:/a:oracle:application_server:9.0.2.0.0 + cpe:/a:oracle:application_server:9.0.2.0.1 + + CVE-2002-1632 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.263-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-18T19:56:00.000-04:00 + + + + CONFIRM + http://www.kb.cert.org/vuls/id/SVIM-576QLZ + + + CERT-VN + VU#717827 + + + XF + oracle-appserver-info-sample(8665) + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + + BID + 6556 + + + CONFIRM + http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf + + Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2. + + + + + + + + + cpe:/a:qnx:qnx_rtos:4.25 + + CVE-2002-1633 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.420-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T19:44:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#879386 + + + XF + qnx-rtos-bin-bo(9341) + + + BID + 5000 + + + BUGTRAQ + 20020612 madcr: QnX 4.25 - multiples bof in suid/no suid files + + Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) termdef, (11) time, (12) unzip, (13) use, (14) wcc, (15) wcc386, (16) wd, (17) wdisasm, (18) which, (19) wlib, (20) wlink, (21) wpp, (22) wpp386, (23) wprof, (24) write, or (25) wstrip. + + + + + + + + + + cpe:/o:novell:netware:5.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-1634 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.560-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-18T19:33:00.000-04:00 + + + + CERT-VN + VU#159203 + + + MISC + http://www.securityfocus.com/advisories/4158 + + + MISC + http://www.securityfocus.com/advisories/4157 + + + CONFIRM + http://support.novell.com/cgi-bin/search/searchtid.cgi?/10064452.htm + + + XF + netware-sample-information-disclosure(9212) + + + BID + 4874 + + + OSVDB + 17468 + + + OSVDB + 17467 + + + OSVDB + 17466 + + + OSVDB + 17465 + + + OSVDB + 17464 + + + OSVDB + 17463 + + + OSVDB + 17462 + + + OSVDB + 17461 + + Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl. + + + + + + + + + cpe:/a:oracle:application_server + + CVE-2002-1635 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-18T19:18:00.000-04:00 + + + + CERT-VN + VU#936507 + + + XF + oracle-perl-cgi-source(10716) + + The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin. + + + + + + + + + cpe:/a:oracle:application_server:1.0.2 + + CVE-2002-1636 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:07.857-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-18T16:04:00.000-04:00 + + + + XF + oracle-htpprint-xss(10687) + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print. + + + + + + + + + cpe:/a:oracle:application_server + + CVE-2002-1637 + 2002-02-26T00:00:00.000-05:00 + 2008-09-05T16:31:08.013-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T15:41:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#712723 + + + XF + default-oracle-applsys(972) + + + XF + default-oracle-apps(971) + + + XF + default-oracle-scott(970) + + + XF + default-oracle-sys(969) + + + XF + default-oracle-system(968) + + + MISC + http://www.nextgenss.com/papers/hpoas.pdf + + Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges. + + + CVE-2002-1638 + 2002-05-27T00:00:00.000-04:00 + 2008-09-10T15:15:08.883-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-2153. Reason: This candidate is a duplicate of CVE-2002-2153. Notes: All CVE users should reference CVE-2002-2153 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + cpe:/a:oracle:configurator:11.5.7.17.31 + cpe:/a:oracle:configurator:11i + cpe:/a:oracle:configurator:11.5.6.16.53 + + CVE-2002-1639 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:31:08.310-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T15:22:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#158323 + + + CONFIRM + http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html + + + SECTRACK + 1003967 + + + XF + oracle-configurator-uiservlet-information(8782) + + + BID + 4433 + + Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host". + + + + + + + + + + + cpe:/a:oracle:configurator:11.5.7.17.31 + cpe:/a:oracle:configurator:11i + cpe:/a:oracle:configurator:11.5.6.16.52 + + CVE-2002-1640 + 2002-04-01T00:00:00.000-05:00 + 2008-09-05T16:31:08.467-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T15:06:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CONFIRM + http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html + + + SECTRACK + 1003967 + + + XF + oracle-configurator-uiservlet-css(8781) + + + XF + oracle-configurator-dhtml-css(8780) + + + BID + 4436 + + + BID + 4430 + + Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet. + + + + + + + + + + + + cpe:/a:oracle:application_server_web_cache:2.0.0.2 + cpe:/a:oracle:application_server_web_cache:2.0.0.3 + cpe:/a:oracle:application_server_web_cache:2.0.0.0 + cpe:/a:oracle:application_server_web_cache:2.0.0.1 + + CVE-2002-1641 + 2002-05-27T00:00:00.000-04:00 + 2008-09-05T16:31:08.607-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-18T14:55:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#291555 + + + BID + 4856 + + Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors. + + + + + + + + + + + cpe:/a:postgresql:postgresql:7.2.2 + cpe:/a:postgresql:postgresql:7.2.1 + cpe:/a:postgresql:postgresql:7.2 + + CVE-2002-1642 + 2002-10-03T00:00:00.000-04:00 + 2008-09-05T16:31:08.763-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-18T14:42:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#891177 + + + BID + 7657 + + + MLIST + [pgsql-announce] 20021003 v7.2.3 Released to fix Potentially Critical Bug + + + XF + postgresql-vacuum-delete-pcclog(11102) + + + REDHAT + RHSA-2003:001 + + PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. + + + + + + + + + + cpe:/a:realnetworks:helix_universal_server:9.0.2.768 + cpe:/a:realnetworks:helix_universal_server:9.0 + + CVE-2002-1643 + 2002-12-19T00:00:00.000-05:00 + 2008-09-05T16:31:08.920-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-18T14:21:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#974689 + + + CONFIRM + http://www.service.real.com/help/faq/security/bufferoverrun12192002.html + + + BID + 6458 + + + BID + 6456 + + + BID + 6454 + + + XF + helix-http-get-bo(10917) + + + XF + helix-rtsp-describe-bo(10916) + + + XF + helix-rtsp-setup-bo(10915) + + + BUGTRAQ + 20021220 RealNetworks HELIX Server Buffer Overflow Vulnerabilities (#NISR20122002) + + + MISC + http://www.nextgenss.com/advisories/realhelix.txt + + Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RSTP request, (2) a DESCRIBE RSTP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh2:3.2.1 + cpe:/a:ssh:ssh2:3.1 + cpe:/a:ssh:ssh2:3.2 + cpe:/a:ssh:ssh2:2.1 + cpe:/a:ssh:ssh2:2.2 + cpe:/a:ssh:ssh2:2.3 + cpe:/a:ssh:ssh2:3.1.1 + cpe:/a:ssh:ssh2:2.4 + cpe:/a:ssh:ssh2:3.0 + cpe:/a:ssh:ssh2:2.5 + cpe:/a:ssh:ssh2:2.0.13 + cpe:/a:ssh:ssh2:3.1.3 + cpe:/a:ssh:ssh2:3.0.1 + cpe:/a:ssh:ssh2:3.1.2 + cpe:/a:ssh:ssh2:3.1.4 + + CVE-2002-1644 + 2002-11-25T00:00:00.000-05:00 + 2008-09-05T16:31:09.077-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-18T14:08:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#740619 + + + CONFIRM + http://www.ssh.com/company/newsroom/article/286/ + + + BID + 6247 + + + XF + ssh-setsid-privilege-elevation(10710) + + SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges. + + + + + + + + + + + + + + cpe:/a:ssh:ssh2:3.1 + cpe:/a:ssh:ssh2:3.2 + cpe:/a:ssh:ssh2:3.1.1 + cpe:/a:ssh:ssh2:3.1.3 + cpe:/a:ssh:ssh2:3.1.2 + cpe:/a:ssh:ssh2:3.1.4 + + CVE-2002-1645 + 2002-11-25T00:00:00.000-05:00 + 2008-09-05T16:31:09.247-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-18T13:51:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CERT-VN + VU#140977 + + + CONFIRM + http://www.ssh.com/company/newsroom/article/287/ + + + BID + 6263 + + + XF + ssh-client-url-bo(10723) + + Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL. + + + + + + + + + + + + cpe:/a:ssh:secure_shell_for_servers:3.1 + cpe:/a:ssh:secure_shell_for_servers:3.0 + cpe:/a:ssh:secure_shell_for_servers:3.0.1 + cpe:/a:ssh:secure_shell_for_servers:3.1.1 + + CVE-2002-1646 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:09.403-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T21:12:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#341187 + + + XF + ssh-allowedauthentications-bypass-auth(9163) + + + CONFIRM + http://www.ssh.com/products/ssh/advisories/authentication.cfm + + + BID + 4810 + + + BUGTRAQ + 20020523 [Fwd: Updated version of SSH Secure Shell available] + + + CIAC + M-081 + + + CONFIRM + http://www.ssh.com/company/newsroom/article/201/ + + SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server. + + + + + + + + + cpe:/a:slashcode.com:slash + + CVE-2002-1647 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:09.560-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-17T20:43:00.000-04:00 + + + + CERT-VN + VU#603945 + + + BUGTRAQ + 20020917 Re: slashdot / slashcode disclosing passwords + + + BUGTRAQ + 20020911 Re: slashdot / slashcode disclosing passwords + + + BUGTRAQ + 20020911 slashdot / slashcode disclosing passwords + + The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL. + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.2 + + CVE-2002-1648 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:09.717-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T20:36:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#153043 + + + XF + squirrelmail-html-execute-script(7989) + + + BID + 3956 + + + BUGTRAQ + 20020124 Vulnerabilities in squirrelmail + + Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters. + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.2 + + CVE-2002-1649 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:09.857-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-17T20:30:00.000-04:00 + + + + CERT-VN + VU#153043 + + + XF + squirrelmail-html-execute-script(7989) + + + BID + 3956 + + + BUGTRAQ + 20020124 Vulnerabilities in squirrelmail + + Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary Javascript via a javascript: URL in an IMG tag. + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.2 + + CVE-2002-1650 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.013-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T20:12:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + squirrelmail-spellchecker-command-execution(7990) + + + BUGTRAQ + 20020124 Re: squirrelmail bug + + + BUGTRAQ + 20020124 squirrelmail bug + + The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter. + + + + + + + + + cpe:/a:verity:search97:2.1 + + CVE-2002-1651 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.153-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-17T20:01:00.000-04:00 + + + + + CERT-VN + VU#636431 + + + XF + verity-search97-xss(9441) + + + BID + 5102 + + Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions. + + + + + + + + + cpe:/a:mit:cgiemail:1.6 + + CVE-2002-1652 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:11.523-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T17:34:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#185251 + + + XF + cgiemail-cgicso-get-bo(10595) + + + BID + 6141 + + + MISC + http://www.securiteam.com/exploits/5TP0W005FE.html + + + SECTRACK + 1002395 + + Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter. + + + + + + + + + cpe:/a:farm9:cryptcat:1.10 + + CVE-2002-1653 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.450-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-17T17:26:00.000-04:00 + + + + CERT-VN + VU#165099 + + + BID + 8431 + + + XF + cryptcat-e-no-encryption(10618) + + Farm9 Cryptcat, when started in server mode with the -e option, does not enable encryption, which allows clients to communicate without encryption despite intended configuration, and may allow remote attackers to sniff sensitive information. + + + + + + + + + + + + + + + + + + + cpe:/a:iplanet:iplanet_web_server:6.0 + cpe:/a:netscape:enterprise_server:3.0 + cpe:/a:iplanet:iplanet_web_server:enterprise_4.1 + cpe:/a:iplanet:iplanet_web_server:enterprise_4.0 + cpe:/a:netscape:enterprise_server:3.6 + cpe:/a:netscape:enterprise_server:3.5 + cpe:/a:netscape:enterprise_server:3.2 + cpe:/a:netscape:enterprise_server:2.0 + cpe:/a:netscape:enterprise_server:3.1 + cpe:/a:netscape:enterprise_server:3.4 + cpe:/a:netscape:enterprise_server:3.3 + + CVE-2002-1654 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.590-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T17:15:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#985347 + + + XF + netscape-enterprise-http-brute-force(7845) + + + BID + 3831 + + + MISC + http://www.securiteam.com/securitynews/5IP0G0060Q.html + + + SECTRACK + 1003157 + + + VULNWATCH + 20020109 Netscape publishing wp-force-auth command + + + CONFIRM + http://www.kb.cert.org/vuls/id/AAMN-567NFX + + iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection. + + + + + + + + + + + + + + + + + cpe:/a:netscape:enterprise_server:3.0 + cpe:/a:iplanet:iplanet_web_server:enterprise_4.1 + cpe:/a:iplanet:iplanet_web_server:enterprise_4.0 + cpe:/a:netscape:enterprise_server:3.6 + cpe:/a:netscape:enterprise_server:3.5 + cpe:/a:netscape:enterprise_server:3.2 + cpe:/a:netscape:enterprise_server:3.1 + cpe:/a:netscape:enterprise_server:3.4 + cpe:/a:netscape:enterprise_server:3.3 + + CVE-2002-1655 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.763-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-17T17:02:00.000-04:00 + + + + CERT-VN + VU#191763 + + + BID + 3826 + + + VULNWATCH + 20020109 Netscape ?wp-html-rend denial of service attack + + + XF + netscape-enterprise-invalid-command-dos(7842) + + + CONFIRM + http://www.kb.cert.org/vuls/id/AAMN-567N48 + + The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request. + + + + + + + + + + cpe:/a:xqus:x-news:1.0 + cpe:/a:xqus:x-news:1.1 + + CVE-2002-1656 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:10.937-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T16:44:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#162723 + + + XF + xnews-users-world-readable(8465) + + + BID + 4283 + + + MISC + http://www.ifrance.com/kitetoua/tuto/x_holes.txt + + + SECTRACK + 1003828 + + X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie. + + + + + + + + + cpe:/a:postgresql:postgresql:7.3.19 + + CVE-2002-1657 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:11.077-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-05-17T16:35:00.000-04:00 + + + + BUGTRAQ + 20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords + + + BUGTRAQ + 20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords + + + MLIST + [pgsql-admin] 20020821 Re: OT: password encryption (salt theory) + + PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:apache:http_server:1.3.27 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:http_server:1.3.6 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.4 + cpe:/a:apache:http_server:1.3.3 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3.19 + + CVE-2002-1658 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:11.233-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-17T16:16:00.000-04:00 + + + + BUGTRAQ + 20021016 Apache 1.3.26 + + + MISC + https://sardonix.org/audit/apache-45.html + + + XF + apache-htdigest-bo(10414) + + + BID + 5993 + + Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability. + + + + + + + + + cpe:/a:iatek:portalapp:2.2 + + CVE-2002-1659 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:11.420-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-05-11T14:50:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + portalapp-user-privilege-elevation(10558) + + + SECTRACK + 1005541 + + user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable. + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.1.9 + + CVE-2002-1660 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:11.560-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-11T14:42:00.000-04:00 + + + + + SECTRACK + 1005284 + + + XF + vbulletin-calendar-command-execution(10176) + + + BID + 5820 + + + MISC + http://www.securiteam.com/exploits/5QP0P158AC.html + + calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter. + + + + + + + + + + + + + + + + + + cpe:/a:leafnode:leafnode:1.9.20 + cpe:/a:leafnode:leafnode:1.9.21 + cpe:/a:leafnode:leafnode:1.9.22 + cpe:/a:leafnode:leafnode:1.9.23 + cpe:/a:leafnode:leafnode:1.9.24 + cpe:/a:leafnode:leafnode:1.9.25 + cpe:/a:leafnode:leafnode:1.9.26 + cpe:/a:leafnode:leafnode:1.9.27 + cpe:/a:leafnode:leafnode:1.9.29 + cpe:/a:leafnode:leafnode:1.9.19 + + CVE-2002-1661 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:17.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-11T14:39:00.000-04:00 + + + + BID + 6490 + + + CONFIRM + http://leafnode.sourceforge.net/leafnode-SA-2002-01.txt + + + XF + leafnode-nntp-dos(10942) + + + SECTRACK + 1005865 + + + MANDRAKE + MDKSA-2003:005 + + + BUGTRAQ + 20030102 GLSA: leafnode + + + BUGTRAQ + 20021229 Leafnode security announcement SA:2002:01 + + The leafnode server in leafnode 1.9.20 to 1.9.29 allows remote attackers to cause a denial of service (infinite loop) when leafnode requests a cross-posted article to one group whose name is a prefix of another group. + + + + + + + + + cpe:/a:mambo:mambo_site_server:4.0.11 + + CVE-2002-1662 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:11.903-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-20T01:31:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6386 + + + XF + mambo-name-field-xss(10859) + + + XF + mambo-search-xss(10854) + + + BUGTRAQ + 20021212 Multiple Mambo Site Server sec-weaknesses + + Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration. + + + + + + + + + cpe:/a:monkey-project:monkey_http_daemon:0.1.1 + + CVE-2002-1663 + 2002-12-31T00:00:00.000-05:00 + 2012-10-24T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-05-20T01:17:00.000-04:00 + + + + + BID + 6096 + + + SECTRACK + 1005507 + + + XF + monkey-http-post-dos(10529) + + + CONFIRM + http://monkeyd.sourceforge.net/Changelog.txt + + + BUGTRAQ + 20021103 Bug in Monkey Webserver 0.5.0 or minors versions + + The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-1664 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.233-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-05-30T16:22:00.000-04:00 + + + + CERT + CA-2002-16 + + + CERT-VN + VU#393195 + + + BUGTRAQ + 20020221 Remote crashes in Yahoo messenger + + Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. + + + + + + + + + cpe:/a:yahoo:messenger:5.0 + + CVE-2002-1665 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.373-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-05-30T16:17:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CERT + CA-2002-16 + + + CERT-VN + VU#755755 + + + BUGTRAQ + 20020221 Remote crashes in Yahoo messenger + + Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field. + + + + + + + + + + + + + + cpe:/a:oracle:e-business_suite:11.1 + cpe:/a:oracle:e-business_suite:11.2 + cpe:/a:oracle:e-business_suite:11.5 + cpe:/a:oracle:e-business_suite:11.6 + cpe:/a:oracle:e-business_suite:11.3 + cpe:/a:oracle:e-business_suite:11.4 + + CVE-2002-1666 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.513-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T08:55:00.000-04:00 + + + + XF + oracle-ebiz-execute-procedures(8897) + + + BID + 4551 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/apps_alert_ebiz2.pdf + + Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL. + + + + + + + + + + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.5:stable + + CVE-2002-1667 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.687-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-01T08:43:00.000-04:00 + + + + XF + freebsd-mmap-msync-dos(8921) + + + FREEBSD + FreeBSD-SA-02:22 + + The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed memory map created with MAP_ANON and MAP_NOSYNC flags. + + + + + + + + + + + + + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux_series_800:10.20 + cpe:/o:hp:hp-ux_series_700:10.20 + cpe:/o:hp:hp-ux:11.0.4 + + CVE-2002-1668 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.827-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-01T09:27:00.000-04:00 + + + + XF + hp-mmap-dos(7844) + + + BID + 3817 + + + HP + HPSBUX0201-178 + + HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file. + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.4 + + CVE-2002-1669 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:12.983-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T09:29:00.000-04:00 + + + + XF + freebsd-pkgadd-insecure-directory(7852) + + + BID + 3819 + + + FREEBSD + FreeBSD-SA-02:01 + + pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1670 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.153-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-01T09:56:00.000-04:00 + + + + XF + winxp-ie-patch-rollback(7922) + + + BID + 3887 + + Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.01 + + CVE-2002-1671 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.310-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T10:01:00.000-04:00 + + + + XF + ie-clipboarddata-view-clipboard(7906) + + + BID + 3862 + + Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object. + + + + + + + + + + cpe:/a:webmin:webmin:0.92.1 + cpe:/a:webmin:webmin:0.92 + + CVE-2002-1672 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.467-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T10:03:00.000-04:00 + + + + XF + webmin-directory-permissions(8595) + + + BID + 4328 + + + CONFIRM + http://www.webmin.com/changes.html + + Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.92.1 + cpe:/a:webmin:webmin:0.1 + cpe:/a:webmin:webmin:0.76 + cpe:/a:webmin:webmin:0.78 + cpe:/a:webmin:webmin:0.88 + cpe:/a:webmin:webmin:0.77 + cpe:/a:webmin:webmin:0.79 + cpe:/a:webmin:webmin:0.42 + cpe:/a:webmin:webmin:0.92 + cpe:/a:webmin:webmin:0.7 + cpe:/a:webmin:webmin:0.22 + cpe:/a:webmin:webmin:0.31 + cpe:/a:webmin:webmin:0.41 + cpe:/a:webmin:webmin:0.91 + cpe:/a:webmin:webmin:0.6 + cpe:/a:webmin:webmin:0.80 + cpe:/a:webmin:webmin:0.21 + cpe:/a:webmin:webmin:0.51 + cpe:/a:webmin:webmin:0.83 + cpe:/a:webmin:webmin:0.3 + cpe:/a:webmin:webmin:0.2 + cpe:/a:webmin:webmin:0.85 + cpe:/a:webmin:webmin:0.5 + cpe:/a:webmin:webmin:0.84 + cpe:/a:webmin:webmin:0.4 + + CVE-2002-1673 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.623-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T10:34:00.000-04:00 + + + + XF + webmin-functions-execute-code(8596) + + + BID + 4329 + + The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name entry in the passwd file. + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1 + + CVE-2002-1674 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.827-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-01T10:38:00.000-04:00 + + + + XF + bsd-fstatfs-dos(8112) + + + BID + 4040 + + + FREEBSD + FreeBSD-SA-02:09 + + procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to. + + + + + + + + + cpe:/a:unreal:unrealircd:3.1.1 + + CVE-2002-1675 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:13.997-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-01T10:41:00.000-04:00 + + + + XF + unreal-ircd-format-string(8360) + + + MISC + http://www.securiteam.com/unixfocus/5MP080A6LQ.html + + + VULN-DEV + 20020225 Unreal ircd Format String Vuln + + Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers. + + + + + + + + + + cpe:/a:bindview:netrc:1.0 + cpe:/a:bindview:netinventory:1.0 + + CVE-2002-1676 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.137-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T10:47:00.000-04:00 + + + + XF + bindview-netinventory-plaintext-password(7992) + + + BID + 3957 + + BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete. + + + + + + + + + cpe:/a:mrtg:mrtgconfig:0.5.9 + + CVE-2002-1677 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.293-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T10:51:00.000-04:00 + + + + XF + mrtg-14allcgi-path-disclosure(8070) + + + BID + 4021 + + + BUGTRAQ + 20020204 Re: Mrtg Path Disclosure Vulnerability + + 14all.cgi 1.1p15 in mrtgconfig allows remote attackers to determine the physical path to the web root directory via a request with an invalid cfg parameter, which generates an error message that reveals the path. + + + + + + + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.2.2 + cpe:/a:jelsoft:vbulletin:2.2.3 + cpe:/a:jelsoft:vbulletin:2.2.0 + cpe:/a:jelsoft:vbulletin:2.2.1 + cpe:/a:jelsoft:vbulletin:2.0_rc2 + cpe:/a:jelsoft:vbulletin:2.0_rc3 + cpe:/a:jelsoft:vbulletin:2.2.4 + + CVE-2002-1678 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.437-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T11:03:00.000-04:00 + + + + XF + vbulletin-memberlist-execute-code(8619) + + + BID + 4349 + + Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits. + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.2.0 + + CVE-2002-1679 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.607-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T11:13:00.000-04:00 + + + + XF + vbulletin-bbs-css(8039) + + + BID + 4008 + + Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execute arbitrary script as other users by injecting script into a bulletin board message. + + + + + + + + + cpe:/a:cows:cgi_online_worldweb_shopping:1.1 + + CVE-2002-1680 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.747-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T11:16:00.000-04:00 + + + + XF + cows-cgi-css(7986) + + + BID + 3921 + + + BID + 3914 + + Cross-site scripting (XSS) vulnerability in CGI Online Worldweb Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute arbitrary script as other users by injecting script into (1) diagnose.cgi or (2) compatible.cgi. + + + + + + + + + + + + + cpe:/a:open_source_development_network:slashcode:2.2.1 + cpe:/a:open_source_development_network:slashcode:2.2.2 + cpe:/a:open_source_development_network:slashcode:2.2.5 + cpe:/a:open_source_development_network:slashcode:2.2.4 + cpe:/a:open_source_development_network:slashcode:2.2.3 + + CVE-2002-1681 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:14.903-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-01T11:18:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + slashcode-cvs-xss(9473) + + + BID + 5140 + + Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag. + + + + + + + + + cpe:/a:daansystems:newsreactor:1.0 + + CVE-2002-1682 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.060-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T11:22:00.000-04:00 + + + + XF + newsreactor-insecure-password(7968) + + + BID + 3927 + + + MISC + http://www.securiteam.com/windowsntfocus/5SP0P0K60C.html + + NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:personal_1.7.3 + + CVE-2002-1683 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.217-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T11:21:00.000-04:00 + + + + XF + badblue-cleansearchstring-xss(9514) + + + BID + 5179 + + Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function. + + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:personal_1.5.6_beta + cpe:/a:working_resources_inc.:badblue:enterprise_1.5 + cpe:/a:deerfield:d2gfx:1.0.2 + + CVE-2002-1684 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.373-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T11:42:00.000-04:00 + + + + XF + badblue-msoffice-script-directory-traversal(7946) + + + BID + 3913 + + Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents. + + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:personal_1.7.2 + cpe:/a:working_resources_inc.:badblue:personal_1.7 + cpe:/a:working_resources_inc.:badblue:enterprise_1.7.2 + + CVE-2002-1685 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.530-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T11:45:00.000-04:00 + + + + XF + badblue-extdll-xss(9513) + + + BID + 5086 + + Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1686 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.687-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-01T11:56:00.000-04:00 + + + + AIXAPAR + IY27855 + + Buffer overflow in lscfg of unknown versions of AIX has unknown impact. + + + + + + + + + cpe:/o:ibm:aix + + CVE-2002-1687 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.827-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T11:58:00.000-04:00 + + + + AIXAPAR + IY27740 + + Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1688 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:15.983-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T12:03:00.000-04:00 + + + + XF + ie-history-javascript-urls(8844) + + + BID + 4505 + + The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button. + + + + + + + + + cpe:/o:ibm:aix:3.2.5 + + CVE-2002-1689 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:16.137-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-01T12:11:00.000-04:00 + + + + AIXAPAR + IY27778 + + Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. + + + + + + + + + cpe:/o:ibm:aix:3.2.5 + + CVE-2002-1690 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:16.280-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-01T12:12:00.000-04:00 + + + + AIXAPAR + IY28225 + + Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225. + + + + + + + + + cpe:/a:alcatel-lucent:omnipcx:4400 + + CVE-2002-1691 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:20.040-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-01T12:14:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + omnipcx-default-user-accounts(8224) + + + BID + 4127 + + + BUGTRAQ + 20020219 Security BugWare : Alcatel 4400 PBX hack + + Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. + + + + + + + + + + cpe:/o:microsoft:windows_95 + cpe:/o:microsoft:windows_95::sr2 + + CVE-2002-1692 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:16.590-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-01T12:17:00.000-04:00 + + + + XF + win95-backup-bo(7892) + + + MISC + http://www.securitytracker.com/alerts/2002/Jan/1003201.html + + + BID + 3864 + + Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:internet_information_server:4.0::symantec + + CVE-2002-1694 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:16.733-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T12:43:00.000-04:00 + + + + XF + iis-modify-log(7919) + + + BID + 3888 + + Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running. + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:symantec:norton_internet_security:2001 + + CVE-2002-1695 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:16.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T12:47:00.000-04:00 + + + + XF + iis-modify-log(7919) + + + BID + 3888 + + Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running. + + + + + + + + + + + + cpe:/a:pgp:pgp:7.0.3 + cpe:/a:pgp:pgp:7.0 + cpe:/a:pgp:pgp:7.0.4 + cpe:/a:microsoft:outlook:98 + + CVE-2002-1696 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:17.043-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T12:53:00.000-04:00 + + + + XF + pgp-outlook-decrypted-copy(7900) + + + BID + 3825 + + Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message. + + + + + + + + + + + + + + cpe:/a:vtun:vtun:2.0 + cpe:/a:vtun:vtun:2.1 + cpe:/a:vtun:vtun:2.2 + cpe:/a:vtun:vtun:2.3 + cpe:/a:vtun:vtun:2.4 + cpe:/a:vtun:vtun:2.5_b1 + + CVE-2002-1697 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:20.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-01T12:56:00.000-04:00 + + + + XF + vtun-ecb-weak-encryption(7904) + + + BID + 3845 + + + BUGTRAQ + 20020109 Security weaknesses of VTun + + Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain senstive information. + + + + + + + + + + + + + + + + cpe:/a:microsoft:msn_messenger:2.0 + cpe:/a:microsoft:msn_messenger:3.0 + cpe:/a:microsoft:msn_messenger:4.0 + cpe:/a:microsoft:msn_messenger:3.6 + cpe:/a:microsoft:msn_messenger:1.0 + cpe:/a:microsoft:msn_messenger:4.5 + cpe:/a:microsoft:msn_messenger:2.2 + cpe:/a:microsoft:msn_messenger:4.6 + + CVE-2002-1698 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:17.357-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-01T12:59:00.000-04:00 + + + + XF + msn-font-header-bo(9014) + + + BID + 4675 + + Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header. + + + + + + + + + + cpe:/a:pascal_michaud:asp_client_check:1.5 + cpe:/a:pascal_michaud:asp_client_check:1.3 + + CVE-2002-1699 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:17.527-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-01T13:11:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + aspcc-sql-injection(9015) + + + BID + 4676 + + + MISC + http://www.securiteam.com/windowsntfocus/5BP031P75C.html + + + OSVDB + 21558 + + SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field. + + + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:macromedia:coldfusion:6.0 + cpe:/o:microsoft:windows_2000 + + CVE-2002-1700 + 2002-12-31T00:00:00.000-05:00 + 2014-04-15T09:57:35.867-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T09:15:00.000-04:00 + + + + + XF + coldfusion-missing-template-css(9360) + + + BID + 5011 + + Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message. + + + + + + + + + cpe:/a:deltascripts:php_classifieds:6.0.5 + + CVE-2002-1702 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:17.827-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T13:23:00.000-04:00 + + + + XF + phpclassifieds-parameters-css(9363) + + + BID + 5022 + + Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter. + + + + + + + + + cpe:/a:mewsoft:netauction:3.0 + + CVE-2002-1703 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:17.950-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-01T13:26:00.000-04:00 + + + + XF + netauction-parameters-css(9365) + + + BID + 5023 + + Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter. + + + + + + + + + cpe:/a:zeroboard:zeroboard:4.1_pl2 + + CVE-2002-1704 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.107-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T13:28:00.000-04:00 + + + + XF + zeroboard-include-remote-file(9366) + + + BID + 5028 + + Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code. + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1705 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-01T13:35:00.000-04:00 + + + + XF + ie-css-bold-dos(9367) + + + BID + 5027 + + Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:11.3t + cpe:/o:cisco:ios:11.3xa + cpe:/o:cisco:ios:12.2xf + cpe:/o:cisco:ios:11.3na + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:12.0t + cpe:/o:cisco:ios:12.1t + cpe:/o:cisco:ios:12.2t + cpe:/o:cisco:ios:12.2bc + cpe:/o:cisco:ios:12.0sc + cpe:/o:cisco:ios:12.0xr + cpe:/o:cisco:ios:12.1ec + cpe:/o:cisco:ios:12.1cx + + CVE-2002-1706 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.420-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T13:53:00.000-04:00 + + + + XF + cisco-ubr-mic-bypass(9368) + + + BID + 5041 + + + CISCO + 20020617 Cable Modem Termination System Authentication Bypass + + Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router. + + + + + + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0.1 + cpe:/a:phpbb_group:phpbb:2.0.0 + cpe:/a:phpbb_group:phpbb:2.0_rc4 + cpe:/a:phpbb_group:phpbb:2.0_rc2 + cpe:/a:phpbb_group:phpbb:2.0_rc3 + cpe:/a:phpbb_group:phpbb:2.0_rc1 + + CVE-2002-1707 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-01T13:59:00.000-04:00 + + + + XF + phpbb-include-remote-files(9370) + + + BID + 5038 + + install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code. + + + + + + + + + cpe:/a:basilix:basilix_webmail:1.1.0 + + CVE-2002-1708 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.747-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T08:19:00.000-04:00 + + + + XF + basilix-webmail-headers-css(9384) + + + BID + 5060 + + + VULNWATCH + 20020619 [VulnWatch] BasiliX multiple vulnerabilities + + Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields. + + + + + + + + + cpe:/a:basilix:basilix_webmail:1.1.0 + + CVE-2002-1709 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:18.887-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T08:21:00.000-04:00 + + + + XF + basilix-webmail-sql-injection(9385) + + + BID + 5061 + + + VULNWATCH + 20020619 [VulnWatch] BasiliX multiple vulnerabilities + + SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable. + + + + + + + + + cpe:/a:basilix:basilix_webmail:1.1.0 + + CVE-2002-1710 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:21.773-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T08:29:00.000-04:00 + + + + XF + basilix-webmail-attach-files(9386) + + + BID + 5062 + + + VULNWATCH + 20020619 [VulnWatch] BasiliX multiple vulnerabilities + + + BUGTRAQ + 20020618 BasiliX multiple vulnerabilities + + The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file. + + + + + + + + + cpe:/a:basilix:basilix_webmail:1.1.0 + + CVE-2002-1711 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:19.187-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T08:31:00.000-04:00 + + + + XF + basilix-webmail-view-attachments(9387) + + + BID + 5065 + + + VULNWATCH + 20020619 [VulnWatch] BasiliX multiple vulnerabilities + + BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + + CVE-2002-1712 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:19.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-05T08:40:00.000-04:00 + + + + XF + win2k-empty-tcp-dos(8037) + + + BID + 3967 + + + MSKB + Q280446 + + Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3. + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:8.2 + + CVE-2002-1713 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:19.560-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T08:48:00.000-04:00 + + + + CERT-VN + VU#455323 + + + XF + mandrake-msec-home-permissions(9389) + + + BID + 5050 + + The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files. + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1714 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:19.700-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-05T08:55:00.000-04:00 + + + + XF + ie-object-directive-dos(8904) + + + BID + 4564 + + Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ssh:ssh:1.2.3 + cpe:/a:ssh:ssh:1.2.4 + cpe:/a:ssh:ssh:1.2.1 + cpe:/a:ssh:ssh:1.2.2 + cpe:/a:ssh:ssh:1.2.7 + cpe:/a:ssh:ssh:1.2.8 + cpe:/a:ssh:ssh:1.2.19 + cpe:/a:ssh:ssh:1.2.5 + cpe:/a:ssh:ssh:1.2.18 + cpe:/a:ssh:ssh:1.2.6 + cpe:/a:ssh:ssh2:2.0.9 + cpe:/a:ssh:ssh2:2.0.8 + cpe:/a:ssh:ssh:1.2.0 + cpe:/a:ssh:ssh2:2.0.1 + cpe:/a:ssh:ssh2:2.0.2 + cpe:/a:ssh:ssh2:2.0.3 + cpe:/a:ssh:ssh2:2.0.4 + cpe:/a:ssh:ssh2:2.0.5 + cpe:/a:ssh:ssh2:2.0.6 + cpe:/a:ssh:ssh2:2.0.7 + cpe:/a:ssh:ssh:1.2.16 + cpe:/a:ssh:ssh:1.2.17 + cpe:/a:ssh:ssh:1.2.14 + cpe:/a:ssh:ssh:1.2.15 + cpe:/a:ssh:ssh:1.2.9 + cpe:/a:ssh:ssh:1.2.12 + cpe:/a:ssh:ssh:1.2.13 + cpe:/a:ssh:ssh:1.2.10 + cpe:/a:ssh:ssh:1.2.11 + cpe:/a:ssh:ssh:1.2.29 + cpe:/a:ssh:ssh:1.2.20 + cpe:/a:ssh:ssh:1.2.25 + cpe:/a:ssh:ssh:1.2.26 + cpe:/a:ssh:ssh:1.2.27 + cpe:/a:ssh:ssh:1.2.28 + cpe:/a:ssh:ssh:1.2.21 + cpe:/a:ssh:ssh:1.2.22 + cpe:/a:ssh:ssh:1.2.23 + cpe:/a:ssh:ssh:1.2.24 + cpe:/a:ssh:ssh:1.2.30 + cpe:/a:ssh:ssh:1.2.31 + cpe:/a:ssh:ssh2:2.0 + cpe:/a:ssh:ssh2:2.1 + cpe:/a:ssh:ssh2:2.2 + cpe:/a:ssh:ssh2:2.3 + cpe:/a:ssh:ssh2:2.4 + cpe:/a:ssh:ssh2:2.5 + cpe:/a:ssh:ssh2:2.0.12 + cpe:/a:ssh:ssh2:2.0.11 + cpe:/a:ssh:ssh2:3.0 + cpe:/a:ssh:ssh2:2.0.13 + cpe:/a:ssh:ssh2:2.0.10 + + CVE-2002-1715 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:19.857-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-05T09:05:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ssh-bypass-restricted-shells(8908) + + + BID + 4547 + + SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access. + + + + + + + + + cpe:/a:microsoft:office + + CVE-2002-1716 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.123-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T09:08:00.000-04:00 + + + + XF + msoffice-spreadsheet-host-cas(8711) + + + BID + 4398 + + + MISC + http://www.guninski.com/m$oxp-2.html + + The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.1 + + CVE-2002-1717 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.277-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T09:13:00.000-04:00 + + + + XF + iis-cnf-reveal-information(8174) + + + BID + 4078 + + Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.1 + + CVE-2002-1718 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.437-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T09:15:00.000-04:00 + + + + BID + 4084 + + Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences. + + + + + + + + + cpe:/a:bavo:bavo:0.3 + + CVE-2002-1719 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.577-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T09:24:00.000-04:00 + + + + BID + 4079 + + + SECTRACK + 1003503 + + + XF + bavo-unspecified-security-bypass(40988) + + Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages. + + + + + + + + + + + + + + cpe:/a:outfront:spooky_login:2.5 + cpe:/a:outfront:spooky_login:2.4 + cpe:/a:outfront:spooky_login:2.2 + cpe:/a:outfront:spooky_login:2.3 + cpe:/a:outfront:spooky_login:2.0 + cpe:/a:outfront:spooky_login:2.1 + + CVE-2002-1720 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.730-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T09:27:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + spooky-login-sql-injection(8991) + + + BID + 4661 + + + MISC + http://www.securiteam.com/windowsntfocus/5VP030K75G.html + + SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field. + + + + + + + + + + cpe:/a:paul_l_daniels:altermime:0.1.11 + cpe:/a:paul_l_daniels:altermime:0.1.10 + + CVE-2002-1721 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:20.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-05T09:35:00.000-04:00 + + + + XF + altermime-snprintf-dos(8992) + + + BID + 4650 + + + CONFIRM + http://www.pldaniels.com/altermime/CHANGELOG + + Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-header that causes snprintf overwrite the FFGET_FILE variable with a (null) byte. + + + + + + + + + + + cpe:/h:logitech:itouch_keyboard + cpe:/h:logitech:cordless_freedom_itouch_keyboard + cpe:/h:logitech:cordless_itouch_keyboard + + CVE-2002-1722 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.027-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T09:48:00.000-04:00 + + + + XF + logitech-itouch-execute-commands(8994) + + + BID + 4662 + + Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button. + + + + + + + + + cpe:/a:powerboards:powerboards:2.2b + + CVE-2002-1723 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.170-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T09:54:00.000-04:00 + + + + XF + powerboards-path-disclosure(8824) + + + MISC + http://www.ifrance.com/kitetoua/tuto/powerboards.txt + + Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message. + + + + + + + + + cpe:/a:onlinetools.org:phpimageview:1.0 + + CVE-2002-1724 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.327-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T10:05:00.000-04:00 + + + + XF + phpimageview-var-css(9000) + + + BID + 4668 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter. + + + + + + + + + cpe:/a:onlinetools.org:phpimageview:1.0 + + CVE-2002-1725 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T10:10:00.000-04:00 + + + + XF + phpimageview-phpinfo-gain-info(9001) + + + BID + 4668 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function. + + + + + + + + + cpe:/a:brokenbytes:photodb:1.4 + + CVE-2002-1726 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.623-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T10:14:00.000-04:00 + + + + XF + photodb-admin-access(9002) + + + BID + 4669 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page. + + + + + + + + + + cpe:/a:asksam_systems:asksam_web_publisher:4.0 + cpe:/a:asksam_systems:asksam_web_publisher:1.0 + + CVE-2002-1727 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.777-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T10:17:00.000-04:00 + + + + XF + asksam-webpub-css(9003) + + + BID + 4670 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL. + + + + + + + + + + cpe:/a:asksam_systems:asksam_web_publisher:4.0 + cpe:/a:asksam_systems:asksam_web_publisher:1.0 + + CVE-2002-1728 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:21.920-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T10:22:00.000-04:00 + + + + XF + asksam-webpub-path-disclosure(9004) + + + BID + 4670 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path. + + + + + + + + + cpe:/a:aspjar:aspjar_guestbook:1.0 + + CVE-2002-1729 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:22.090-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-05T10:26:00.000-04:00 + + + + XF + aspjar-guestbook-css(9005) + + + BID + 4671 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message. + + + + + + + + + cpe:/a:aspjar:aspjar_guestbook:1.0 + + CVE-2002-1730 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:22.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T10:39:00.000-04:00 + + + + XF + aspjar-guestbook-delete-messages(9006) + + + BID + 4671 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes4.txt + + ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true". + + + + + + + + + + + + + cpe:/o:ibm:os_400:v4r2 + cpe:/o:ibm:os_400:v4r4 + cpe:/o:ibm:os_400:v4r3 + cpe:/o:ibm:os_400:v5r1 + cpe:/o:ibm:os_400:v4r5 + + CVE-2002-1731 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:22.403-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T10:42:00.000-04:00 + + + + XF + as400-system-request-information(8179) + + + BID + 4059 + + + SECTRACK + 1003507 + + The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF. + + + + + + + + + cpe:/a:actinic:actinic_catalog:4.7 + + CVE-2002-1732 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:22.560-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T10:46:00.000-04:00 + + + + XF + actinic-html-tags-css(8180) + + + BID + 4042 + + + SECTRACK + 1003502 + + + OSVDB + 27098 + + + OSVDB + 27097 + + + OSVDB + 27096 + + + OSVDB + 27095 + + + VIM + 20060720 vendor ack/fix: Actinic Catalog Unspecified .pl Files XSS (fwd) + + Multiple cross-site scripting (XSS) vulnerabilities in Actinic Catalog 4.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string argument to certain .pl files, (2) the REFPAGE parameter to ca000007.pl, (3) PRODREF parameter to ss000007.pl, or (4) hop parameter to ca000001.pl. + + + + + + + + + cpe:/a:prospero_technologies:prospero_message_board + + CVE-2002-1733 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:22.717-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T10:56:00.000-04:00 + + + + XF + prospero-html-msg-css(8184) + + + MISC + http://www.sentinelchicken.com/advisories/prospero/ + + + BID + 4109 + + Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post. + + + + + + + + + cpe:/a:aspbin:newspro:1.0.1 + + CVE-2002-1734 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:24.603-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-05T11:09:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + newspro-admin-access(9007) + + + BID + 4672 + + + VULN-DEV + 20020504 Security holes : PHP Image View, NewsPro, Photo DB, As_web, GuestBook + + NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true". + + + + + + + + + cpe:/a:davin_mccall:dlogin:1.0a + + CVE-2002-1735 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.013-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-05T11:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + linux-dlogin-bo(8186) + + + BID + 4043 + + + SECTRACK + 1003493 + + Buffer overflow in dlogin 1.0a could allow local users to gain privileges via unknown attack vectors. + + + + + + + + + cpe:/a:markus_triska:cginews + + CVE-2002-1736 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.153-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-05T11:07:00.000-04:00 + + + + XF + cginews-view-files(8187) + + + SECTRACK + 1003506 + + Unknown vulnerability in CGINews before 1.06 allow remote attackers to read arbitrary files via "unfiltered user input." + + + + + + + + + cpe:/o:astaro:security_linux:2.01 + + CVE-2002-1737 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.293-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T11:18:00.000-04:00 + + + + XF + astaro-insecure-file-permissions(8190) + + + BID + 4103 + + Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files. + + + + + + + + + + + + + + + cpe:/a:alt-n:mdaemon:5.0.3 + cpe:/a:alt-n:mdaemon:5.0.2 + cpe:/a:alt-n:mdaemon:5.0.1 + cpe:/a:alt-n:mdaemon:5.0::pro + cpe:/a:alt-n:mdaemon:5.0 + cpe:/a:alt-n:mdaemon:5.0.5 + cpe:/a:alt-n:mdaemon:5.0.4 + + CVE-2002-1738 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.433-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-05T11:24:00.000-04:00 + + + + XF + mdaemon-default-account(9024) + + + BID + 4685 + + Alt-N Technologies MDaemon 5.0.5.0 and earlier creates a default MDaemon mail account with a password of MServer, which could allow remote attackers to send anonymous email. + + + + + + + + + + + + + + + + cpe:/a:alt-n:mdaemon:5.0.3 + cpe:/a:alt-n:mdaemon:5.0.2 + cpe:/a:alt-n:mdaemon:5.0.1 + cpe:/a:alt-n:mdaemon:5.0::pro + cpe:/a:alt-n:mdaemon:5.0 + cpe:/a:alt-n:mdaemon:5.0.6 + cpe:/a:alt-n:mdaemon:5.0.5 + cpe:/a:alt-n:mdaemon:5.0.4 + + CVE-2002-1739 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.590-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-06T13:58:00.000-04:00 + + + + XF + mdaemon-weak-encryption(9025) + + + BID + 4686 + + Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords. + + + + + + + + + + + + + + + + cpe:/a:alt-n:mdaemon:5.0.3 + cpe:/a:alt-n:mdaemon:5.0.2 + cpe:/a:alt-n:mdaemon:5.0.1 + cpe:/a:alt-n:mdaemon:5.0::pro + cpe:/a:alt-n:mdaemon:5.0 + cpe:/a:alt-n:worldclient:5.0::pro + cpe:/a:alt-n:mdaemon:5.0.5 + cpe:/a:alt-n:mdaemon:5.0.4 + + CVE-2002-1740 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.763-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T14:02:00.000-04:00 + + + + XF + mdaemon-worldclient-foldername-bo(9026) + + + BID + 4689 + + Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter). + + + + + + + + + + + + + + + cpe:/a:alt-n:worldclient:5.0.5 + cpe:/a:alt-n:worldclient:5.0::pro + cpe:/a:alt-n:worldclient:5.0.4 + cpe:/a:alt-n:worldclient:5.0.3 + cpe:/a:alt-n:worldclient:5.0.2 + cpe:/a:alt-n:worldclient:5.0 + cpe:/a:alt-n:worldclient:5.0.1 + + CVE-2002-1741 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:23.933-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-06T14:10:00.000-04:00 + + + + XF + mdaemon-worldclient-delete-files(9027) + + + BID + 4687 + + Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter. + + + + + + + + + + + cpe:/a:paul_kulchenko:soap_lite:0.51 + cpe:/a:paul_kulchenko:soap_lite:0.50 + cpe:/a:paul_kulchenko:soap_lite:0.52 + + CVE-2002-1742 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:24.107-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T14:21:00.000-04:00 + + + + MISC + http://www.soaplite.com/ + + + BID + 4493 + + + MISC + http://use.perl.org/articles/02/04/09/000212.shtml?tid=5 + + + XF + soap-perl-execute-functions(8838) + + + MISC + http://www.phrack.org/show.php?p=58&a=9 + + + FREEBSD + FreeBSD-SN-02:02 + + SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger. + + + + + + + + + cpe:/a:mirabilis:icq:2002a_build3722 + + CVE-2002-1743 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:24.263-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-06T14:26:00.000-04:00 + + + + XF + icq-hpf-access-dos(8843) + + + BID + 4514 + + AOL ICQ 2002a Build 3722 allows remote attackers to cause a denial of service (crash) via a malformed .hpf file. + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2002-1744 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:24.403-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-06T14:37:00.000-04:00 + + + + XF + iis-codebrws-view-source(8853) + + + BID + 4525 + + Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot). + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + + CVE-2002-1745 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:24.527-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-06T14:45:00.000-04:00 + + + + XF + iis-codebrws-view-source(8853) + + + BID + 4543 + + Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files. + + + + + + + + + cpe:/a:maxim_krasnyansky:vtun:2.5b1 + + CVE-2002-1746 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:26.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T14:49:00.000-04:00 + + + + XF + vpn-replay-attack(7870) + + + BUGTRAQ + 20020109 Security weaknesses of VTun + + Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets. + + + + + + + + + cpe:/a:maxim_krasnyansky:vtun:2.5b1 + + CVE-2002-1747 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:26.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T14:51:00.000-04:00 + + + + XF + vpn-modify-packets(7868) + + + BUGTRAQ + 20020109 Security weaknesses of VTun + + Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB. + + + + + + + + + + + + + cpe:/a:open_source_development_network:slashcode:2.2.1 + cpe:/a:open_source_development_network:slashcode:2.2.2 + cpe:/a:open_source_development_network:slashcode:2.1.1 + cpe:/a:open_source_development_network:slashcode:2.1 + cpe:/a:open_source_development_network:slashcode:2.2 + + CVE-2002-1748 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:24.967-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-06T14:58:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + slashcode-account-access(7863) + + + BID + 3839 + + Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2002-1749 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:25.123-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-06T15:05:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + win2k-terminal-services-unlocked(8199) + + + BID + 4095 + + + NTBUGTRAQ + 20020211 Terminal doesn't lock after disconnect in Terminal Services + + Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. + + + + + + + + + cpe:/a:cgiscript.net:csguestbook:1.0 + + CVE-2002-1750 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:26.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T15:26:00.000-04:00 + + + + XF + cgiscript-url-execute-commands(8636) + + + BID + 4448 + + + BUGTRAQ + 20020408 multiple CGIscript.net scripts - Remote Code Execution + + csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. + + + + + + + + + cpe:/a:cgiscript.net:cslivesupport:1.0 + + CVE-2002-1751 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:26.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T15:50:00.000-04:00 + + + + XF + cgiscript-url-execute-commands(8636) + + + BID + 4450 + + + BUGTRAQ + 20020408 multiple CGIscript.net scripts - Remote Code Execution + + csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. + + + + + + + + + cpe:/a:cgiscript.net:cschat-r-box:1.0 + + CVE-2002-1752 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:27.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-06T15:53:00.000-04:00 + + + + XF + cgiscript-url-execute-commands(8636) + + + BID + 4452 + + + BUGTRAQ + 20020408 multiple CGIscript.net scripts - Remote Code Execution + + csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. + + + + + + + + + + cpe:/a:cgiscript.net:csnews:1.0 + cpe:/a:cgiscript.net:csnewspro:1.0 + + CVE-2002-1753 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:27.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T13:12:00.000-04:00 + + + + XF + cgiscript-url-execute-commands(8636) + + + BID + 4451 + + + BUGTRAQ + 20020408 multiple CGIscript.net scripts - Remote Code Execution + + csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. + + + + + + + + + + + + cpe:/a:novell:netware_client:4.83 + cpe:/a:novell:netware_client:4.82 + cpe:/a:novell:netware_client:4.81 + cpe:/a:novell:netware_client:4.80 + + CVE-2002-1754 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:25.840-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-07T13:17:00.000-04:00 + + + + MISC + http://www.cqure.net/advisories.jsp?id=15 + + + XF + netware-client-hostname-dos(9035) + + Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname. + + + + + + + + + + cpe:/a:tinc:tinc:1.0pre4 + cpe:/a:tinc:tinc:1.0pre3 + + CVE-2002-1755 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:25.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T13:22:00.000-04:00 + + + + XF + vpn-modify-packets(7868) + + tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC. + + + + + + + + + cpe:/a:acd_systems:acdsee:4.0 + + CVE-2002-1756 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:26.137-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-07T13:34:00.000-04:00 + + + + XF + acdsee-ais-description-bo(9052) + + + BID + 4719 + + + BUGTRAQ + 20020510 Possible Buffer Overflow in ACDSee 4.0 + + ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed. + + + + + + + + + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + cpe:/a:phprojekt:phprojekt:3.1 + cpe:/a:phprojekt:phprojekt:3.0 + cpe:/a:phprojekt:phprojekt:3.1a + cpe:/a:phprojekt:phprojekt:2.3 + cpe:/a:phprojekt:phprojekt:2.2 + cpe:/a:phprojekt:phprojekt:2.1a + cpe:/a:phprojekt:phprojekt:2.4a + cpe:/a:phprojekt:phprojekt:2.4 + + CVE-2002-1757 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:26.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T13:40:00.000-04:00 + + + + XF + phprojekt-unauth-script-access(8943) + + + BID + 4596 + + PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms". + + + + + + + + + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + cpe:/a:phprojekt:phprojekt:3.1 + cpe:/a:phprojekt:phprojekt:3.0 + cpe:/a:phprojekt:phprojekt:3.1a + cpe:/a:phprojekt:phprojekt:2.3 + cpe:/a:phprojekt:phprojekt:2.2 + cpe:/a:phprojekt:phprojekt:2.1a + cpe:/a:phprojekt:phprojekt:2.4a + cpe:/a:phprojekt:phprojekt:2.4 + + CVE-2002-1758 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:26.467-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T13:42:00.000-04:00 + + + + XF + phprojekt-unauth-script-access(8943) + + + BID + 4599 + + PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is logged in. + + + + + + + + + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + cpe:/a:phprojekt:phprojekt:3.1 + cpe:/a:phprojekt:phprojekt:3.0 + cpe:/a:phprojekt:phprojekt:3.1a + cpe:/a:phprojekt:phprojekt:2.3 + cpe:/a:phprojekt:phprojekt:2.2 + cpe:/a:phprojekt:phprojekt:2.1a + cpe:/a:phprojekt:phprojekt:2.4a + cpe:/a:phprojekt:phprojekt:2.4 + + CVE-2002-1759 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:28.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T13:44:00.000-04:00 + + + + XF + phprojekt-upload-read-files(8944) + + + BID + 4597 + + + BUGTRAQ + 20020424 PHProjekt multiple vulnerabilities + + The upload function in PHPProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHPProjekt to process arbitrary files. + + + + + + + + + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + cpe:/a:phprojekt:phprojekt:3.1 + cpe:/a:phprojekt:phprojekt:3.0 + cpe:/a:phprojekt:phprojekt:3.1a + cpe:/a:phprojekt:phprojekt:2.3 + cpe:/a:phprojekt:phprojekt:2.2 + cpe:/a:phprojekt:phprojekt:2.1a + cpe:/a:phprojekt:phprojekt:2.4a + cpe:/a:phprojekt:phprojekt:2.4 + + CVE-2002-1760 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:29.057-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T13:52:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + phprojekt-sql-injection(8945) + + + BID + 4598 + + + BUGTRAQ + 20020424 PHProjekt multiple vulnerabilities + + Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown attack vectors. + + + + + + + + + + + + + + + + + + + cpe:/a:phprojekt:phprojekt:2.0.1 + cpe:/a:phprojekt:phprojekt:2.1 + cpe:/a:phprojekt:phprojekt:2.0 + cpe:/a:phprojekt:phprojekt:3.1 + cpe:/a:phprojekt:phprojekt:3.0 + cpe:/a:phprojekt:phprojekt:3.1a + cpe:/a:phprojekt:phprojekt:2.3 + cpe:/a:phprojekt:phprojekt:2.2 + cpe:/a:phprojekt:phprojekt:2.1a + cpe:/a:phprojekt:phprojekt:2.4a + cpe:/a:phprojekt:phprojekt:2.4 + + CVE-2002-1761 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:26.980-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-07T13:53:00.000-04:00 + + + + BUGTRAQ + 20020424 PHProjekt multiple vulnerabilities + + Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences. + + + + + + + + + cpe:/a:microsoft:baseline_security_analyzer:1.0 + + CVE-2002-1762 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.153-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-07T13:56:00.000-04:00 + + + + XF + mbsa-plaintext-system-info(8947) + + + BID + 4594 + + Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java. + + + + + + + + + cpe:/o:sun:solaris:8.0 + + CVE-2002-1763 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.293-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T14:01:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + solaris-dtscreen-screenlock-bypass(9406) + + + BID + 5040 + + The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session. + + + + + + + + + cpe:/a:adobe:acrobat_reader:4.0.5 + + CVE-2002-1764 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.433-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T14:04:00.000-04:00 + + + + XF + adobe-acrobat-tmpfile-symlink(9407) + + + BID + 5068 + + acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files. + + + + + + + + + + cpe:/a:ximian:evolution:1.0.3 + cpe:/a:ximian:evolution:1.0.4 + + CVE-2002-1765 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-07T14:19:00.000-04:00 + + + + XF + evolution-mime-header-dos(9059) + + + BID + 4715 + + + REDHAT + RHBA-2002:080 + + + CONECTIVA + CLA-2002:486 + + + MLIST + [gnome-announce] 20020503 Patch for serious bug in 1.0.3 + + Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header. + + + + + + + + + cpe:/a:netscape:communicator:4.77 + + CVE-2002-1766 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.747-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T14:31:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + netscape-composer-font-bo(9355) + + + BID + 5010 + + Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute. + + + + + + + + + cpe:/a:oracle:database_server:8.1.5 + + CVE-2002-1767 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:27.887-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-07T14:33:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + oracle-tnslsnr-command-line-bo(8772) + + + BID + 4413 + + Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument. + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:11.2 + + CVE-2002-1768 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:29.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-07T14:41:00.000-04:00 + + + + XF + cisco-ios-hsrp-dos(9282) + + + BID + 4948 + + + BUGTRAQ + 20020606 Re: Three possible DoS attacks against some IOS versions. + + + BUGTRAQ + 20020605 Three possible DoS attacks against some IOS versions. + + Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985. + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:site_server:3.0:sp1_alpha + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0::i386 + cpe:/a:microsoft:site_server:3.0:apha + cpe:/a:microsoft:site_server_commerce:3.0:alpha + cpe:/a:microsoft:site_server:3.0:sp2:i386 + cpe:/a:microsoft:site_server:3.0:sp2_alpha + cpe:/a:microsoft:site_server:3.0:sp1:i386 + cpe:/a:microsoft:site_server_commerce:3.0:sp3_alpha + cpe:/a:microsoft:site_server:3.0:sp3_alpha + cpe:/a:microsoft:site_server:3.0:sp3:i386 + cpe:/a:microsoft:site_server_commerce:3.0:sp1_alpha + cpe:/a:microsoft:site_server_commerce:3.0:sp2_alpha + + CVE-2002-1769 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:28.200-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T14:51:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + siteserver-ldap-anonymous-account(8048) + + + BID + 3998 + + + MSKB + Q248840 + + + MISC + http://online.securityfocus.com/advisories/3843 + + + VULNWATCH + 20020129 RFP2201: MS Site Server Evilness + + Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege. + + + + + + + + + cpe:/a:qualcomm:eudora:5.1 + + CVE-2002-1770 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:28.373-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T14:55:00.000-04:00 + + + + XF + msviewer-tvideo-execute-attachment(8609) + + + BID + 4343 + + + MISC + http://security.greymagic.com/adv/gm002-ie/ + + + NTBUGTRAQ + 2002032 Automatically opening IE + Executing attachments + + + BUGTRAQ + 2002032 Automatically opening IE + Executing attachments + + Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code, which is launched and executed in the My Computer zone by Internet Explorer. + + + + + + + + + + + + + + + + + + cpe:/a:matt_wright:formmail:1.8 + cpe:/a:matt_wright:formmail:1.9 + cpe:/a:matt_wright:formmail:1.6 + cpe:/a:matt_wright:formmail:1.7 + cpe:/a:matt_wright:formmail:1.4 + cpe:/a:matt_wright:formmail:1.5 + cpe:/a:matt_wright:formmail:1.2 + cpe:/a:matt_wright:formmail:1.3 + cpe:/a:matt_wright:formmail:1.1 + cpe:/a:matt_wright:formmail:1.0 + + CVE-2002-1771 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:30.430-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-07T14:58:00.000-04:00 + + + + XF + formmail-smtp-header-spam(8013) + + + BID + 3955 + + + CONFIRM + http://www.scriptarchive.com/readme/formmail.html#history + + + BUGTRAQ + 20020123 Anonymous Mail Forwarding Vulnerabilities in FormMail 1.9 + + Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables. + + + + + + + + + + + cpe:/o:novell:netware:5.0 + cpe:/o:novell:netware:5.1 + cpe:/o:novell:netware:5.0:sp5 + + CVE-2002-1772 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:28.683-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:07:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + netware-nds-unauth-access(8065) + + + BID + 4012 + + Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not in the NT domain but has domain access rights, which allows the user to enter a null password. + + + + + + + + + cpe:/a:mirabilis:icq_for_macos_x:2.6_x_beta + + CVE-2002-1773 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:28.840-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:15:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + icq-macos-dos(8085) + + + BID + 4031 + + Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2002 + + CVE-2002-1774 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:28.997-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:22:00.000-04:00 + + + + XF + nav-nullchar-bypass-protection(8389) + + + BID + 4242 + + ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2002 + + CVE-2002-1775 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.123-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:25:00.000-04:00 + + + + XF + nav-nonrfc-bypass-protection(8390) + + + BID + 4243 + + ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass the initial virus scan and cause NAV to prematurely stop scanning by using a non-RFC compliant MIME header. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2002 + + CVE-2002-1776 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.247-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:27:00.000-04:00 + + + + XF + nav-filetype-bypass-protection(8391) + + + BID + 4245 + + ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2002 + + CVE-2002-1777 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.403-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:35:00.000-04:00 + + + + XF + nav-contenttype-bypass-protection(8392) + + + BID + 4246 + + ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed. + + + + + + + + + cpe:/a:symantec:norton_personal_firewall:2002 + + CVE-2002-1778 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.543-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-07T15:43:00.000-04:00 + + + + XF + norton-bypass-portscan-protection(8859) + + + BID + 4521 + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.05.16.html + + Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan. + + + + + + + + + cpe:/a:symantec:norton_personal_firewall:2002 + + CVE-2002-1779 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.667-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T08:34:00.000-04:00 + + + + BID + 4545 + + + CONFIRM + http://securityresponse.symantec.com/avcenter/security/Content/2002.05.16.html + + The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305). + + + + + + + + + cpe:/a:alcatech_gmbh:bpm_studio_pro:4.2 + + CVE-2002-1780 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.810-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-08T08:50:00.000-04:00 + + + + XF + bpm-http-device-dos(8299) + + BPM Studio Pro 4.2 by ALCATech GmbH includes a webserver that allows a remote attacker to cause a denial of service (crash) by sending a URL request for a MS-DOS device such as con. NOTE: it has been disputed that this and possibly other application-level DOS device issues stem from a bug in Windows, and as such, such applications should not be considered vulnerable themselves. + + + + + + + + + + + + cpe:/a:delegate:delegate:7.7.1 + cpe:/a:delegate:delegate:7.7.0 + cpe:/a:delegate:delegate:7.8.1 + cpe:/a:delegate:delegate:7.8.0 + + CVE-2002-1781 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:29.950-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T08:57:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + delegate-proxy-pop-bo(8114) + + + BID + 4055 + + + MISC + http://www.globalintersec.com/adv/delegate-2002012101.txt + + + BUGTRAQ + 20020207 [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities + + Multiple buffer overflows in DeleGate 7.7.0 through 7.8.1 allow remote attackers to execute arbitrary code, as demonstrated using a long USER command to the POP proxy. + + + + + + + + + cpe:/a:university_of_washington:uw-imap:2001.0a + + CVE-2002-1782 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.090-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T09:19:00.000-04:00 + + + + XF + wuimapd-information-disclosure(9238) + + + CONFIRM + http://www.washington.edu/imap/IMAP-FAQs/index.html#5.1 + + + BID + 4909 + + + MISC + http://www.security.nnov.ru/advisories/courier.asp + + The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.2.3 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:3.0.16 + cpe:/a:php:php:4.2.0 + cpe:/a:php:php:3.0.17 + cpe:/a:php:php:3.0.14 + cpe:/a:php:php:3.0.15 + + CVE-2002-1783 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.217-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T09:25:00.000-04:00 + + + + XF + php-fopen-crlf-injection(10080) + + + BID + 5681 + + + DEBIAN + DSA-168 + + + BUGTRAQ + 20020912 Re: PHP fopen() CRLF Injection + + + BUGTRAQ + 20020909 PHP fopen() CRLF Injection + + CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions. + + + + + + + + + + + + + cpe:/o:hp:tru64:5.1 + cpe:/o:hp:tru64:5.0a + cpe:/o:hp:tru64:5.1a + cpe:/o:hp:tru64:4.0g + cpe:/o:hp:tru64:4.0f + + CVE-2002-1784 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.403-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-08T09:36:00.000-04:00 + + + + BID + 5242 + + + XF + tru64-inetd-remote-dos(9614) + + + COMPAQ + SSRT0795 + + Unknown vulnerability in inetd in HP Tru64 Unix 4.0f through 5.1a allows remote attackers to cause a denial of service via unknown attack vectors. + + + + + + + + + + + + + + cpe:/a:zeus_technologies:zeus_web_server:4.1 + cpe:/a:zeus_technologies:zeus_web_server:4.1_r1 + cpe:/a:zeus_technologies:zeus_web_server:4.0 + cpe:/a:zeus_technologies:zeus_web_server:4.1_r2 + cpe:/a:zeus_technologies:zeus_web_server:4.1_r3 + cpe:/a:zeus_technologies:zeus_web_server:4.1_r4 + + CVE-2002-1785 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.560-04:00 + + + 1.9 + LOCAL + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T09:58:00.000-04:00 + + + + BID + 6144 + + + XF + zeus-admin-index-xss(10567) + + + BUGTRAQ + 20021211 Re: Zeus Admin Server v4.1r2 index.fcgi XSS bug + + + BUGTRAQ + 20021108 Zeus Admin Server v4.1r2 index.fcgi XSS bug + + Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + + CVE-2002-1786 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.730-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T10:01:00.000-04:00 + + + + BID + 5737 + + + XF + irix-root-coredumps(10138) + + + SGI + 20020902-01-I + + SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.17m + + CVE-2002-1787 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:30.903-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T10:25:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5892 + + + XF + irix-uux-bo(10274) + + + CIAC + N-004 + + + SGI + 20020903-02-P + + Buffer overflow in uux in eoe.sw.uucp package of SGI IRIX 6.5 through 6.5.17 allows local users to execute arbitrary code via unknown attack vectors. + + + + + + + + + + + + cpe:/a:kim_storm:nn:6.6.3 + cpe:/a:kim_storm:nn:6.6.0 + cpe:/a:kim_storm:nn:6.6.1 + cpe:/a:kim_storm:nn:6.6.2 + + CVE-2002-1788 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T10:28:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5160 + + + XF + nn-error-msg-format-string(9491) + + + OSVDB + 27086 + + Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses. + + + + + + + + + cpe:/a:newsx:newsx:1.4_pl6 + + CVE-2002-1789 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.247-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-08T10:30:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5240 + + + XF + newsx-syslog-format-string(9583) + + + FREEBSD + FreeBSD-SN-02:05 + + Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function. + + + + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:exchange_server:5.5:sp1 + cpe:/a:microsoft:internet_information_server:4.0 + cpe:/a:microsoft:exchange_server:5.5 + cpe:/a:microsoft:exchange_server:5.5:sp2 + + CVE-2002-1790 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.403-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T10:34:00.000-04:00 + + + + BID + 5213 + + + XF + iis-smtp-mail-relay(9580) + + The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.10 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.17 + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.15 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:sgi:irix:6.5.16 + cpe:/o:sgi:irix:6.5.1 + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:sgi:irix:6.5.16m + cpe:/o:sgi:irix:6.5.17m + + CVE-2002-1791 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.560-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T10:37:00.000-04:00 + + + + BID + 5895 + + + XF + irix-desktop-files-insecure(10273) + + + CIAC + N-004 + + + SGI + 20020903-01-P + + SGI IRIX 6.5 through 6.5.17 creates temporary desktop files with world-writable permissions, which allows local users to overwrite or corrupt those files. + + + + + + + + + + + + + + cpe:/a:fake_identd:fake_identd:1.1 + cpe:/a:fake_identd:fake_identd:1.2 + cpe:/a:fake_identd:fake_identd:1.3 + cpe:/a:fake_identd:fake_identd:0.9 + cpe:/a:fake_identd:fake_identd:1.4 + cpe:/a:fake_identd:fake_identd:0.9b + + CVE-2002-1792 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.763-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-08T10:39:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5351 + + + XF + fake-identd-bo(9731) + + Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers execute arbitrary code as root via a long request that is that is split into multiple packets. + + + + + + + + + + + + + + + cpe:/o:hp:vvos:11.04 + cpe:/a:hp:virtualvault:4.6 + cpe:/a:hp:virtualvault:4.5 + + CVE-2002-1793 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:31.917-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-08T10:43:00.000-04:00 + + + + BID + 5791 + + + XF + hp-vvos-modssl-dos(10206) + + + HP + HPSBUX0209-220 + + HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service. + + + + + + + + + + + + + + + + cpe:/a:hp:ldap-ux_integration:b.03.00 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:11.00 + cpe:/a:hp:ldap-ux_integration:b.02.00 + + CVE-2002-1794 + 2002-12-31T00:00:00.000-05:00 + 2009-03-04T00:15:18.920-05:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-08T11:02:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5839 + + + XF + hp-ldapux-pamauthz-bypass(10266) + + + CIAC + N-006 + + + HP + HPSBUX0209-221 + + + + + Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users. + + + + + + + + + cpe:/a:microsoft:tsac_activex_control + + CVE-2002-1795 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:32.247-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T11:06:00.000-04:00 + + + + BID + 5952 + + + XF + ms-tsac-connect-xss(10342) + + Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors. + + + + + + + + + cpe:/a:hp:chaivm + + CVE-2002-1796 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:32.433-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T11:12:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + HP + HPSBUX0207-203 + + + BID + 5334 + + + MISC + http://www.phenoelit.de/stuff/HP_Chai.txt + + + XF + hp-chaivm-add-services(9695) + + ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services. + + + + + + + + + cpe:/a:hp:chaivm + + CVE-2002-1797 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:32.573-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T11:19:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5332 + + + MISC + http://www.phenoelit.de/stuff/HP_Chai.txt + + + XF + hp-chaivm-unauth-access(9694) + + ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer. + + + + + + + + + + + cpe:/a:coxco_support:midicart_php:plus + cpe:/a:coxco_support:midicart_php:maxi + cpe:/a:coxco_support:midicart_php + + CVE-2002-1798 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:32.717-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T11:33:00.000-04:00 + + + + + BID + 5855 + + + BID + 5851 + + + XF + midicart-php-access-upload(10306) + + + BUGTRAQ + 20021002 Multiple Web Security Holes + + MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php. + + + + + + + + + cpe:/a:phprank:phprank:1.8 + + CVE-2002-1799 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:32.870-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T11:35:00.000-04:00 + + + + BUGTRAQ + 20021010 Multiple vulnerabilities in phpRank + + + BID + 5945 + + + XF + phprank-javascript-xss(10336) + + Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter. + + + + + + + + + cpe:/a:phprank:phprank:1.8 + + CVE-2002-1800 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T11:43:00.000-04:00 + + + + BID + 5947 + + + XF + phprank-admin-plaintext-password(10352) + + + BUGTRAQ + 20021010 Multiple vulnerabilities in phpRank + + phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password. + + + + + + + + + + + + cpe:/a:bizdesign:imagefolio:2.26 + cpe:/a:bizdesign:imagefolio:2.23 + cpe:/a:bizdesign:imagefolio:2.24 + cpe:/a:bizdesign:imagefolio:2.27 + + CVE-2002-1801 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T12:10:00.000-04:00 + + + + BID + 4976 + + + XF + magefolio-setup-cgi-access(9308) + + ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message. + + + + + + + + + cpe:/a:xoops:xoops:1.0_rc3 + + CVE-2002-1802 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.323-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:13:00.000-04:00 + + + + BID + 5785 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 Xoops RC3 script injection vulnerability + + Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news. + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:6.0 + + CVE-2002-1803 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.467-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:14:00.000-04:00 + + + + BID + 5796 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables + + Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. + + + + + + + + + cpe:/a:npds:npds:4.8 + + CVE-2002-1804 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.607-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:16:00.000-04:00 + + + + BID + 5797 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables + + Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. + + + + + + + + + cpe:/a:dacode:dacode:1.2.0 + + CVE-2002-1805 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.763-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:23:00.000-04:00 + + + + BID + 5798 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables + + Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. + + + + + + + + + cpe:/a:drupal:drupal:4.0.0 + + CVE-2002-1806 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:33.917-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:25:00.000-04:00 + + + + BID + 5801 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables + + Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. + + + + + + + + + cpe:/a:phpwebsite:phpwebsite:0.8.3 + + CVE-2002-1807 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.060-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:26:00.000-04:00 + + + + BID + 5802 + + + XF + cms-news-image-xss(10173) + + + BUGTRAQ + 20020924 ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables + + Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. + + + + + + + + + cpe:/a:zack_coburn:meunity_community_system:1.0 + + CVE-2002-1808 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.200-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T12:29:00.000-04:00 + + + + BID + 5957 + + + XF + meunity-forum-image-xss(10369) + + + BUGTRAQ + 20021014 ECHU Alert #3 : Meunity 1.1 script injection vulnerability + + Cross-site scripting (XSS) vulnerability in Meunity Community System 1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when creating a topic. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + + CVE-2002-1809 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.357-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T12:35:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5503 + + + XF + mysql-default-root-access(9902) + + + BUGTRAQ + 20020818 Weak MySQL Default Configuration on Windows + + The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database. + + + + + + + + + + cpe:/h:d-link:dwl-900ap%2b:2.1 + cpe:/h:d-link:dwl-900ap%2b:2.2 + + CVE-2002-1810 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.590-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T12:40:00.000-04:00 + + + + BID + 6015 + + + XF + dlink-tftp-obtain-information(10424) + + D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information. + + + + + + + + + cpe:/h:belkin:f5d6130_wnap:ap14g8 + + CVE-2002-1811 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.747-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:08:00.000-04:00 + + + + BID + 5571 + + + XF + belkin-ap-snmp-dos(9960) + + Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending several SNMP GetNextRequest requests. + + + + + + + + + + cpe:/a:gdam:gdam:0.942 + cpe:/a:gdam:gdam:0.933 + + CVE-2002-1812 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:34.887-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-08T13:15:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5578 + + + MISC + http://www.securiteam.com/exploits/5CP0Y0080G.html + + + XF + gdam123-mp3-filename-bo(9991) + + Buffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter. + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.8.2616 + cpe:/a:aol:instant_messenger:4.8.2646 + cpe:/a:aol:instant_messenger:5.0.2938 + cpe:/a:aol:instant_messenger:4.7.2480 + + CVE-2002-1813 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.043-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T13:20:00.000-04:00 + + + + XF + aim-url-execute-files(10441) + + + BID + 6027 + + + BUGTRAQ + 20021021 AIM 4.8.2790 remote file execution vulnerability + + Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:mandrakesoft:mandrake_linux:9.0 + cpe:/o:redhat:linux:7.0::sparc + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:mandrakesoft:mandrake_linux:7.1 + cpe:/a:gnome:bonobo + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/o:slackware:slackware_linux:8.0 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:7.0::alpha + + CVE-2002-1814 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.200-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:30:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5125 + + + MISC + http://www.securiteam.com/exploits/5AP0E0K8AO.html + + + XF + linux-efstool-bo(9451) + + Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments. + + + + + + + + + cpe:/a:aquonics_scripting:aquonics_file_manager:1.5 + + CVE-2002-1815 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.370-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T13:35:00.000-04:00 + + + + BID + 5533 + + + XF + aquonics-filemanager-directory-traversal(9929) + + Directory traversal vulnerability in source.php and source.cgi in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. + + + + + + + + + + cpe:/a:yann_ramin:atphttpd:0.4 + cpe:/a:yann_ramin:atphttpd:0.4b + + CVE-2002-1816 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.527-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:37:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5956 + + + XF + atphttpd-sockgets-bo(10362) + + + BUGTRAQ + 20021012 Pyramid Research Project - atphttpd security advisorie + + Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + + + + cpe:/a:symantec_veritas:cluster_server:1.3_hp-ux + cpe:/a:symantec_veritas:cluster_server:1.3 + cpe:/a:symantec_veritas:cluster_server:1.3_solaris + cpe:/a:symantec_veritas:cluster_server:1.2_nt + + CVE-2002-1817 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.683-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:48:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5688 + + + XF + vcs-unauth-root-access(10082) + + + CONFIRM + http://seer.support.veritas.com/docs/238143.htm + + + SECTRACK + 1005204 + + Unknown vulnerability in Veritas Cluster Server (VCS) 1.2 for WindowsNT, Cluster Server 1.3.0 for Solaris, and Cluster Server 1.3.1 for HP-UX allows attackers to gain privileges via unknown attack vectors. + + + + + + + + + cpe:/a:ez_systems:httpbench:1.1 + + CVE-2002-1818 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.823-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T13:53:00.000-04:00 + + + + BID + 6153 + + + XF + ez-httpbench-view-files(10589) + + + BUGTRAQ + 20021110 benchmark tool for HTTP pages. + + ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter. + + + + + + + + + cpe:/a:tinyhttpd:tinyhttpd:0.1.0 + + CVE-2002-1819 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:35.980-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-08T13:55:00.000-04:00 + + + + BID + 6158 + + + XF + tinyhttpd-dotdot-directory-traversal(10596) + + + BUGTRAQ + 20021111 Multiple vulnerabilities in Tiny HTTPd + + Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL. + + + + + + + + + + cpe:/a:ultimate_php_board:ultimate_php_board:1.0_beta + cpe:/a:ultimate_php_board:ultimate_php_board:1.0 + + CVE-2002-1820 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.120-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:58:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + upb-register-admin-spoof(9972) + + + BID + 5580 + + register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a." + + + + + + + + + + cpe:/a:ultimate_php_board:ultimate_php_board:1.0_beta + cpe:/a:ultimate_php_board:ultimate_php_board:1.0 + + CVE-2002-1821 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.277-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T13:59:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5666 + + + SECTRACK + 1005198 + + Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php. + + + + + + + + + cpe:/a:ibm:http_server:1.0 + + CVE-2002-1822 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-08T14:29:00.000-04:00 + + + + BID + 6181 + + + XF + ibm-http-path-disclosure(10628) + + + BUGTRAQ + 20021113 JSP processor 1.1 information disclosure + + IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP). + + + + + + + + + cpe:/a:lonerunner:zeroo_http_server:1.5 + + CVE-2002-1823 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.573-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-08T14:32:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20021116 Remote Buffer Overflow vulnerability in Zeroo HTTP Server. + + + BID + 6190 + + + XF + zeroo-http-server-bo(10642) + + Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request. + + + + + + + + + + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-1824 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-25T13:05:00.000-04:00 + + + + BID + 5778 + + + XF + ie-ssl-certificate-expired(10180) + + Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability. + + + + + + + + + + + + + + cpe:/a:wasd:wasd_http_server:7.2.2 + cpe:/a:wasd:wasd_http_server:7.2.3 + cpe:/a:wasd:wasd_http_server:7.1 + cpe:/a:wasd:wasd_http_server:8.0 + cpe:/a:wasd:wasd_http_server:7.2 + cpe:/a:wasd:wasd_http_server:7.2.1 + + CVE-2002-1825 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:36.870-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-25T13:14:00.000-04:00 + + + + BID + 5811 + + + XF + wasd-http-perlrte-format-string(10213) + + + MISC + http://www.teaser.fr/~jlgailly/security/wasd-vuln-2002-09.txt + + + CONFIRM + http://wasd.vsm.com.au/ht_root/doc/misc/wasd_advisory_020925.txt + + + OSVDB + 21288 + + Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable. + + + + + + + + + cpe:/a:grsecurity:grsecurity_kernel_patch:1.9.4 + + CVE-2002-1826 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.027-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-25T13:20:00.000-04:00 + + + + BID + 4762 + + + XF + grsecurity-linux-kernel-patch(9109) + + grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.11.6 + cpe:/a:sendmail:sendmail:8.11.2 + cpe:/a:sendmail:sendmail:8.11.3 + cpe:/a:sendmail:sendmail:8.11.4 + cpe:/a:sendmail:sendmail:8.11.5 + cpe:/a:sendmail:sendmail:8.11.0 + cpe:/a:sendmail:sendmail:8.12:beta10 + cpe:/a:sendmail:sendmail:8.11.1 + cpe:/a:sendmail:sendmail:8.9.0 + cpe:/a:sendmail:sendmail:8.10 + cpe:/a:sendmail:sendmail:8.9.1 + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.9.2 + cpe:/a:sendmail:sendmail:8.12:beta7 + cpe:/a:sendmail:sendmail:8.12.2 + cpe:/a:sendmail:sendmail:8.9.3 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/a:sendmail:sendmail:8.12:beta12 + cpe:/a:sendmail:sendmail:8.12:beta5 + cpe:/a:sendmail:sendmail:8.12.0 + cpe:/a:sendmail:sendmail:8.12:beta16 + cpe:/a:sendmail:sendmail:8.10.2 + cpe:/a:sendmail:sendmail:8.10.1 + + CVE-2002-1827 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.167-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-25T13:25:00.000-04:00 + + + + CONFIRM + http://www.sendmail.org/LockingAdvisory.txt + + + BID + 4822 + + + XF + sendmail-file-locking-dos(9162) + + Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files. + + + + + + + + + cpe:/a:savant:savant_webserver:3.1 + + CVE-2002-1828 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.370-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-25T13:28:00.000-04:00 + + + + BID + 5707 + + + XF + savant-neg-content-dos(10103) + + Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. + + + + + + + + + cpe:/a:openbb:openbb:1.0.0_rc3 + + CVE-2002-1829 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.513-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:03:00.000-04:00 + + + + XF + openbb-admin-access(9160) + + + BID + 4819 + + + VULN-DEV + 20020523 Security holes in OpenBB + + Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag. + + + + + + + + + + + cpe:/a:openbb:openbb:1.0.0_rc3 + cpe:/a:openbb:openbb:1.0.0_rc1 + cpe:/a:openbb:openbb:1.0.0_rc2 + + CVE-2002-1830 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.653-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:05:00.000-04:00 + + + + BID + 4823 + + + XF + openbb-admin-access(9160) + + + VULN-DEV + 20020523 Security holes in OpenBB + + Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters. + + + + + + + + + + + + + + + + cpe:/a:microsoft:msn_messenger:2.0 + cpe:/a:microsoft:msn_messenger:3.0 + cpe:/a:microsoft:msn_messenger:4.0 + cpe:/a:microsoft:msn_messenger:3.6 + cpe:/a:microsoft:msn_messenger:1.0 + cpe:/a:microsoft:msn_messenger:4.5 + cpe:/a:microsoft:msn_messenger:2.2 + cpe:/a:microsoft:msn_messenger:4.6 + + CVE-2002-1831 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.810-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:09:00.000-04:00 + + + + BID + 4827 + + + XF + msn-invite-dos(9161) + + Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field. + + + + + + + + + + + cpe:/a:scaramanga:firestorm_ids:0.4.0 + cpe:/a:scaramanga:firestorm_ids:0.4.1 + cpe:/a:scaramanga:firestorm_ids:0.4.2 + + CVE-2002-1832 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:37.967-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:12:00.000-04:00 + + + + BID + 4871 + + + XF + firestorm-nids-ipoptions-dos(9192) + + + CONFIRM + http://www.scaramanga.co.uk/firestorm/NEWS + + Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options. + + + + + + + + + + cpe:/h:xerox:docutech_6115 + cpe:/h:xerox:docutech_6110 + + CVE-2002-1833 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.120-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:17:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4766 + + + BID + 4765 + + + XF + xerox-docutech-insecure-configuration(9108) + + The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges. + + + + + + + + + + cpe:/h:xerox:docutech_6115 + cpe:/h:xerox:docutech_6110 + + CVE-2002-1834 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.263-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:21:00.000-04:00 + + + + BID + 4766 + + + XF + xerox-docutech-insecure-configuration(9108) + + The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history. + + + + + + + + + + cpe:/h:xerox:docutech_6115 + cpe:/h:xerox:docutech_6110 + + CVE-2002-1835 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.417-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:24:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4765 + + + XF + xerox-docutech-insecure-configuration(9108) + + The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device. + + + + + + + + + + cpe:/h:xerox:docutech_6115 + cpe:/h:xerox:docutech_6110 + + CVE-2002-1836 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.560-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:26:00.000-04:00 + + + + BID + 4765 + + + XF + xerox-docutech-insecure-configuration(9108) + + The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files. + + + + + + + + + cpe:/a:ids:ids:0.8.1 + + CVE-2002-1837 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.717-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T08:29:00.000-04:00 + + + + BID + 4870 + + + XF + ids-dir-existence(9201) + + + CONFIRM + http://ids.sourceforge.net/ChangeLog.html + + The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not. + + + + + + + + + + + + cpe:/a:steve_sachs:charities.cron:1.6.0 + cpe:/a:steve_sachs:charities.cron:1.5.0 + cpe:/a:steve_sachs:charities.cron:1.1.1 + cpe:/a:steve_sachs:charities.cron:1.0.2 + + CVE-2002-1838 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:38.857-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:34:00.000-04:00 + + + + BID + 4869 + + + CONFIRM + http://www.stevesachs.com/charities.cron_CHANGELOG + + Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.52 + + CVE-2002-1839 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:36:00.000-04:00 + + + + BID + 4830 + + + XF + interscan-viruswall-header-removal(9168) + + Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message. + + + + + + + + + cpe:/a:irssi:irssi:0.8.4 + + CVE-2002-1840 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.167-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-26T08:40:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4831 + + + XF + irssi-backdoor-version(9176) + + + CONFIRM + http://real.irssi.org/?page=backdoor + + irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system. + + + + + + + + + + cpe:/a:noguska:nola:1.1.2 + cpe:/a:noguska:nola:1.1.1 + + CVE-2002-1841 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T08:45:00.000-04:00 + + + + BID + 5116 + + + VULN-DEV + 20020702 Re: Noguska Nola 1.1.1 [ Intranet Business Management Software ] + + + XF + nola-php-script-upload(9438) + + + VULN-DEV + 20020625 Noguska Nola 1.1.1 [ Intranet Business Management Software ] + + The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4. + + + + + + + + + cpe:/a:perlbot:perlbot:1.0_beta + + CVE-2002-1842 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.480-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:48:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5999 + + + BID + 5998 + + + XF + perlbot-email-command-execution(10402) + + + XF + perlbot-shell-command-execution(10401) + + Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address. + + + + + + + + + cpe:/a:perlbot:perlbot:1.9.2 + + CVE-2002-1843 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T08:50:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 6009 + + + BID + 6008 + + + XF + perlbot-filename-command-execution(10404) + + + XF + perlbot-text-command-execution(10403) + + Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm. + + + + + + + + + cpe:/a:microsoft:windows_media_player:6.3::solaris + + CVE-2002-1844 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.763-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-26T08:53:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6003 + + + XF + mediaplayer-world-writable-executables(10398) + + + BUGTRAQ + 20021018 Microsoft Windows Media Player for Sparc/Solaris vulnerability + + Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges. + + + + + + + + + + cpe:/a:yabb:yabb:1.40 + cpe:/a:yabb:yabb:1.41 + + CVE-2002-1845 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:39.903-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T14:26:00.000-04:00 + + + + BID + 6004 + + + XF + yabb-index-xss(10406) + + Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter. + + + + + + + + + + cpe:/a:yabb:yabb:1.40 + cpe:/a:yabb:yabb:1.41 + + CVE-2002-1846 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:40.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T14:27:00.000-04:00 + + + Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php. + + + + + + + + + + + + + cpe:/a:microsoft:windows_media_player:xp + cpe:/a:microsoft:windows_media_player:7.1 + cpe:/a:microsoft:windows_media_player:7 + cpe:/a:microsoft:windows_media_player:6.4 + cpe:/a:microsoft:windows_media_player:6.3 + + CVE-2002-1847 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:40.183-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T14:33:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5357 + + + XF + mediaplayer-mplay32-filename-bo(9727) + + Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability. + + + + + + + + + + + + cpe:/a:tightvnc:tightvnc:1.2 + cpe:/a:tightvnc:tightvnc:1.2.2 + cpe:/a:tightvnc:tightvnc:1.2.1 + cpe:/a:tightvnc:tightvnc:1.2.3 + + CVE-2002-1848 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:40.340-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T14:40:00.000-04:00 + + + + CONFIRM + http://www.tightvnc.com/changelog-win32.html + + + BID + 4835 + + TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords. + + + + + + + + + cpe:/a:parachat:parachat_server:4.0 + + CVE-2002-1849 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:40.497-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-26T14:42:00.000-04:00 + + + + BID + 5370 + + + XF + parachat-no-logoff-dos(9735) + + + BUGTRAQ + 20020731 FW: Parachat DoS Vulnerability + + ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users. + + + + + + + + + + cpe:/a:apache:http_server:2.0.39 + cpe:/a:apache:http_server:2.0.40 + + CVE-2002-1850 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:42.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-26T14:45:00.000-04:00 + + + + BID + 8725 + + + XF + apache-stderr-dos(10200) + + + SECTRACK + 1007823 + + + MISC + http://issues.apache.org/bugzilla/show_bug.cgi?id=22030 + + + BID + 5787 + + + BUGTRAQ + 20020923 Apache 2.0.(39|40) DOS (PHP!) + + + MLIST + [apache-httpd-dev] 20020925 CGI bucket needed + + + MISC + http://issues.apache.org/bugzilla/show_bug.cgi?id=10515 + + + CONFIRM + http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/generators/mod_cgi.c?r1=1.148.2.7&r2=1.148.2.8 + + mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script. + + + + + + + + + cpe:/a:ipswitch:ws_ftp_pro:7.5 + + CVE-2002-1851 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:40.793-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-26T14:47:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4850 + + + XF + wsftp-pro-client-bo(10185) + + Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors. + + + + + + + + + cpe:/a:monkey-project:monkey_http_daemon:0.5.0 + + CVE-2002-1852 + 2002-12-31T00:00:00.000-05:00 + 2012-10-24T00:00:00.000-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T14:49:00.000-04:00 + + + + + BID + 5829 + + + XF + monkey-url-request-xss(10229) + + + XF + monkey-url-test2pl-xss(10226) + + + BUGTRAQ + 20020930 XSS bug in Monkey (0.5.0) HTTP server + + Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl. + + + + + + + + + + cpe:/a:carlos_sanchez_valle:mynewsgroups:0.4.1 + cpe:/a:carlos_sanchez_valle:mynewsgroups:0.4 + + CVE-2002-1853 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.090-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-26T14:52:00.000-04:00 + + + + BID + 5836 + + + XF + mynewsgroups-message-subject-xss(10238) + + Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php. + + + + + + + + + cpe:/a:rlaj:rlaj_whois:1.0 + + CVE-2002-1854 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.247-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-26T14:55:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5113 + + + XF + rlaj-whois-command-execution(9439) + + Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field. + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-1855 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:07:00.000-04:00 + + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + + BID + 5119 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23164 + + + XF + webinf-dot-file-retrieval(9446) + + Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:hp:application_server:8.0 + + CVE-2002-1856 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.543-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:11:00.000-04:00 + + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:jo:jo_webserver:1.0_rc1 + + CVE-2002-1857 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.683-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:12:00.000-04:00 + + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:oracle:application_server:9.0.2.0.0 + cpe:/a:oracle:application_server:9.0.2.0.1 + + CVE-2002-1858 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.840-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:15:00.000-04:00 + + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert47rev1.pdf + + Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:orion%2a:orion_application_server:1.5.3 + + CVE-2002-1859 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:41.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:18:00.000-04:00 + + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:pramati:pramati_server:3.0 + + CVE-2002-1860 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.137-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-26T15:19:00.000-04:00 + + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:sybase:easerver:4.0 + + CVE-2002-1861 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.277-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-28T10:15:00.000-04:00 + + + + MISC + http://www.westpoint.ltd.uk/advisories/wp-02-0002.txt + + + BID + 5119 + + + XF + webinf-dot-file-retrieval(9446) + + Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). + + + + + + + + + cpe:/a:virtualzone:smartmail_server:2.0 + + CVE-2002-1862 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.450-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-28T10:19:00.000-04:00 + + + + BID + 6074 + + + XF + smartmail-terminate-connection-dos(10533) + + + BUGTRAQ + 20021031 SmartMail server DOS + + SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent. + + + + + + + + + cpe:/h:iomega:network_attached_storage:a300u + + CVE-2002-1863 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.620-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T10:27:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + iomega-ftp-shared-directories(10530) + + + BUGTRAQ + 20021101 Iomega NAS A300U security and inter-operability issues + + Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled. + + + + + + + + + + + + cpe:/a:sws:sws_simple_web_server:0.0.3 + cpe:/a:sws:sws_simple_web_server:0.1.0 + cpe:/a:sws:sws_simple_web_server:0.0.4 + cpe:/a:sws:sws_simple_web_server:0.1.1 + + CVE-2002-1864 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.777-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-28T10:30:00.000-04:00 + + + + BID + 5662 + + + XF + sws-webserver-directory-traversal(10070) + + + BUGTRAQ + 20020903 Re: SWS Web Server v0.1.0 Exploit + + Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request. + + + + + + + + + + + + + + + + + + + cpe:/h:linksys:befw11s4:1.42.7 + cpe:/h:linksys:befw11s4:1.37.2 + cpe:/h:d-link:di-804:4.68 + cpe:/h:linksys:befw11s4:1.4.2.7 + cpe:/h:linksys:befw11s4:1.37.9b + cpe:/h:linksys:wap11:1.4 + cpe:/h:d-link:dl-704:2.56_b5 + cpe:/h:linksys:wap11:1.3 + cpe:/h:linksys:befw11s4:1.40.3 + cpe:/h:d-link:dl-704:2.56_b6 + cpe:/h:linksys:befw11s4:1.37.2b + + CVE-2002-1865 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:42.933-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-28T10:34:00.000-04:00 + + + + BID + 6090 + + + XF + ap-embedded-http-dos(10537) + + + VULNWATCH + 20021101 Re: IDEFENSE DOS in Linksys BEFSR41 EtherFast Cable/DSL Router + More issues DLINK & LINKSYS + + Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header. + + + + + + + + + + + + cpe:/a:sws:sws_simple_web_server:0.0.3 + cpe:/a:sws:sws_simple_web_server:0.1.0 + cpe:/a:sws:sws_simple_web_server:0.0.4 + cpe:/a:sws:sws_simple_web_server:0.1.1 + + CVE-2002-1866 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.107-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-28T10:36:00.000-04:00 + + + + BID + 5659 + + + XF + sws-webserver-invalid-file-dos(10071) + + + BUGTRAQ + 20020903 Re: SWS Web Server v0.1.0 Exploit + + Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist. + + + + + + + + + + + cpe:/a:bizdesign:imagefolio:2.26 + cpe:/a:bizdesign:imagefolio:2.23 + cpe:/a:bizdesign:imagefolio:2.24 + + CVE-2002-1867 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.260-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T10:56:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4975 + + + XF + imagefolio-setup-cgi-access(9308) + + + BUGTRAQ + 20020609 [LoWNOISE] ImageFolio Pro 2.2 + + The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption). + + + + + + + + + + cpe:/a:daniel_stenberg:dispair:0.1 + cpe:/a:daniel_stenberg:dispair:0.2 + + CVE-2002-1868 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.417-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-28T15:53:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5392 + + + XF + dispair-execute-commands(9787) + + Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields. + + + + + + + + + + + + cpe:/a:heysoft:eventsave%2b:5.1 + cpe:/a:heysoft:eventsave%2b:5.2 + cpe:/a:heysoft:eventsave:5.1 + cpe:/a:heysoft:eventsave:5.2 + + CVE-2002-1869 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.557-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-28T20:12:00.000-04:00 + + + + BID + 6095 + + + XF + eventsave-event-log-loss(10535) + + + CONFIRM + http://www.heysoft.de/nt/eventlog/hsb01e.htm + + + SECTRACK + 1005517 + + Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer. + + + + + + + + + + + + cpe:/a:sws:sws_simple_web_server:0.0.3 + cpe:/a:sws:sws_simple_web_server:0.1.0 + cpe:/a:sws:sws_simple_web_server:0.0.4 + cpe:/a:sws:sws_simple_web_server:0.1.1 + + CVE-2002-1870 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:16:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5660 + + + XF + sws-webserver-recv-overwrite(10072) + + + BUGTRAQ + 20020903 Re: SWS Web Server v0.1.0 Exploit + + Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution. + + + + + + + + + + + + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2002-1871 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:43.870-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-28T20:19:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5208 + + + XF + solaris-pkgadd-insecure-permissions(9544) + + + SUNALERT + 45693 + + pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges. + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:sql_server:7.0:sp2 + cpe:/a:microsoft:sql_server:7.0 + cpe:/a:microsoft:sql_server:7.0:sp4 + cpe:/a:microsoft:sql_server:7.0:sp1 + cpe:/a:microsoft:sql_server:7.0:sp3 + cpe:/a:microsoft:sql_server:6.0 + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + cpe:/a:microsoft:sql_server:6.5 + + CVE-2002-1872 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-28T20:26:00.000-04:00 + + + + BID + 6097 + + + MISC + http://www.nextgenss.com/papers/tp-SQL2000.pdf + + + XF + mssql-weak-password-encryption(10542) + + + BUGTRAQ + 20021102 Weak Password Encryption Scheme in MS SQL Server + + Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. + + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000:sp2 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:2000:sp1 + + CVE-2002-1873 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.200-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:30:00.000-04:00 + + + + BID + 5412 + + + XF + exchange-msrpc-dos(9789) + + Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls. + + + + + + + + + + + + + cpe:/a:astrocam:astrocam:1.0.1:beta + cpe:/a:astrocam:astrocam:1.4:beta + cpe:/a:astrocam:astrocam:0.9-7-3:beta + cpe:/a:astrocam:astrocam:0.9-1-1:beta + cpe:/a:astrocam:astrocam:0.9-5-1:beta + + CVE-2002-1874 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.340-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-28T20:33:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6105 + + + XF + astrocam-cgi-command-execution(10538) + + + SECTRACK + 1005523 + + + CONFIRM + http://astrocam.svn.sourceforge.net/viewvc/astrocam/BUGS?view=markup + + astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect. + + + + + + + + + cpe:/a:mcafee:entercept_agent:2.5::win32 + + CVE-2002-1875 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.497-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:38:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5206 + + + XF + entercept-agent-password-exposure(9546) + + + NTBUGTRAQ + 20020710 Entercept Agent Password Exposure + + Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the entercept agent password, which could allow the administrators to log on as the entercept_agent account and conceal their identity. + + + + + + + + + + + cpe:/a:microsoft:exchange_server:2000:sp2 + cpe:/a:microsoft:exchange_server:2000 + cpe:/a:microsoft:exchange_server:2000:sp1 + + CVE-2002-1876 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.653-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:41:00.000-04:00 + + + + BID + 5413 + + + XF + exchange-license-dos(9791) + + Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS. + + + + + + + + + cpe:/h:netgear:fm114p + + CVE-2002-1877 + 2002-12-31T00:00:00.000-05:00 + 2009-10-14T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:46:00.000-04:00 + + + + + BID + 5667 + + + XF + netgear-fm114p-ip-bypass(10061) + + NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname. + + + + + + + + + + + cpe:/a:w-agora:w-agora:4.1.3 + cpe:/a:w-agora:w-agora:4.1.2 + cpe:/a:w-agora:w-agora:4.1.1 + + CVE-2002-1878 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:44.950-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-28T20:50:00.000-04:00 + + + + XF + wagora-file-include(9317) + + + CONFIRM + http://www.w-agora.net/current/view.php?site=support&bn=support_dl&key=1023878911&first=1023878911&last=957369563 + + + BID + 4977 + + + MISC + http://www.ifrance.com/kitetoua/tuto/W-Agora.txt + + + BUGTRAQ + 20020608 Security holes in LokwaBB and W-Agora + + PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter. + + + + + + + + + cpe:/a:lokwa:lokwabb:1.2.1 + + CVE-2002-1879 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.107-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-28T20:52:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4981 + + + XF + lokwa-bb-sql-injection(9318) + + + MISC + http://www.ifrance.com/kitetoua/tuto/LokwaBB.txt + + + BUGTRAQ + 20020608 Security holes in LokwaBB and W-Agora + + SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php. + + + + + + + + + cpe:/a:lokwa:lokwabb:1.2.2 + + CVE-2002-1880 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.247-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-29T10:24:00.000-04:00 + + + + MISC + http://www.ifrance.com/kitetoua/tuto/LokwaBB.txt + + + BUGTRAQ + 20020608 Security holes in LokwaBB and W-Agora + + LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php. + + + + + + + + + + + + + + + cpe:/a:macromedia:flash_player:6.0.47.0 + cpe:/a:macromedia:flash_player:6.0 + cpe:/a:macromedia:flash_player:5.0_r50 + cpe:/a:macromedia:flash_player:6.0.29.0 + cpe:/a:macromedia:flash_player:5.0 + cpe:/a:macromedia:flash_player:6.0.40.0 + cpe:/a:macromedia:flash_player:4.0_r12 + + CVE-2002-1881 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:27:00.000-04:00 + + + + BID + 5445 + + + XF + flash-swf-rot13-dos(9843) + + + BUGTRAQ + 20020811 Re: EEYE: Macromedia Shockwave Flash Malformed Header Overflow + + Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers. + + + + + + + + + + + + + + cpe:/a:oracle:e-business_suite:11.1 + cpe:/a:oracle:e-business_suite:11.2 + cpe:/a:oracle:e-business_suite:11.5 + cpe:/a:oracle:e-business_suite:11.6 + cpe:/a:oracle:e-business_suite:11.3 + cpe:/a:oracle:e-business_suite:11.4 + + CVE-2002-1882 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:30:00.000-04:00 + + + + BID + 5901 + + + XF + oracle-ebusiness-unauth-access(10285) + + + CONFIRM + http://www.oracle.com/technology/deploy/security/pdf/2002alert44rev1.pdf + + Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors. + + + + + + + + + cpe:/a:trolltech:qt_assistant:1.0 + + CVE-2002-1883 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.713-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:33:00.000-04:00 + + + + XF + qt-assistant-default-port(10227) + + + BID + 5833 + + + MLIST + [Qt-interest] 20020915 assistant leaves port unfiltered + + Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service. + + + + + + + + + cpe:/a:py-membres:py-membres:3.1 + + CVE-2002-1884 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:45.857-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:34:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5849 + + + XF + py-membres-admin-privileges(10308) + + + BUGTRAQ + 20021002 Multiple Web Security Holes + + index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin". + + + + + + + + + + + cpe:/a:powerphlogger:powerphlogger:2.0.9 + cpe:/a:powerphlogger:powerphlogger:2.2.1 + cpe:/a:powerphlogger:powerphlogger:2.2.2a + + CVE-2002-1885 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.010-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:37:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5860 + + + XF + powerphlogger-showhits-file-include(10309) + + + BUGTRAQ + 20021002 Multiple Web Security Holes + + PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter. + + + + + + + + + cpe:/a:tightauction:tightauction:3.0 + + CVE-2002-1886 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.153-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-29T10:41:00.000-04:00 + + + + BID + 5850 + + + XF + tightauction-config-information-disclosure(10310) + + + BUGTRAQ + 20021002 Multiple Web Security Holes + + TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password. + + + + + + + + + cpe:/a:gregory_kokanosky:phpmynewsletter:0.6.10 + + CVE-2002-1887 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.307-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-29T10:45:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + phpmynewsletter-customize-file-include(10288) + + + BUGTRAQ + 20021003 phpMyNewsletter + + + BID + 5886 + + PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. + + + + + + + + + cpe:/a:commonname:commonname_toolbar:3.5.2.0 + + CVE-2002-1888 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.450-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-31T20:21:00.000-04:00 + + + + BID + 5878 + + + XF + commonname-intranet-address-disclosure(10293) + + + BUGTRAQ + 20021003 CommonName Toolbar potentially exposes LAN web addresses + + CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names. + + + + + + + + + + + cpe:/a:logsurfer:logsurfer:1.5 + cpe:/a:logsurfer:logsurfer:1.5a + cpe:/a:logsurfer:logsurfer:1.41 + + CVE-2002-1889 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.607-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T20:29:00.000-04:00 + + + + BID + 5898 + + + XF + logsurfer-contextaction-offbyone-bo(10287) + + + CONFIRM + ftp://ftp.cert.dfn.de/pub/tools/audit/logsurfer/logsurfer.README.asc + + Off-by-one buffer overflow in the context_action function in context.c of Logsurfer 1.41 through 1.5a allows remote attackers to cause a denial of service (crash) via a malformed log entry. + + + + + + + + + cpe:/a:redhat:rhmask:1.0-9 + + CVE-2002-1890 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.747-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T20:40:00.000-04:00 + + + + BID + 4984 + + + XF + rhmask-mask-file-symlink(9335) + + rhmask 1.0-9 in Red Hat Linux 7.1 allows local users to overwrite arbitrary files via a symlink attack on the mask file. + + + + + + + + + cpe:/a:ayman_akt:ircit:0.3.1 + + CVE-2002-1891 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:46.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-31T20:42:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4998 + + + XF + ircit-invite-bo(9340) + + Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request. + + + + + + + + + cpe:/h:netgear:fvs318:1.1 + + CVE-2002-1892 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.027-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-31T20:45:00.000-04:00 + + + + BID + 5830 + + + XF + netgear-fvs318-plaintext-passwords(10216) + + + BUGTRAQ + 20021001 NETGEAR FVS318 Information Disclosure + + + VULNWATCH + 20020927 FVS318 Config stores usernames/passwd's in plain text + + NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information. + + + + + + + + + cpe:/a:argosoft:argosoft_mail_server:1.8.1.9::pro + + CVE-2002-1893 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.167-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T20:48:00.000-04:00 + + + + BID + 5906 + + + XF + argosoft-webmail-xss(10301) + + + BUGTRAQ + 20021006 ArGoSoft Web-Mail security problem + + Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message. + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0.3 + + CVE-2002-1894 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.323-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T20:55:00.000-04:00 + + + + BID + 6195 + + + CONFIRM + http://www.phpbb.com/phpBB/viewtopic.php?t=56283 + + + XF + phpbb-viewtopic-script-xss(10653) + + + BUGTRAQ + 20021118 XSS bug in phpBB + + Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. + + + + + + + + + + cpe:/a:apache:tomcat:3.3 + cpe:/a:apache:tomcat:4.0.4 + + CVE-2002-1895 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:00:00.000-04:00 + + + + XF + tomcat-get-device-dos(10348) + + + VULNWATCH + 20021011 Apache Tomcat 3.x and 4.0.x: Remote denial-of-service vulnerability + + + CONFIRM + http://tomcat.apache.org/security-4.html + + The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN. + + + + + + + + + cpe:/a:alsaplayer:alsaplayer:0.99.71 + + CVE-2002-1896 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.620-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-31T21:04:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5767 + + + XF + alsaplayer-command-line-bo(10157) + + + FULLDISC + 20020920 Alsasound local b0f (not an issue if not setuid root) + + + CONFIRM + http://cvs.sourceforge.net/viewcvs.py/alsaplayer/alsaplayer/app/Main.cpp.diff?r1=1.66&r2=1.67 + + + CONFIRM + http://alsaplayer.org/changelog.php3 + + Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument. + + + + + + + + + + + cpe:/a:mywebserver:mywebserver:1.0.0 + cpe:/a:mywebserver:mywebserver:1.0.1 + cpe:/a:mywebserver:mywebserver:1.0.2 + + CVE-2002-1897 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:50.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:06:00.000-04:00 + + + + BID + 5954 + + + CONFIRM + http://www.mywebserver.org/us/downloads/whats_new_in_this_version.shtml + + + XF + mywebserver-long-url-dos(10349) + + + BUGTRAQ + 20021012 Long URL crashes My Web Server 1.0.2 + + MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow. + + + + + + + + + cpe:/o:apple:mac_os_x:10.2 + + CVE-2002-1898 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:47.917-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-07-31T21:09:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5768 + + + XF + macos-terminal-url-link(10156) + + + APPLE + 2002-09-20 + + + MISC + http://apple.slashdot.org/apple/02/09/21/122236.shtml?tid=172 + + Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window. + + + + + + + + + + cpe:/a:icewarp:web_mail:3.3.3 + cpe:/a:icewarp:web_mail:3.3.5 + + CVE-2002-1899 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.057-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T21:11:00.000-04:00 + + + + XF + icewarp-name-xss(9866) + + + BUGTRAQ + 20021112 IceWarp 3.4.5 XSS *AGAIN* + + + BUGTRAQ + 20020814 IceWarp Webmail XSS + + Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter. + + + + + + + + + cpe:/a:pinboard:pinboard:1.0 + + CVE-2002-1900 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.213-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T21:13:00.000-04:00 + + + + BID + 4988 + + Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists. + + + + + + + + + cpe:/a:bodo_bauer:bbgallery:1.0 + + CVE-2002-1901 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.357-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-07-31T21:14:00.000-04:00 + + + + BID + 4992 + + Cross-site scripting (XSS) vulnerability in Bodo Bauer BBGallery 1.0 allows remote attackers to inject arbitrary web script or HTML via image tags. + + + + + + + + + + + + + + cpe:/a:markus_triska:cgiforum:1.0.5 + cpe:/a:markus_triska:cgiforum:1.0 + cpe:/a:markus_triska:cgiforum:1.0.1 + cpe:/a:markus_triska:cgiforum:1.0.2 + cpe:/a:markus_triska:cgiforum:1.0.3 + cpe:/a:markus_triska:cgiforum:1.0.4 + + CVE-2002-1902 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.510-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:20:00.000-04:00 + + + + BID + 4960 + + + XF + cgiforum-infinite-recursion-dos(10055) + + + CONFIRM + http://freshmeat.net/releases/86842/ + + CGIForum 1.0 through 1.05 allows remote attackers to cause a denial of service (infinite recursion) by creating a message board post that is a child of an outdated parent. + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.30 + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.33 + cpe:/a:university_of_washington:pine:4.44 + + CVE-2002-1903 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.667-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-31T21:23:00.000-04:00 + + + + BID + 4963 + + + XF + pine-username-disclosure(9297) + + Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information. + + + + + + + + + + + + cpe:/a:gaztek:ghttpd:1.4.3 + cpe:/a:gaztek:ghttpd:1.4.2 + cpe:/a:gaztek:ghttpd:1.4.1 + cpe:/a:gaztek:ghttpd:1.4 + + CVE-2002-1904 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:48.840-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:27:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5960 + + + CONFIRM + http://lynorics.sundawn.net/prog/ghttpd.html#versionen + + + XF + gaztek-httpd-log-bo(10361) + + Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request. + + + + + + + + + + cpe:/h:polycom:viavideo:3.0 + cpe:/h:polycom:viavideo:2.2 + + CVE-2002-1905 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.010-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:31:00.000-04:00 + + + + BID + 5964 + + + XF + viavideo-webserver-get-bo(10359) + + Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. + + + + + + + + + + cpe:/h:polycom:viavideo:3.0 + cpe:/h:polycom:viavideo:2.2 + + CVE-2002-1906 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.153-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:34:00.000-04:00 + + + + BID + 5962 + + + XF + viavideo-inc-request-dos(10360) + + The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open. + + + + + + + + + cpe:/a:telcondex:simplewebserver:2.06.20817 + + CVE-2002-1907 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.293-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:38:00.000-04:00 + + + + BID + 5961 + + + XF + simplewebserver-long-url-dos(10367) + + TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. + + + + + + + + + + cpe:/a:microsoft:internet_information_server:5.0 + cpe:/a:microsoft:internet_information_server:5.1 + + CVE-2002-1908 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.433-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-07-31T21:40:00.000-04:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/6C00C1F5QA.html + + + BID + 5907 + + + XF + iis-http-host-dos(10370) + + Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters. + + + + + + + + + + cpe:/a:click2learn:ingenium_learning_management_system:6.1 + cpe:/a:click2learn:ingenium_learning_management_system:5.1 + + CVE-2002-1909 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.573-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-31T21:42:00.000-04:00 + + + + BID + 5969 + + + XF + ingenium-config-sensitive-information(10387) + + Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password. + + + + + + + + + + cpe:/a:click2learn:ingenium_learning_management_system:6.1 + cpe:/a:click2learn:ingenium_learning_management_system:5.1 + + CVE-2002-1910 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.713-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-07-31T21:45:00.000-04:00 + + + + BID + 5970 + + + XF + ingenium-weak-encryption(10389) + + Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords. + + + + + + + + + + cpe:/a:zonelabs:zonealarm:3.1::pro + cpe:/a:zonelabs:zonealarm:3.0::pro + + CVE-2002-1911 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:49.870-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:33:00.000-04:00 + + + + BID + 5975 + + + XF + zonealarm-synflood-dos(10379) + + + BUGTRAQ + 20021017 Re: NSSI-2002-zonealarm3: ZoneAlarm Pro Denial of Service Vulnerability + + ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue. + + + + + + + + + + + cpe:/h:skystream:emr5000:1.16 + cpe:/h:skystream:emr5000:1.18 + cpe:/h:skystream:emr5000:1.17 + + CVE-2002-1912 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:35:00.000-04:00 + + + + MISC + http://www.globalintersec.com/adv/skystream-2002021001.txt + + + BID + 5977 + + + XF + skystream-emr5000-kernel-dos(10380) + + SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets. + + + + + + + + + cpe:/a:myphpnuke:myphpnuke:1.8.8 + + CVE-2002-1913 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.183-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T13:36:00.000-04:00 + + + + BID + 5982 + + + XF + myphpnuke-phptonuke-view-files(10396) + + + BUGTRAQ + 20021016 phptonuke allows Remote File Retrieving + + phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable. + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:dump:dump:0.4_b20 + cpe:/a:dump:dump:0.4_b12 + cpe:/a:dump:dump:0.4_b21 + cpe:/a:dump:dump:0.4_b22 + cpe:/a:dump:dump:0.4_b13 + cpe:/a:dump:dump:0.4_b23 + cpe:/a:dump:dump:0.4_b10 + cpe:/a:dump:dump:0.4_b24 + cpe:/a:dump:dump:0.4_b11 + cpe:/a:dump:dump:0.4_b25 + cpe:/a:dump:dump:0.4_b16 + cpe:/a:dump:dump:0.4_b26 + cpe:/a:dump:dump:0.4_b17 + cpe:/a:dump:dump:0.4_b27 + cpe:/a:dump:dump:0.4_b14 + cpe:/a:dump:dump:0.4_b28 + cpe:/a:dump:dump:0.4_b15 + cpe:/a:dump:dump:0.4_b29 + cpe:/a:dump:dump:0.4_b18 + cpe:/a:dump:dump:0.4_b19 + + CVE-2002-1914 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.323-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:39:00.000-04:00 + + + + BID + 5264 + + + XF + dump-flock-dumpdates-dos(9632) + + + REDHAT + RHSA-2005:583 + + + CONFIRM + http://support.avaya.com/elmodocs2/security/ASA-2006-156.htm + + dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.4:stable + cpe:/o:freebsd:freebsd:4.5:stable + cpe:/o:freebsd:freebsd:4.2:stable + cpe:/o:freebsd:freebsd:4.3:stable + cpe:/o:freebsd:freebsd:3.5:stable + cpe:/o:netbsd:netbsd:1.2.1 + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:freebsd:freebsd:3.5.1:release + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + cpe:/o:freebsd:freebsd:5.0 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:netbsd:netbsd:1.2 + cpe:/o:openbsd:openbsd:2.9 + cpe:/o:netbsd:netbsd:1.1 + cpe:/o:openbsd:openbsd:2.8 + cpe:/o:netbsd:netbsd:1.0 + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:3.5.1:stable + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.5 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:4.6 + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/o:freebsd:freebsd:4.6:release + cpe:/o:freebsd:freebsd:4.5:release + cpe:/o:freebsd:freebsd:4.3:release + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.1.1:release + + CVE-2002-1915 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.527-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:41:00.000-04:00 + + + + BID + 5265 + + + XF + tip-flock-acculog-dos(9633) + + tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file. + + + + + + + + + + cpe:/a:pirch:pirch_irc + cpe:/a:pirch:ruspirch + + CVE-2002-1916 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.793-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:43:00.000-04:00 + + + + MISC + http://www.securiteam.com/windowsntfocus/6F00A205QQ.html + + + XF + pirch-auto-log-dos(10395) + + Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries. + + + + + + + + + + cpe:/a:geeklog:geeklog:1.3.5_sr1 + cpe:/a:geeklog:geeklog:1.35 + + CVE-2002-1917 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:50.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T13:47:00.000-04:00 + + + + BID + 5271 + + + XF + geeklog-email-crlf-injection(9639) + + CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header. + + + + + + + + + + + + + + cpe:/a:microsoft:data_access_components:2.5:gold + cpe:/a:microsoft:data_access_components:2.6:gold + cpe:/a:microsoft:data_access_components:2.7:gold + cpe:/a:microsoft:data_access_components:2.5:sp2 + cpe:/a:microsoft:data_access_components:2.6:sp1 + cpe:/a:microsoft:data_access_components:2.5:sp1 + + CVE-2002-1918 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:51.107-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-01T13:49:00.000-04:00 + + + + XF + ms-ado-bo(10186) + + + BID + 4849 + + + MISC + http://www.nextgenss.com/vna/ms-ado.txt + + Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED. + + + + + + + + + cpe:/a:virtual_programming:vp-asp:4.0 + + CVE-2002-1919 + 2002-12-31T00:00:00.000-05:00 + 2009-04-11T00:14:39.577-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:55:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4861 + + + BUGTRAQ + 20020610 Re: VP-ASP shopping cart software. + + + BUGTRAQ + 20020527 Re: VP-ASP shopping cart software. + + SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields. + + + + + + + + + cpe:/a:datawizard:ftpxq:2.5 + + CVE-2002-1920 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:51.403-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T13:56:00.000-04:00 + + + + BID + 4862 + + + XF + ftpxq-mkd-bo(9189) + + Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:mysql:mysql:3.23.28:gamma + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:mysql:mysql:3.20.32a + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + cpe:/a:mysql:mysql:3.22.30 + + CVE-2002-1921 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:51.543-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T14:00:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5511 + + + XF + mysql-disabled-binding-loopback(9908) + + The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database. + + + + + + + + + + + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.2.8 + cpe:/a:jelsoft:vbulletin:2.2.2 + cpe:/a:jelsoft:vbulletin:2.2.3 + cpe:/a:jelsoft:vbulletin:2.2.0 + cpe:/a:jelsoft:vbulletin:2.2.1 + cpe:/a:jelsoft:vbulletin:2.2.6 + cpe:/a:jelsoft:vbulletin:2.0_rc2 + cpe:/a:jelsoft:vbulletin:2.2.7 + cpe:/a:jelsoft:vbulletin:2.0_rc3 + cpe:/a:jelsoft:vbulletin:2.2.4 + cpe:/a:jelsoft:vbulletin:2.2.5 + + CVE-2002-1922 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:51.777-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T14:08:00.000-04:00 + + + + BID + 5997 + + + XF + vBulletin-usercp-xss(10407) + + + BUGTRAQ + 20021018 vBulletin XSS Security Bug + + Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mysql:mysql:3.23.42 + cpe:/a:mysql:mysql:3.23.43 + cpe:/a:mysql:mysql:3.23.44 + cpe:/a:mysql:mysql:3.23.45 + cpe:/a:mysql:mysql:3.23.40 + cpe:/a:mysql:mysql:3.23.41 + cpe:/a:mysql:mysql:3.23.23 + cpe:/a:mysql:mysql:3.23.24 + cpe:/a:mysql:mysql:3.23.25 + cpe:/a:mysql:mysql:3.23.26 + cpe:/a:mysql:mysql:3.23.27 + cpe:/a:mysql:mysql:3.23.46 + cpe:/a:mysql:mysql:3.23.28 + cpe:/a:mysql:mysql:3.23.47 + cpe:/a:mysql:mysql:3.23.29 + cpe:/a:mysql:mysql:3.23.48 + cpe:/a:mysql:mysql:3.23.49 + cpe:/a:mysql:mysql:3.22.28 + cpe:/a:mysql:mysql:3.22.27 + cpe:/a:mysql:mysql:3.22.29 + cpe:/a:mysql:mysql:3.22.26 + cpe:/a:mysql:mysql:3.23.28:gamma + cpe:/a:mysql:mysql:3.23.34 + cpe:/a:mysql:mysql:3.23.31 + cpe:/a:mysql:mysql:3.23.30 + cpe:/a:mysql:mysql:3.20.32a + cpe:/a:mysql:mysql:3.23.10 + cpe:/a:mysql:mysql:3.23.52 + cpe:/a:mysql:mysql:3.23.51 + cpe:/a:mysql:mysql:3.23.50 + cpe:/a:mysql:mysql:3.23.39 + cpe:/a:mysql:mysql:3.23.37 + cpe:/a:mysql:mysql:3.23.38 + cpe:/a:mysql:mysql:3.23.36 + cpe:/a:mysql:mysql:3.23.9 + cpe:/a:mysql:mysql:3.23.8 + cpe:/a:mysql:mysql:3.23.3 + cpe:/a:mysql:mysql:3.23.2 + cpe:/a:mysql:mysql:3.22.32 + cpe:/a:mysql:mysql:3.23.5 + cpe:/a:mysql:mysql:3.23.4 + cpe:/a:mysql:mysql:3.22.30 + + CVE-2002-1923 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:51.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T14:11:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5513 + + + XF + mysql-win-logging-disabled(9909) + + The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection. + + + + + + + + + cpe:/a:apc:powerchute:5.0.2::plus + + CVE-2002-1924 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.183-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T14:14:00.000-04:00 + + + + BID + 5069 + + + MISC + http://www.security.nnov.ru/news2064.html + + + XF + powerchute-dir-world-writeable(9413) + + PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory. + + + + + + + + + + + cpe:/a:tiny_software:tiny_personal_firewall:3.0.6 + cpe:/a:tiny_software:tiny_personal_firewall:3.0 + cpe:/a:tiny_software:tiny_personal_firewall:3.0.5 + + CVE-2002-1925 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-01T14:17:00.000-04:00 + + + + BID + 5525 + + + XF + tinyfw-portscan-log-dos(9918) + + + BUGTRAQ + 20020820 NSSI-2002-tpfw: Tiny Personal Firewall 3.0 Denial of Service Vulnerabilities + + Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module. + + + + + + + + + cpe:/a:aquonics_scripting:aquonics_file_manager:1.5 + + CVE-2002-1926 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.497-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T14:20:00.000-04:00 + + + + BID + 5533 + + + XF + aquonics-filemanager-directory-traversal(9929) + + + BUGTRAQ + 20020821 bugtraq@security.nnov.ru list issues [2] + + Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string. + + + + + + + + + cpe:/a:aquonics_scripting:aquonics_file_manager:1.5 + + CVE-2002-1927 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.650-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T14:25:00.000-04:00 + + + + XF + aquonics-filemanager-userlist-access(9930) + + + BUGTRAQ + 20020821 bugtraq@security.nnov.ru list issues [2] + + Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file. + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2002 + + CVE-2002-1928 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T14:37:00.000-04:00 + + + + XF + 602pro-get-directory-tree(10450) + + + BUGTRAQ + 20021018 interSEC security advisory - Multiple bugs in Web602 web server + + 602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing "~" (tilde) or ".bak" extension. + + + + + + + + + + + cpe:/a:php_arena:pafiledb:1.1.3 + cpe:/a:php_arena:pafiledb:3.0 + cpe:/a:php_arena:pafiledb:2.1.1 + + CVE-2002-1929 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:52.933-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T14:39:00.000-04:00 + + + + BID + 6020 + + + BID + 6019 + + + BID + 6018 + + + XF + pafiledb-script-xss(10416) + + + MISC + http://www.securiteam.com/unixfocus/6J00Q0A5PK.html + + Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions. + + + + + + + + + + + + + + cpe:/a:an:an-httpd:1.41c + cpe:/a:an:an-httpd:1.41b + cpe:/a:an:an-httpd:1.41 + cpe:/a:an:an-httpd:1.40 + cpe:/a:an:an-httpd:1.39 + cpe:/a:an:an-httpd:1.38 + + CVE-2002-1930 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:53.073-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T14:41:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 6012 + + + XF + an-http-socks4-bo(10410) + + + VULNWATCH + 20021021 AN HTTPD SOCKS4 username Buffer Overflow Vulnerability + + Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username. + + + + + + + + + + cpe:/a:php_arena:pafiledb:1.1.3 + cpe:/a:php_arena:pafiledb:2.1.1 + + CVE-2002-1931 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:53.230-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T14:42:00.000-04:00 + + + + BID + 6021 + + + XF + pafiledb-url-request-xss(10451) + + + CONFIRM + http://www.phparena.net/downloads/pafiledb.php?action=license&id=1&file=16 + + Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + + CVE-2002-1932 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:15:54.663-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T14:52:00.000-04:00 + + + + BID + 5972 + + + XF + win-admin-alerts-fail(10377) + + + MSKB + Q329350 + + Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection. + + + + + + + + + + + + cpe:/o:microsoft:windows_2000_terminal_services::sp3 + cpe:/o:microsoft:windows_2000_terminal_services::sp2 + cpe:/o:microsoft:windows_2000_terminal_services::sp1 + cpe:/o:microsoft:windows_2000_terminal_services + + CVE-2002-1933 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:53.543-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-01T14:54:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5535 + + + XF + win2k-ts-screensaver-unlocked(9946) + + The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window. + + + + + + + + + + + + + cpe:/h:pingtel:xpressa:2.0 + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.8 + cpe:/h:pingtel:xpressa:1.2.7.4 + cpe:/h:pingtel:xpressa:2.0.1 + + CVE-2002-1934 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:53.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T15:01:00.000-04:00 + + + + MISC + http://www.sys-security.com/archive/advisories/More_Vulnerabilities_with_Pingtel_xpressa_SIP-based_IP_phones.txt + + + BID + 5534 + + + XF + pingtel-xpressa-information-leak(9948) + + Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information. + + + + + + + + + + + + + cpe:/h:pingtel:xpressa:2.0 + cpe:/h:pingtel:xpressa:1.2.5 + cpe:/h:pingtel:xpressa:1.2.8 + cpe:/h:pingtel:xpressa:1.2.7.4 + cpe:/h:pingtel:xpressa:2.0.1 + + CVE-2002-1935 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:53.857-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T15:04:00.000-04:00 + + + + MISC + http://www.sys-security.com/archive/advisories/More_Vulnerabilities_with_Pingtel_xpressa_SIP-based_IP_phones.txt + + + BID + 5537 + + + XF + pingtel-xpressa-weak-parameters(9949) + + Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar. + + + + + + + + + cpe:/h:utstarcom:bas_1000:3.1.10 + + CVE-2002-1936 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.010-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T15:07:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5564 + + + XF + utstarcom-bas-default-accounts(9951) + + UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase". + + + + + + + + + + + cpe:/h:symantec:firewall_vpn_appliance_200r + cpe:/h:symantec:firewall_vpn_appliance_100 + cpe:/h:symantec:firewall_vpn_appliance_200 + + CVE-2002-1937 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-01T15:11:00.000-04:00 + + + + XF + firewallvpn-arp-mitm(10442) + + + BUGTRAQ + 20021022 Re: Sniffing Administrator's Password in Symantec Firewall/VPN Appliance V. 200R + + + BUGTRAQ + 20021022 Sniffing Administrator's Password in Symantec Firewall/VPN Appliance V. 200R + + Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password. + + + + + + + + + cpe:/a:virgil:cgi_scanner:0.9 + + CVE-2002-1938 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.323-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-01T15:14:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 6031 + + + XF + virgil-cgi-execute-commands(10444) + + Virgil CGI Scanner 0.9 allows remote attackers to execute arbitrary commands via the (1) tar (TARGET) or (2) zielport (ZIELPORT) parameters. + + + + + + + + + cpe:/a:flashfxp:flashfxp:1.4 + + CVE-2002-1939 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.463-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T15:16:00.000-04:00 + + + + XF + flashfxp-password-disclosure(10445) + + + BID + 6032 + + FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties. + + + + + + + + + cpe:/a:jacob_navia:lcc-win32:3.2 + + CVE-2002-1940 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-01T15:18:00.000-04:00 + + + + BID + 5391 + + + XF + lccwin32-binary-file-disclosure(9749) + + + BUGTRAQ + 20020802 Lcc-win32 infos diffusion + + LCC-Win32 3.2 compiler, when running on Windows 95, 98, or ME, writes portions of previously used memory after the import table, which could allow attackers to gain sensitive information. NOTE: it has been reported that this problem is due to the OS and not the application. + + + + + + + + + cpe:/a:radiobird_software:web_server_4_everyone:1.28 + + CVE-2002-1941 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.760-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:07:00.000-04:00 + + + + BID + 6034 + + + XF + webserver-4everyone-host-bo(10447) + + Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set. + + + + + + + + + cpe:/a:imatix:xitami:2.5_b5 + + CVE-2002-1942 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:54.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:14:00.000-04:00 + + + + BID + 5394 + + + XF + xitami-keep-alive-dos(9751) + + + BUGTRAQ + 20020804 Clarification on Xitami DoS + + + BUGTRAQ + 20020802 Xitami Connection Flood Server Termination Vulnerability + + Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (crash) via a large number of concurrent sessions. + + + + + + + + + cpe:/a:safetp:safetp_server:1.46 + + CVE-2002-1943 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-02T11:16:00.000-04:00 + + + + BID + 5822 + + + XF + safetp-passivemode-ip-disclosure(10210) + + SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PASV) file transfer request. + + + + + + + + + cpe:/h:motorola:surfboard:4200 + + CVE-2002-1944 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:18:00.000-04:00 + + + + XF + motorola-surfboard-portscan-dos(10513) + + + BUGTRAQ + 20021030 Motorola Cable Modem DOS + + Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap. + + + + + + + + + cpe:/a:virtualzone:smartmail_server:1.0_beta_10 + + CVE-2002-1945 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.340-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:40:00.000-04:00 + + + + BID + 6075 + + + XF + smartmail-server-ports-dos(10512) + + + BUGTRAQ + 20021031 SmartMail server DOS + + Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3). + + + + + + + + + cpe:/a:videsh_sanchar_nigam_limited:integrated_dialer_software:1.2.000 + + CVE-2002-1946 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.497-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-02T11:42:00.000-04:00 + + + + XF + integrated-dialer-weak-encryption(10517) + + + BUGTRAQ + 20021101 Weak Password Encryption Scheme in Integrated Dialer + + Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:1.0.00 + cpe:/a:webmin:webmin:0.76 + cpe:/a:webmin:webmin:0.99 + cpe:/a:webmin:webmin:0.98 + cpe:/a:webmin:webmin:0.78 + cpe:/a:webmin:webmin:0.97 + cpe:/a:webmin:webmin:0.88 + cpe:/a:webmin:webmin:0.77 + cpe:/a:webmin:webmin:0.79 + cpe:/a:webmin:webmin:0.42 + cpe:/a:webmin:webmin:0.92 + cpe:/a:webmin:webmin:0.22 + cpe:/a:webmin:webmin:0.31 + cpe:/a:webmin:webmin:0.41 + cpe:/a:webmin:webmin:0.91 + cpe:/a:webmin:webmin:0.21 + cpe:/a:webmin:webmin:0.51 + cpe:/a:webmin:webmin:0.80 + cpe:/a:webmin:webmin:0.96 + cpe:/a:webmin:webmin:0.95 + cpe:/a:webmin:webmin:0.94 + cpe:/a:webmin:webmin:0.85 + cpe:/a:webmin:webmin:0.93 + + CVE-2002-1947 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.637-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-02T11:45:00.000-04:00 + + + + BID + 5936 + + + XF + webmin-identical-ssl-keys(10381) + + + CONFIRM + http://www.webmin.com/changes.html + + + FREEBSD + FreeBSD-SA-02:06 + + Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. + + + + + + + + + cpe:/a:gringotts:gringotts:0.5.9 + + CVE-2002-1948 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.840-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-02T11:48:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5488 + + + XF + gringotts-multiple-bo(9882) + + Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors. + + + + + + + + + cpe:/h:iomega:nas:a300u + + CVE-2002-1949 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:55.997-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-02T11:51:00.000-04:00 + + + + BID + 6092 + + + XF + iomega-plaintext-administrative-password(10521) + + + BUGTRAQ + 20021101 Iomega NAS A300U security and inter-operability issues + + The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password. + + + + + + + + + cpe:/a:phprank:phprank:1.8 + + CVE-2002-1950 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.137-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-02T11:54:00.000-04:00 + + + + BID + 5946 + + + XF + phprank-banner-url-xss(10351) + + + BUGTRAQ + 20021010 Multiple vulnerabilities in phpRank + + Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list. + + + + + + + + + cpe:/a:goahead_software:goahead_webserver:2.1 + + CVE-2002-1951 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.277-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:56:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5464 + + + MISC + http://www.securiteam.com/securitynews/5MP0C1580W.html + + + XF + goahead-long-url-bo(9884) + + Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. + + + + + + + + + cpe:/a:phprank:phprank:1.8 + + CVE-2002-1952 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.433-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-02T11:59:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5948 + + + XF + phprank-null-bypass-authentication(10353) + + + BUGTRAQ + 20021010 Multiple vulnerabilities in phpRank + + phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable. + + + + + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.4 + cpe:/a:aol:instant_messenger:4.6 + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.8.2616 + cpe:/a:aol:instant_messenger:4.8.2646 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:4.7.2480 + + CVE-2002-1953 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.573-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-02T12:03:00.000-04:00 + + + + BID + 5492 + + + XF + aim-goim-screenname-bo(9950) + + Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy. + + + + + + + + + cpe:/a:php:php:4.2.3 + + CVE-2002-1954 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.730-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-02T12:10:00.000-04:00 + + + + MISC + http://www.techie.hopto.org/vulns/2002-36.txt + + + XF + php-phpinfo-xss(10355) + + + VULNWATCH + 20021013 PHP Information Functions May Allow Cross-Site Scripting + + + BUGTRAQ + 20030603 PHP XSS exploit in phpinfo() + + Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php. + + + + + + + + + cpe:/h:iomega:nas:a300u + + CVE-2002-1955 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:56.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-02T12:16:00.000-04:00 + + + + BID + 6093 + + + XF + iomega-nas-a300u-mitm(10523) + + + BUGTRAQ + 20021101 Iomega NAS A300U security and inter-operability issues + + Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack. + + + + + + + + + + cpe:/a:rox:filer:1.2 + cpe:/a:rox:filer:1.1.9 + + CVE-2002-1956 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.027-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-02T12:25:00.000-04:00 + + + + BID + 5172 + + + XF + rox-filer-insecure-permissions(9504) + + ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files. + + + + + + + + + + cpe:/a:pen:pen:0.9.2 + cpe:/a:pen:pen:0.9.1 + + CVE-2002-1957 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.167-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-05T14:35:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5152 + + + XF + pen-netlog-bo(9505) + + + CONFIRM + http://siag.nu/pen/news-0.9.3.shtml + + Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages. + + + + + + + + + + + cpe:/a:kmmail:kmmail:1.0 + cpe:/a:kmmail:kmmail:1.0b + cpe:/a:kmmail:kmmail:1.0a + + CVE-2002-1958 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.323-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-08T11:07:00.000-04:00 + + + + + BID + 5173 + + + XF + kmmail-safe-tag-xss(9507) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=191501 + + + BID + 6013 + + + FULLDISC + 20021021 kmMail XSS + + Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field. + + + + + + + + + + + cpe:/a:nagios:nagios:1.0_b2 + cpe:/a:nagios:nagios:1.0_b3 + cpe:/a:nagios:nagios:1.0_b1 + + CVE-2002-1959 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.480-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-08T11:09:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5174 + + + XF + nagios-plugin-command-execution(9508) + + + CONFIRM + http://www.nagios.org/changelog.php + + Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output. + + + + + + + + + cpe:/a:cybozu:share360:1.1 + + CVE-2002-1960 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.620-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-08T11:14:00.000-04:00 + + + + BID + 5151 + + + XF + share360-xss(9510) + + Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link. + + + + + + + + + + cpe:/a:finjan_software:surfingate:6.0 + cpe:/a:finjan_software:surfingate:6.0.1 + + CVE-2002-1961 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-08T11:35:00.000-04:00 + + + + BID + 5634 + + + XF + finjan-surfingate-dot-bypass(10037) + + + BUGTRAQ + 20020904 RE: Bypassing the Finjan SurfinGate URL filter + + + BUGTRAQ + 20020904 Bypassing the Finjan SurfinGate URL filter + + Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a "." (dot). + + + + + + + + + + cpe:/a:finjan_software:surfingate:6.0 + cpe:/a:finjan_software:surfingate:6.0.1 + + CVE-2002-1962 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:57.917-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-08T11:37:00.000-04:00 + + + + BID + 5629 + + + XF + finjan-surfingate-ip-bypass(10038) + + + BUGTRAQ + 20020904 RE: Bypassing the Finjan SurfinGate URL filter + + + BUGTRAQ + 20020904 Bypassing the Finjan SurfinGate URL filter + + Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.18::x86 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + + CVE-2002-1963 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.073-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-08T14:36:00.000-04:00 + + + + BID + 5178 + + + XF + linux-file-limit-dos(9515) + + Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries. + + + + + + + + + cpe:/a:wesmo:phpeventcalendar:1.1 + + CVE-2002-1964 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.293-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-08T14:38:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5021 + + Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors. + + + + + + + + + + cpe:/a:imatix:xitami:2.5_b4 + cpe:/a:imatix:xitami:2.5_b5 + + CVE-2002-1965 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.433-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-08T14:40:00.000-04:00 + + + + BID + 5025 + + Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request. + + + + + + + + + + cpe:/a:my_postcards:my_postcards_platinum:6.0 + cpe:/a:my_postcards:my_postcards_platinum:5.0 + + CVE-2002-1966 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.590-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-08T14:42:00.000-04:00 + + + + BID + 5029 + + + MISC + http://www.securiteam.com/unixfocus/5IP0G2K7FQ.html + + + MISC + http://packetstormsecurity.nl/0206-exploits/magiccard_vuln.txt + + Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. + + + + + + + + + cpe:/a:mark_hanson:xircon:1.0_beta_4 + + CVE-2002-1967 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.730-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-08T14:43:00.000-04:00 + + + + BID + 5185 + + + XF + xircon-client-command-dos(9516) + + + VULNWATCH + 20020705 bug + + Buffer overflow in XiRCON 1.0 Beta 4 allows remote attackers to cause a denial of service (disconnect) via a long (1) ctcp, (2) primsg, (3) msg, or (4) notice command. + + + + + + + + + cpe:/h:com21:doxport_1100:2.1.1.106 + + CVE-2002-1968 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:58.887-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-08T14:46:00.000-04:00 + + + + XF + com21-doxport-config-file(10543) + + + SECTRACK + 1005524 + + + BUGTRAQ + 20021128 Lag Security Advisory - Com21 cable modem configuration file feeding vulnerability + + Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server. + + + + + + + + + + cpe:/a:the_magic_notebook:the_magic_notebook:1.0b + cpe:/a:the_magic_notebook:the_magic_notebook:1.1b + + CVE-2002-1969 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.043-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-08T14:49:00.000-04:00 + + + + BID + 6106 + + + XF + magic-book-username-dos(10562) + + Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login. + + + + + + + + + cpe:/a:snortcenter:snortcenter:0.9.5 + + CVE-2002-1970 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.183-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-08T14:51:00.000-04:00 + + + + BID + 6109 + + + XF + snortcenter-tmp-file-insecure(10540) + + + BUGTRAQ + 20021105 SnortCenter 0.9.5 temp file naming problems... + + SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers. + + + + + + + + + cpe:/a:sourcecraft:networking_utils:1.0 + + CVE-2002-1971 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.323-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-08T14:53:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6107 + + + XF + networkingutils-ping-read-files(10541) + + + SECTRACK + 1005543 + + + BUGTRAQ + 20021105 networking_utils.php + + The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument. + + + + + + + + + cpe:/a:sebastian_dehne:pp_powerswitch:0.1 + + CVE-2002-1972 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.480-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-09T08:04:00.000-04:00 + + + + XF + pp-powerswitch-port-access(10552) + + + SECTRACK + 1005534 + + + CONFIRM + http://freshmeat.net/releases/101529/ + + Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports. + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:personal_1.7.3 + cpe:/a:microsoft:foundation_class_library:7.0 + + CVE-2002-1973 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:03.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-09T08:20:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020712 MFC Overflow Test Code + + + XF + mfc-lib-isapi-bo(9529) + + + BID + 5188 + + + MSKB + 310649 + + + MSKB + 216562 + + + BUGTRAQ + 20020712 Re: MFC ISAPI Framework Buffer Overflow + + + BUGTRAQ + 20020711 MFC ISAPI Framework Buffer Overflow + + + BUGTRAQ + 20020708 ALERT: Working Resources BadBlue #2 (DoS, Heap Overflow) + + Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error. + + + + + + + + + + cpe:/a:sharp:zaurus:sl-5500 + cpe:/a:sharp:zaurus:sl-5000d + + CVE-2002-1974 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.760-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-09T08:22:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5200 + + + XF + zaurus-insecure-ftp-permissions(9534) + + The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root. + + + + + + + + + + cpe:/a:sharp:zaurus:sl-5500 + cpe:/a:sharp:zaurus:sl-5000d + + CVE-2002-1975 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:31:59.917-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T08:24:00.000-04:00 + + + + BID + 5201 + + + XF + zaurus-passcode-weak-encryption(9535) + + Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.18::x86 + cpe:/o:linux:linux_kernel:2.2.9 + cpe:/o:linux:linux_kernel:2.2.20 + cpe:/o:linux:linux_kernel:2.2.8 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.2.7 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.2.6 + cpe:/o:linux:linux_kernel:2.2.17 + cpe:/o:linux:linux_kernel:2.2.18 + cpe:/o:linux:linux_kernel:2.2.19 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.9 + cpe:/o:linux:linux_kernel:2.4.8 + cpe:/o:linux:linux_kernel:2.4.5 + cpe:/o:linux:linux_kernel:2.3.0 + cpe:/o:linux:linux_kernel:2.4.4 + cpe:/o:linux:linux_kernel:2.4.7 + cpe:/o:linux:linux_kernel:2.4.6 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.2 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.3 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.2.12 + cpe:/o:linux:linux_kernel:2.2.11 + cpe:/o:linux:linux_kernel:2.2.10 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.2.16 + cpe:/o:linux:linux_kernel:2.2.15 + cpe:/o:linux:linux_kernel:2.2.14 + cpe:/o:linux:linux_kernel:2.2.13 + cpe:/o:linux:linux_kernel:2.2.2 + cpe:/o:linux:linux_kernel:2.2.3 + cpe:/o:linux:linux_kernel:2.2.4 + cpe:/o:linux:linux_kernel:2.2.5 + cpe:/o:linux:linux_kernel:2.2.0 + cpe:/o:linux:linux_kernel:2.2.1 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.3.99 + + CVE-2002-1976 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:00.073-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T08:28:00.000-04:00 + + + + BID + 5304 + + + XF + linux-ifconfig-promiscuous-mode(9676) + + + BUGTRAQ + 20020724 Interface promiscuity obscurity in Linux + + ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap. + + + + + + + + + + cpe:/a:pgp:pgp:7.0.4 + cpe:/a:pgp:pgp:7.1 + + CVE-2002-1977 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:00.323-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T08:35:00.000-04:00 + + + + XF + pgp-passphrase-cache(9690) + + + BID + 5318 + + + BUGTRAQ + 20020725 RE: PGP 7.04 Patch Modifies the Password Cache Setting + + + BUGTRAQ + 20020725 PGP 7.04 Patch Modifies the Password Cache Setting + + Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:darren_reed:ipfilter:3.3.3 + cpe:/a:darren_reed:ipfilter:3.3.2 + cpe:/a:darren_reed:ipfilter:3.3.1 + cpe:/a:darren_reed:ipfilter:3.1.6 + cpe:/a:darren_reed:ipfilter:3.1.7 + cpe:/a:darren_reed:ipfilter:3.1.8 + cpe:/a:darren_reed:ipfilter:3.1.9 + cpe:/a:darren_reed:ipfilter:3.4.1 + cpe:/a:darren_reed:ipfilter:3.4.2 + cpe:/a:darren_reed:ipfilter:3.2.4 + cpe:/a:darren_reed:ipfilter:3.2.3 + cpe:/a:darren_reed:ipfilter:3.2.2 + cpe:/a:darren_reed:ipfilter:3.2.1 + cpe:/a:darren_reed:ipfilter:3.3.10 + cpe:/a:darren_reed:ipfilter:3.3.15 + cpe:/a:darren_reed:ipfilter:3.3.16 + cpe:/a:darren_reed:ipfilter:3.3.17 + cpe:/a:darren_reed:ipfilter:3.3.18 + cpe:/a:darren_reed:ipfilter:3.3.11 + cpe:/a:darren_reed:ipfilter:3.3.12 + cpe:/a:darren_reed:ipfilter:3.3.13 + cpe:/a:darren_reed:ipfilter:3.3.14 + cpe:/a:darren_reed:ipfilter:3.2.5 + cpe:/a:darren_reed:ipfilter:3.4.9 + cpe:/a:darren_reed:ipfilter:3.2.6 + cpe:/a:darren_reed:ipfilter:3.4.8 + cpe:/a:darren_reed:ipfilter:3.2.7 + cpe:/a:darren_reed:ipfilter:3.4.7 + cpe:/a:darren_reed:ipfilter:3.2.8 + cpe:/a:darren_reed:ipfilter:3.4.6 + cpe:/a:darren_reed:ipfilter:3.2.9 + cpe:/a:darren_reed:ipfilter:3.4.5 + cpe:/a:darren_reed:ipfilter:3.4.4 + cpe:/a:darren_reed:ipfilter:3.4.3 + cpe:/a:darren_reed:ipfilter:3.3.8 + cpe:/a:darren_reed:ipfilter:3.1.5 + cpe:/a:darren_reed:ipfilter:3.3.9 + cpe:/a:darren_reed:ipfilter:3.1.4 + cpe:/a:darren_reed:ipfilter:3.1.3 + cpe:/a:darren_reed:ipfilter:3.1.2 + cpe:/a:darren_reed:ipfilter:3.3.4 + cpe:/a:darren_reed:ipfilter:3.1.1 + cpe:/a:darren_reed:ipfilter:3.3.5 + cpe:/a:darren_reed:ipfilter:3.3.6 + cpe:/a:darren_reed:ipfilter:3.3.7 + cpe:/a:darren_reed:ipfilter:3.2.10 + cpe:/a:darren_reed:ipfilter:3.2.11 + cpe:/a:darren_reed:ipfilter:3.2.12 + cpe:/a:darren_reed:ipfilter:3.2.13 + cpe:/a:darren_reed:ipfilter:3.2.14 + cpe:/a:darren_reed:ipfilter:3.2.15 + cpe:/a:darren_reed:ipfilter:3.2.16 + cpe:/a:darren_reed:ipfilter:3.2.17 + cpe:/a:darren_reed:ipfilter:3.1.10 + cpe:/a:darren_reed:ipfilter:3.4.13 + cpe:/a:darren_reed:ipfilter:3.4.12 + cpe:/a:darren_reed:ipfilter:3.4.15 + cpe:/a:darren_reed:ipfilter:3.4.14 + cpe:/a:darren_reed:ipfilter:3.4.17 + cpe:/a:darren_reed:ipfilter:3.4.16 + cpe:/a:darren_reed:ipfilter:3.4.19 + cpe:/a:darren_reed:ipfilter:3.4.18 + cpe:/a:darren_reed:ipfilter:3.4.11 + cpe:/a:darren_reed:ipfilter:3.4.10 + cpe:/a:darren_reed:ipfilter:3.2.21 + cpe:/a:darren_reed:ipfilter:3.2.22 + cpe:/a:darren_reed:ipfilter:3.3.19 + cpe:/a:darren_reed:ipfilter:3.2.20 + cpe:/a:darren_reed:ipfilter:3.4.26 + cpe:/a:darren_reed:ipfilter:3.4.25 + cpe:/a:darren_reed:ipfilter:3.4.24 + cpe:/a:darren_reed:ipfilter:3.4.23 + cpe:/a:darren_reed:ipfilter:3.3.20 + cpe:/a:darren_reed:ipfilter:3.3.21 + cpe:/a:darren_reed:ipfilter:3.4.28 + cpe:/a:darren_reed:ipfilter:3.4.27 + cpe:/a:darren_reed:ipfilter:3.2.19 + cpe:/a:darren_reed:ipfilter:3.3.22 + cpe:/a:darren_reed:ipfilter:3.2.18 + cpe:/a:darren_reed:ipfilter:3.4.22 + cpe:/a:darren_reed:ipfilter:3.4.21 + cpe:/a:darren_reed:ipfilter:3.4.20 + + CVE-2002-1978 + 2002-12-31T00:00:00.000-05:00 + 2009-04-03T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-09T08:38:00.000-04:00 + + + + + CERT-VN + VU#328867 + + + BID + 6010 + + + XF + ip-filter-bypass-firewall(10409) + + + SECTRACK + 1005442 + + + NETBSD + NetBSD-SA2002-024 + + IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server. + + + + + + + + + + + cpe:/h:watchguard:legacy_rssa:3.2_sp1 + cpe:/h:watchguard:soho:5.1.6 + cpe:/h:watchguard:vclass:3.2_sp1 + + CVE-2002-1979 + 2002-12-31T00:00:00.000-05:00 + 2009-04-03T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-09T08:41:00.000-04:00 + + + + + CERT-VN + VU#328867 + + + CONFIRM + http://www.kb.cert.org/vuls/id/AAMN-5EQR65 + + WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:8.0 + cpe:/o:sun:solaris:2.5.1 + + CVE-2002-1980 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:00.963-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-09T08:47:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5207 + + + XF + solaris-vold-bo(9545) + + + SUNALERT + 45707 + + Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors. + + + + + + + + + + + cpe:/a:microsoft:sql_server:2000:sp1 + cpe:/a:microsoft:sql_server:2000:sp2 + cpe:/a:microsoft:sql_server:2000 + + CVE-2002-1981 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.137-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-09T08:58:00.000-04:00 + + + + BID + 5604 + + + MISC + http://www.ngssoftware.com/advisories/mssql-sp_MSSetServerProperties.txt + + + XF + mssql-sp-public-access(10012) + + + BUGTRAQ + 20020902 Microsoft SQL Server Stored procedures [sp_MSSetServerPropertiesn and sp_MSsetalertinfo] (#NISR03092002A) + + Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings. + + + + + + + + + cpe:/a:icecast:icecast:1.3.12 + + CVE-2002-1982 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.277-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T19:35:00.000-04:00 + + + + BID + 5189 + + + XF + icecast-dotdot-information-disclosure(9530) + + Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not. + + + + + + + + + cpe:/a:qnx:rtos:6.1.0 + + CVE-2002-1983 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.417-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-09T19:37:00.000-04:00 + + + + XF + qnx-rtp-timer-dos(10550) + + + BID + 6114 + + + BUGTRAQ + 20021106 QNX 6.1 TimeCreate weakness + + The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-1984 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.573-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-09T19:41:00.000-04:00 + + + + BID + 5094 + + + BUGTRAQ + 20020625 A DoS against IE in W2K and XP? You Make the Call... + + Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046". + + + + + + + + + cpe:/a:incognito_software_inc:ismtp_gateway:5.0.1 + + CVE-2002-1985 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.730-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-09T19:44:00.000-04:00 + + + + MISC + http://www.nii.co.in/vuln/ismtp.html + + + XF + ismtp-mailfrom-command-bo(10577) + + + BUGTRAQ + 20021111 Buffer Overflow in iSMTP Gateway + + + BID + 6151 + + iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow. + + + + + + + + + + + cpe:/a:perception:liteserve:2.0 + cpe:/a:perception:liteserve:2.0.2 + cpe:/a:perception:liteserve:2.0.1 + + CVE-2002-1986 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:01.887-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T19:47:00.000-04:00 + + + + XF + liteserve-script-source-disclosure(10635) + + + BID + 6188 + + + VULNWATCH + 20021114 Perception LiteServe HTTP CGI Disclosure Vulnerability + + Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot ("."). + + + + + + + + + cpe:/a:caucho_technology:resin:2.1.2 + + CVE-2002-1987 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.027-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-09T19:51:00.000-04:00 + + + + BID + 5031 + + + XF + resin-viewsource-directory-traversal(9351) + + Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot). + + + + + + + + + cpe:/a:caucho_technology:resin:2.1.1 + + CVE-2002-1988 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.183-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-09T19:54:00.000-04:00 + + + + BID + 5032 + + + XF + resin-large-variable-dos(9352) + + Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources. + + + + + + + + + cpe:/a:caucho_technology:resin:2.1.1 + + CVE-2002-1989 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-09T21:37:00.000-04:00 + + + + VULNWATCH + 20020617 KPMG-2002022: Resin DOS device Denial of Service + + Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp. + + + + + + + + + + + cpe:/a:caucho_technology:resin:2.0 + cpe:/a:caucho_technology:resin:2.1.1 + cpe:/a:caucho_technology:resin:2.1.2 + + CVE-2002-1990 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.480-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-10T10:17:00.000-04:00 + + + + BID + 5095 + + + XF + resin-example-path-disclosure(9419) + + Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet. + + + + + + + + + cpe:/a:oscommerce:oscommerce:2.1 + + CVE-2002-1991 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-10T10:31:00.000-04:00 + + + + + CONFIRM + http://www.oscommerce.com/about.php/news,72 + + + BID + 5037 + + + XF + oscommerce-include-remote-files(9369) + + PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php. + + + + + + + + + + + cpe:/a:macromedia:coldfusion_professional + cpe:/a:macromedia:coldfusion:::developer + cpe:/a:macromedia:coldfusion + + CVE-2002-1992 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.777-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-10T10:34:00.000-04:00 + + + + BID + 5121 + + + CONFIRM + http://www.macromedia.com/v1/handlers/index.cfm?ID=23161 + + + XF + coldfusion-mx-jrundll-bo(9460) + + Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.22 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.33 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:5.0 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.12 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.11 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.10 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.32 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.31 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.21 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.30 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.20 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.0 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.1 + cpe:/a:affordable_web_space_design:affordable_web_space_design_webbbs:4.2 + + CVE-2002-1993 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:02.963-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-10T10:39:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5048 + + + XF + webbs-followup-execute-commands(9378) + + + BUGTRAQ + 20020618 WebBBS 5.0 (andlater versions) vulnerable: allow commands execution via "followup" bug + + webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter. + + + + + + + + + cpe:/a:gamecheats:advanced_web_server_professional:1.030000 + + CVE-2002-1994 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-10T10:42:00.000-04:00 + + + + BID + 5080 + + + XF + advserver-http-crlf-dos(9410) + + advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence. + + + + + + + + + cpe:/a:lebios:phptonuke.php:1.0 + + CVE-2002-1995 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.307-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-10T10:46:00.000-04:00 + + + + BID + 3807 + + + XF + phpnuke-phptonuke-css(7837) + + + VULN-DEV + 20020106 CSS in PHPNuke add-on + + Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter. + + + + + + + + + + + + + + + cpe:/a:postnuke_software_foundation:postnuke:0.71 + cpe:/a:postnuke_software_foundation:postnuke:0.703 + cpe:/a:postnuke_software_foundation:postnuke:0.70 + cpe:/a:postnuke_software_foundation:postnuke:0.64 + cpe:/a:postnuke_software_foundation:postnuke:0.63 + cpe:/a:postnuke_software_foundation:postnuke:0.7 + cpe:/a:postnuke_software_foundation:postnuke:0.62 + + CVE-2002-1996 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.463-04:00 + + + 2.6 + NETWORK + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-10T10:49:00.000-04:00 + + + + BID + 4350 + + + XF + postnuke-modules-index-css(8605) + + + BUGTRAQ + 20020322 PostNuke Bugged + + + MISC + http://sourceforge.net/tracker/index.php?func=detail&aid=524777&group_id=27927&atid=392228 + + + BUGTRAQ + 20020322 Re: PostNuke Bugged + + Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php. + + + + + + + + + cpe:/a:zonelabs:zonealarm:3.0 + + CVE-2002-1997 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-10T10:54:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + zonealarm-mailsafe-dot-bypass(8744) + + + BID + 4407 + + ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension. + + + + + + + + + + cpe:/o:sco:open_unix:8.0.0 + cpe:/o:sco:unixware:7.1.1 + + CVE-2002-1998 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T07:56:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + openunix-unixware-rpccmsd-bo(8597) + + + CALDERA + CSSA-2002-SCO.12 + + + BUGTRAQ + 20020110 Re: Unixware 7.1.1 rpc.cmsd remote exploit code. + + + BUGTRAQ + 20020110 Unixware 7.1.1 rpc.cmsd remote exploit code. + + Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21). + + + + + + + + + cpe:/a:hp:praesidium_webproxy:1.0 + + CVE-2002-1999 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:03.963-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-11T07:59:00.000-04:00 + + + + BID + 4342 + + + XF + hp-praesidium-unauth-access(8606) + + + CIAC + M-061 + + + HP + HPSBUX0203-189 + + HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests. + + + + + + + + + + cpe:/a:compaq:acms:4.4 + cpe:/a:compaq:acms:4.3 + + CVE-2002-2000 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:04.103-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:03:00.000-04:00 + + + + BID + 4184 + + + XF + openvms-acms-process-privileges(8306) + + ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data. + + + + + + + + + + + + + + cpe:/a:jmcce:jmcce:1.3.8 + cpe:/o:mandrakesoft:mandrake_linux:8.1 + + CVE-2002-2001 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:06.977-04:00 + + + 1.2 + LOCAL + HIGH + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-11T08:08:00.000-04:00 + + + + BID + 3940 + + + XF + linux-jmcce-tmp-symlink(7980) + + + MANDRAKE + MDKSA-2002:008 + + jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. + + + + + + + + + + + + cpe:/o:compaq:tru64:5.0 + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:5.1a + cpe:/o:compaq:tru64:4.0f + + CVE-2002-2002 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:09.393-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T08:12:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4544 + + + XF + libc-lang-locpath-bo(8863) + + + BUGTRAQ + 20020417 [SNS Advisory No.51] Compaq Tru64 UNIX libc Buffer Overflow Vulnerability + + + COMPAQ + SSRT541 + + Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables. + + + + + + + + + + + + + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:5.1 + cpe:/o:compaq:tru64:4.0g + cpe:/o:compaq:tru64:5.1a + cpe:/o:compaq:tru64:4.0f + + CVE-2002-2003 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:04.573-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:17:00.000-04:00 + + + ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap. + + + + + + + + + + cpe:/o:compaq:tru64:5.0a + cpe:/o:compaq:tru64:4.0g + + CVE-2002-2004 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:04.730-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-11T08:22:00.000-04:00 + + + portmapper in Compaq Tru64 4.0G and 5.0A allows remote attackers to cause a denial of service via a flood of packets. + + + + + + + + + + + cpe:/a:sun:java_web_start:1.0.1 + cpe:/a:sun:java_web_start:1.0 + cpe:/a:sun:java_web_start:1.0.1_01 + + CVE-2002-2005 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:09.610-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T08:26:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + java-webstart-access-resources(8483) + + + SUN + 00217 + + + HP + HPSBUX0203-188 + + + MISC + http://www.securityfocus.com/bid/4310 + + Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:tomcat:3.3.1 + cpe:/a:apache:tomcat:3.3 + cpe:/a:apache:tomcat:3.2 + cpe:/a:apache:tomcat:3.1 + cpe:/a:apache:tomcat:3.0 + cpe:/a:apache:tomcat:4.0.0 + cpe:/a:apache:tomcat:4.0.1 + cpe:/a:apache:tomcat:4.0.2 + cpe:/a:apache:tomcat:4.0.3 + cpe:/a:apache:tomcat:3.2.1 + cpe:/a:apache:tomcat:3.2.3 + cpe:/a:apache:tomcat:3.2.4 + cpe:/a:apache:tomcat:4.1.0 + cpe:/a:apache:tomcat:3.1.1 + + CVE-2002-2006 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:09.703-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:39:00.000-04:00 + + + + VUPEN + ADV-2008-1979 + + + BID + 4575 + + + XF + tomcat-example-class-information(8932) + + + BUGTRAQ + 20020422 Tomcat real path disclosure (2) + + + CONFIRM + http://tomcat.apache.org/security-4.html + + + SUNALERT + 239312 + + The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets. + + + + + + + + + + cpe:/a:apache:tomcat:3.2.3 + cpe:/a:apache:tomcat:3.2.4 + + CVE-2002-2007 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:43:00.000-04:00 + + + + CERT-VN + VU#116963 + + + BID + 4878 + + + BID + 4877 + + + BID + 4876 + + + MISC + http://www.procheckup.com/security_info/vuln_pr0207.html + + + MISC + http://www.procheckup.com/security_info/vuln_pr0206.html + + + MISC + http://www.procheckup.com/security_info/vuln_pr0205.html + + + XF + tomcat-sample-reveal-path(9208) + + + BUGTRAQ + 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (part 2) + + + BUGTRAQ + 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 + + The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. + + + + + + + + + cpe:/a:apache:tomcat:4.0.3 + + CVE-2002-2008 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:46:00.000-04:00 + + + + BID + 5054 + + + XF + tomcat-lpt9-path-disclosure(9394) + + + BUGTRAQ + 20020619 KPMG-2002024: Apache Tomcat Path Disclosure + + + CONFIRM + http://tomcat.apache.org/security-4.html + + Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message. + + + + + + + + + cpe:/a:apache:tomcat:4.0.1 + + CVE-2002-2009 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T08:53:00.000-04:00 + + + + BID + 4557 + + + BUGTRAQ + 20010419 Re: Tomcat 4.1 real path disclosure + + + BUGTRAQ + 20020419 Tomcat 4.1 real path disclosure + + + XF + tomcat-jsp-path-disclosure(42915) + + + CONFIRM + http://tomcat.apache.org/security-4.html + + Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message. + + + + + + + + + + + + cpe:/a:htdig:htdig:3.2.0 + cpe:/a:htdig:htdig:3.2.0b3 + cpe:/a:htdig:htdig:3.1.6 + cpe:/a:htdig:htdig:3.1.5 + + CVE-2002-2010 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.650-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-11T09:09:00.000-04:00 + + + + BID + 5091 + + + XF + htdig-htsearch-xss(9433) + + + BUGTRAQ + 20020626 XSS in HTDIG + + Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter. + + + + + + + + + + cpe:/a:jon_howell:faq-o-matic:2.711 + cpe:/a:jon_howell:faq-o-matic:2.712 + + CVE-2002-2011 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.807-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-11T09:12:00.000-04:00 + + + + BID + 4565 + + + XF + faqomatic-cgi-file-css(8906) + + + BUGTRAQ + 20020419 Another Faq-O-Matic XSS Vuln? + + Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter. + + + + + + + + + cpe:/a:apache:http_server:1.3.19 + + CVE-2002-2012 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:05.963-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-11T09:22:00.000-04:00 + + + + HP + HPSBTL0201-010 + + + XF + apache-http-unexpected-behavior(7810) + + + BID + 3796 + + Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:navigator:6.0 + cpe:/a:mozilla:mozilla:0.9.6 + cpe:/a:netscape:navigator:6.1 + cpe:/a:mozilla:mozilla:0.9.5 + cpe:/a:netscape:navigator:6.2 + cpe:/a:mozilla:mozilla:0.9.4 + cpe:/a:mozilla:mozilla:0.9.3 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.4 + cpe:/a:netscape:navigator:6.01 + cpe:/a:mozilla:mozilla:0.9.2 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.07 + cpe:/a:netscape:communicator:4.78 + cpe:/a:netscape:navigator:4.77 + cpe:/a:netscape:communicator:4.77 + cpe:/a:mozilla:mozilla:0.9.2.1 + cpe:/a:netscape:communicator:4.5_beta + cpe:/a:mozilla:mozilla:0.9.4.1 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.75 + cpe:/a:netscape:communicator:4.76 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.72 + + CVE-2002-2013 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T10:16:00.000-04:00 + + + + BID + 3925 + + + XF + mozilla-netscape-steal-cookies(7973) + + + BUGTRAQ + 20020121 Mozilla Cookie Exploit + + + MISC + http://alive.znep.com/~marcs/security/mozillacookie/demo.html + + Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. + + + + + + + + + cpe:/a:ibm:lotus_domino:5.0.8 + + CVE-2002-2014 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.323-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T10:20:00.000-04:00 + + + + BID + 3991 + + + XF + lotus-domino-username-disclosure(8038) + + + VULN-DEV + 20020130 Enumerating users on a Domino webserver + + + BUGTRAQ + 20020131 Script for find domino + + Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks. + + + + + + + + + cpe:/a:postnuke_software_foundation:postnuke:0.703 + + CVE-2002-2015 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T10:23:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + postnuke-caselist-include-modules(8699) + + + BID + 4381 + + + BUGTRAQ + 20020327 postnuke v 0.7.0.3 remote command execution + + PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter. + + + + + + + + + cpe:/a:user-mode_linux:user-mode_linux:2.4.17.8 + + CVE-2002-2016 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.637-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-11T10:26:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + uml-kernel-memory-access(8005) + + + BID + 3973 + + + BUGTRAQ + 20020128 user-mode-linux problems + + User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code. + + + + + + + + + + cpe:/a:sas:integration_technologies:8.0 + cpe:/a:sas:base:8.0 + + CVE-2002-2017 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-11T10:28:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 3994 + + + XF + sas-sastcpd-authprog-env(8024) + + sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd. + + + + + + + + + + cpe:/a:sas:integration_technologies:8.0 + cpe:/a:sas:base:8.0 + + CVE-2002-2018 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:06.933-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-11T10:31:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + MISC + http://www.sas.com/service/techsup/unotes/SN/004/004201.html + + + BID + 3995 + + + SECTRACK + 1003406 + + sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault. + + + + + + + + + cpe:/a:oscommerce:oscommerce:2.1 + + CVE-2002-2019 + 2002-12-31T00:00:00.000-05:00 + 2011-06-29T00:00:00.000-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T10:58:00.000-04:00 + + + + + CONFIRM + http://www.oscommerce.com/about.php/news,72 + + + BID + 5037 + + + XF + oscommerce-include-remote-files(9369) + + + BUGTRAQ + 20020616 PHP source injection in osCommerce + + PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter. + + + + + + + + + cpe:/h:netgear:rp114:3.26 + + CVE-2002-2020 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.230-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-11T11:01:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5036 + + + XF + netgear-default-external-access(9371) + + + BUGTRAQ + 20020617 External access to Netgear RP114 "firewall" + + Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed. + + + + + + + + + cpe:/a:woltlab:burning_board:1.1.1 + + CVE-2002-2021 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.387-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-11T11:02:00.000-04:00 + + + + BID + 4512 + + + XF + burningboard-bbs-css(8841) + + + BUGTRAQ + 20020413 wbboard 1.1.1 Cross Site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter. + + + + + + + + + cpe:/a:kaffe:kaffe_openvm:1.0.6 + + CVE-2002-2022 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.540-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-11T11:05:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4249 + + + XF + openvm-class-format-strings(8399) + + + VULN-DEV + 20020305 Latest Kaffe Java Virtual Machine Format Strings issue. + + Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute. + + + + + + + + + + + + cpe:/a:yamaguchi:shingo_beep2:1.1 + cpe:/a:yamaguchi:shingo_beep2:1.0 + cpe:/a:yamaguchi:shingo_beep2:1.2 + cpe:/a:yamaguchi:shingo_beep2:1.0a + + CVE-2002-2023 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.697-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T11:06:00.000-04:00 + + + + BID + 3859 + + + CONFIRM + http://www.kip.iis.toyama-u.ac.jp/~shingo/beep/package/src/beep2-1.2a.tar.gz + + The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors. + + + + + + + + + cpe:/a:horde:imp:2.2.7 + + CVE-2002-2024 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-11T11:08:00.000-04:00 + + + + BID + 4445 + + + XF + imp-php-path-disclosure(8768) + + Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:ibm:lotus_domino_server:5.0.8 + cpe:/a:ibm:lotus_domino_server:5.0.7 + cpe:/a:ibm:lotus_domino_server:5.0.6 + cpe:/a:ibm:lotus_domino_server:5.0.5 + cpe:/a:ibm:lotus_domino_server:5.0.4 + cpe:/a:ibm:lotus_domino_server:5.0.3 + cpe:/a:ibm:lotus_domino_server:4.6.3 + cpe:/a:ibm:lotus_domino_server:5.0.2 + cpe:/a:ibm:lotus_domino_server:5.0.1 + cpe:/a:ibm:lotus_domino_server:4.6.1 + cpe:/a:ibm:lotus_domino_server:5.0.7a + cpe:/a:ibm:lotus_domino_server:4.6.4 + cpe:/a:ibm:lotus_domino_server:5.0 + cpe:/a:ibm:lotus_domino_server:5.0.9 + + CVE-2002-2025 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:07.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-14T18:34:00.000-04:00 + + + + BID + 4020 + + + BID + 4019 + + + CONFIRM + http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/a77f8a5132cce70085256b8000792112?OpenDocument&Highlight=0,JCHN4UMKLA + + + VULNWATCH + 20020204 KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service + + Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name. + + + + + + + + + cpe:/a:browseftp:browseftp_client:1.62 + + CVE-2002-2026 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:08.183-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T18:36:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3781 + + + XF + browseftp-server-response-bo(7793) + + + SECTRACK + 1003130 + + Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply. + + + + + + + + + + + + cpe:/a:doow:doow:0.1.1 + cpe:/a:doow:doow:0.2.1 + cpe:/a:doow:doow:0.1 + cpe:/a:doow:doow:0.2 + + CVE-2002-2027 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:08.323-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T18:44:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3932 + + + CONFIRM + http://prdownloads.sourceforge.net/doow/doow_v0.2.2.zip?use_mirror=unc + + Database of Our Owlish Wisdom (DOOW) 0.1 through 0.2.1 does not properly verify user permissions, which allows remote attackers to perform unauthorized activities. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::server + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_nt:4.0::terminal_server + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server + cpe:/o:microsoft:windows_nt:4.0::enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_server + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_server + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_xp::gold:professional + + CVE-2002-2028 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:08.480-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-14T18:58:00.000-04:00 + + + + BID + 3933 + + + MISC + http://www.heysoft.de/nt/lbh.htm + + + MSKB + Q188700 + + + BUGTRAQ + 20020121 The "Lunch Break Hole" + + The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing. + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.15 + cpe:/a:apache:http_server:1.3.16 + cpe:/a:apache:http_server:1.3.13 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.12 + + CVE-2002-2029 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:08.730-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T20:28:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3786 + + + MISC + http://www.securiteam.com/windowsntfocus/5ZP030U60U.html + + + XF + apache-php-view-files(7815) + + PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string. + + + + + + + + + cpe:/a:sqldata:sqldata_enterprise_server:3.0 + + CVE-2002-2030 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:08.900-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T20:31:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3778 + + + XF + sqldata-enterprise-bo(7821) + + + SECTRACK + 1003123 + + Stack-based buffer overflow in SQLData Enterprise Server 3.0 allows remote attacker to execute arbitrary code and cause a denial of service via a long HTTP request. + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.0.1:sp1 + + CVE-2002-2031 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.040-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-14T20:37:00.000-04:00 + + + + BID + 3779 + + + XF + ie-javascript-onerror(7784) + + + BUGTRAQ + 20020103 Serious IE privacy issues + + Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:francisco_burzi:php-nuke:4.0 + cpe:/a:francisco_burzi:php-nuke:4.3 + cpe:/a:francisco_burzi:php-nuke:4.4 + cpe:/a:francisco_burzi:php-nuke:1.0 + cpe:/a:francisco_burzi:php-nuke:2.5 + cpe:/a:francisco_burzi:php-nuke:5.0.1 + cpe:/a:francisco_burzi:php-nuke:5.3.1 + cpe:/a:francisco_burzi:php-nuke:4.4.1a + cpe:/a:francisco_burzi:php-nuke:3.0 + cpe:/a:francisco_burzi:php-nuke:5.4 + cpe:/a:francisco_burzi:php-nuke:5.2 + cpe:/a:francisco_burzi:php-nuke:5.1 + cpe:/a:francisco_burzi:php-nuke:5.0 + cpe:/a:francisco_burzi:php-nuke:5.2a + + CVE-2002-2032 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.213-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-14T21:01:00.000-04:00 + + + + BID + 3906 + + + MISC + http://www.securityfaq.com/unixfocus/5OP041P6BE.html + + sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php. + + + + + + + + + + + + + + + + + + cpe:/a:faqmanager:faqmanager.cgi:2.2.2 + cpe:/a:faqmanager:faqmanager.cgi:2.2.1 + cpe:/a:faqmanager:faqmanager.cgi:2.1.2 + cpe:/a:faqmanager:faqmanager.cgi:2.1.1 + cpe:/a:faqmanager:faqmanager.cgi:2.2.3 + cpe:/a:faqmanager:faqmanager.cgi:2.0 + cpe:/a:faqmanager:faqmanager.cgi:2.2.4 + cpe:/a:faqmanager:faqmanager.cgi:2.2.5 + cpe:/a:faqmanager:faqmanager.cgi:2.2 + cpe:/a:faqmanager:faqmanager.cgi:2.1 + + CVE-2002-2033 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-14T21:05:00.000-04:00 + + + + BID + 3810 + + + XF + faqmanager-cgi-null-file-read(7833) + + + BUGTRAQ + 20020107 Faqmanager.cgi file read vulnerability + + faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00). + + + + + + + + + + cpe:/a:john_hardin:procmail_email_sanitizer:1.132 + cpe:/a:john_hardin:procmail_email_sanitizer:1.131 + + CVE-2002-2034 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.620-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T21:08:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3820 + + + XF + pes-mime-bypass-filter(7847) + + + CONFIRM + http://www.impsec.org/email-tools/sanitizer-changelog.html + + The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments. + + + + + + + + + cpe:/a:realityscape:mylogin_2000:1.0.0 + + CVE-2002-2035 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T21:10:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.securiteam.com/windowsntfocus/5CP041P75S.html + + + XF + mylogin2000-sql-injection(9016) + + SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form. + + + + + + + + + cpe:/a:sun:ray_server_software:1.3 + + CVE-2002-2036 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:09.917-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-14T21:13:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4911 + + + XF + srss-nscm-unauthorized-access(9252) + + + SUNALERT + 44069 + + Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client. + + + + + + + + + + + + + cpe:/a:cisco:bams + cpe:/a:cisco:pgw_2200:9.1 + cpe:/a:cisco:vsc3000:9.1 + cpe:/a:cisco:sc2200:7.4 + cpe:/a:cisco:vspt + + CVE-2002-2037 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.057-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T07:29:00.000-04:00 + + + + BID + 3897 + + + XF + cisco-mgc-exposure(7912) + + + CISCO + 20020116 Hardening of Solaris OS for MGC + + The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities. + + + + + + + + + cpe:/o:bill_abt:next_generation_posix_threading:1.9.0 + + CVE-2002-2038 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.230-04:00 + + + 3.6 + LOCAL + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T07:37:00.000-04:00 + + + + BID + 4913 + + + XF + ngpt-shared-memory-dos(9255) + + Next Generation POSIX Threading (NGPT) 1.9.0 uses a filesystem-based shared memory entry, which allows local users to cause a denial of service or in threaded processes or spoof files via unknown methods. + + + + + + + + + + cpe:/a:qnx:rtos:6.1.0 + cpe:/a:qnx:rtos:4.25 + + CVE-2002-2039 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.370-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-15T07:39:00.000-04:00 + + + + BUGTRAQ + 20020603 QNX + + + BID + 4914 + + + XF + qnx-rtos-su-core-dump(9256) + + /bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal. + + + + + + + + + + cpe:/a:qnx:rtos:6.1.0 + cpe:/a:qnx:rtos:4.25 + + CVE-2002-2040 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.510-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-15T07:43:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4916 + + + BID + 4915 + + + XF + qnx-rtos-phgrafx-privileges(9257) + + The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program. + + + + + + + + + cpe:/a:qnx:rtos:6.1.0 + + CVE-2002-2041 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:12.353-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-15T07:47:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4917 + + + XF + qnx-rtos-pkginstaller-bo(9259) + + + XF + qnx-rtos-phlocale-bo(9258) + + + BID + 4918 + + Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer. + + + + + + + + + + cpe:/a:qnx:rtos:6.1.0 + cpe:/a:qnx:rtos:4.25 + + CVE-2002-2042 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.823-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-15T07:52:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4919 + + + XF + qnx-rtos-process-modification(9260) + + ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by modifying running processes. + + + + + + + + + + cpe:/a:cyrus:sasl:1.5.24 + cpe:/a:cyrus:sasl:1.5.27 + + CVE-2002-2043 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:10.963-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T07:55:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4409 + + + XF + cyrus-sasl-patch-pop-access(8748) + + + BUGTRAQ + 20020402 SASL (v1/v2) MYSQL/LDAP authentication patch. + + SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password. + + + + + + + + + + cpe:/a:xqus:x-stat:2.2 + cpe:/a:xqus:x-stat:2.3 + + CVE-2002-2044 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.120-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T08:00:00.000-04:00 + + + + BID + 4281 + + + XF + xstat-admin-php-css(8468) + + + MISC + http://www.ifrance.com/kitetoua/tuto/x_holes.txt + + + SECTRACK + 1003827 + + + VULN-DEV + 20020313 X_holes + + Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo action. + + + + + + + + + + cpe:/a:xqus:x-stat:2.2 + cpe:/a:xqus:x-stat:2.3 + + CVE-2002-2045 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.260-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T08:03:00.000-04:00 + + + + XF + xstat-phpinfo-reveal-info(8467) + + + XF + xstat-action-reveal-path(8466) + + + BID + 4280 + + + BID + 4279 + + + MISC + http://www.ifrance.com/kitetoua/tuto/x_holes.txt + + + SECTRACK + 1003827 + + + VULN-DEV + 20020313 X_holes + + x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message. + + + + + + + + + cpe:/a:xqus:x-news:1.1 + + CVE-2002-2046 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.417-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T08:06:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.ifrance.com/kitetoua/tuto/x_holes.txt + + + VULN-DEV + 20020313 X_holes + + x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie. + + + + + + + + + cpe:/a:sketch:sketch:0.6.12 + + CVE-2002-2047 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.573-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-08-15T08:10:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4296 + + + XF + sketch-eps-command-execution(8469) + + + SECTRACK + 1003818 + + The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file. + + + + + + + + + cpe:/a:michael_baumer:pfinger:0.7.8 + + CVE-2002-2048 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.713-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T08:12:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + pfinger-query-bo(9269) + + + VULN-DEV + 20020604 PFinger Buffer Overflow Vulnerability. + + Buffer overflow in PFinger 0.7.8 client allows remote attackers to execute arbitrary code via a long query value passed to the (1) finger program, (2) -l, (3) -d, and (4) -t options. NOTE: if PFinger is not setuid or setgid, then this issue would not cross privilege boundaries and would not be considered a vulnerability. + + + + + + + + + + + cpe:/a:dug_song:fragrouter:1.6 + cpe:/a:dug_song:fragroute:1.2 + cpe:/a:dug_song:dsniff:2.3 + + CVE-2002-2049 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:11.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T08:15:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4898 + + + XF + fragroute-host-download-backdoor(9272) + + + BUGTRAQ + 20020531 Trojan/backdoor in fragroute 1.2 source distribution + + + CONFIRM + http://www.freebsd.org/cgi/query-pr.cgi?pr=38716 + + configure for Dsniff 2.3, fragroute 1.2, and fragrouter 1.6, when downloaded from monkey.org on May 17, 2002, has been modified to contain a backdoor, which allows remote attackers to access the system. + + + + + + + + + + + + + cpe:/a:modlogan:modlogan:0.5.6 + cpe:/a:modlogan:modlogan:0.5.7 + cpe:/a:modlogan:modlogan:0.7.11 + cpe:/a:modlogan:modlogan:0.6 + cpe:/a:modlogan:modlogan:0.5 + + CVE-2002-2050 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.027-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T08:18:00.000-04:00 + + + + BID + 3821 + + + XF + modlogan-splitby-symlink(7848) + + + CONFIRM + http://jan.kneschke.de/projects/modlogan/download/ChangeLog + + Directory traversal vulnerability in processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a .. (dot dot) in the hostname of a log entry. + + + + + + + + + + + + + cpe:/a:modlogan:modlogan:0.5.6 + cpe:/a:modlogan:modlogan:0.5.7 + cpe:/a:modlogan:modlogan:0.7.11 + cpe:/a:modlogan:modlogan:0.6 + cpe:/a:modlogan:modlogan:0.5 + + CVE-2002-2051 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.183-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T14:58:00.000-04:00 + + + + BID + 3821 + + + XF + modlogan-splitby-symlink(7848) + + + MISC + http://jan.kneschke.de/projects/modlogan/download/ChangeLog + + The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file. + + + + + + + + + cpe:/o:cisco:ios:12.1%286.5%29 + + CVE-2002-2052 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:02:00.000-04:00 + + + + BID + 4947 + + + XF + cisco-ios-portscan-dos(9281) + + + BUGTRAQ + 20020606 Re: Three possible DoS attacks against some IOS versions. + + + BUGTRAQ + 20020605 Three possible DoS attacks against some IOS versions. + + Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the router. NOTE: the vendor could not reproduce this issue, saying that the original reporter was using an interim release of the software. + + + + + + + + + cpe:/o:cisco:ios:12.1 + + CVE-2002-2053 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:05:00.000-04:00 + + + + BID + 4949 + + + XF + cisco-ios-hsrp-loop-dos(9283) + + + BUGTRAQ + 20020606 Re: Three possible DoS attacks against some IOS versions. + + + BUGTRAQ + 20020605 Three possible DoS attacks against some IOS versions. + + The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop. + + + + + + + + + cpe:/a:teekai:teekai_forum:1.2 + + CVE-2002-2054 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.637-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:10:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4925 + + + XF + teekais-forum-admin-access(9285) + + + MISC + http://www.ifrance.com/kitetoua/tuto/Teekai.txt + + + VULN-DEV + 20020603 Security holes in two Teekai's products + security hole in ncmail.netscape.com + + TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin. + + + + + + + + + cpe:/a:teekai:teekai_tracking_online:1.0 + + CVE-2002-2055 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.790-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T15:13:00.000-04:00 + + + + BID + 4924 + + + XF + teekais-tracking-xss(9284) + + + MISC + http://www.ifrance.com/kitetoua/tuto/Teekai.txt + + + VULN-DEV + 20020603 Security holes in two Teekai's products + security hole in ncmail.netscape.com + + Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. + + + + + + + + + cpe:/a:teekai:teekai_forum:1.2 + + CVE-2002-2056 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:12.933-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T15:15:00.000-04:00 + + + + MISC + http://www.ifrance.com/kitetoua/tuto/Teekai.txt + + + VULN-DEV + 20020603 Security holes in two Teekai's products + security hole in ncmail.netscape.com + + Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows remote attackers to inject arbitrary web script or HTML via the valid_username_online cookie. + + + + + + + + + cpe:/a:teekai:teekai_forum:1.2 + + CVE-2002-2057 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:13.120-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-15T15:18:00.000-04:00 + + + + BID + 4926 + + + XF + teekais-forum-obtain-information(9286) + + + MISC + http://www.ifrance.com/kitetoua/tuto/Teekai.txt + + + VULN-DEV + 20020603 Security holes in two Teekai's products + security hole in ncmail.netscape.com + + TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'. + + + + + + + + + cpe:/a:teekai:teekai_tracking_online:1.0 + + CVE-2002-2058 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:13.277-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-15T15:25:00.000-04:00 + + + + BID + 4926 + + + XF + teekais-forum-obtain-information(9286) + + TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:intel:d845hv_motherboard:p04-0018 + cpe:/h:intel:d845pt_motherboard:p03-0021 + cpe:/h:intel:d845bg_motherboard:p03-0021 + cpe:/h:intel:d845wn_motherboard:p07-0029 + cpe:/h:intel:d845wn_motherboard:p04-0018 + cpe:/h:intel:d845pt_motherboard:p02-0015 + cpe:/h:intel:d845pt_motherboard:p04-0023 + cpe:/h:intel:d845wn_motherboard:p11-0040 + cpe:/h:intel:d845bg_motherboard:p01-0012 + cpe:/h:intel:d845pt_motherboard:p01-0012 + cpe:/h:intel:d845bg_motherboard:p02-0015 + cpe:/h:intel:d845hv_motherboard:p06-0024 + cpe:/h:intel:d845wn_motherboard:p09-0035 + cpe:/h:intel:d845hv_motherboard:p11-0040 + cpe:/h:intel:d845wn_motherboard:p10-0038 + cpe:/h:intel:d845hv_motherboard:p09-0035 + cpe:/h:intel:d845bg_motherboard:p05-0024 + cpe:/h:intel:d845wn_motherboard:p06-0024 + cpe:/h:intel:d845hv_motherboard:p05-0022 + cpe:/h:intel:d845hv_motherboard:p10-0038 + cpe:/h:intel:d845hv_motherboard:p08-0031 + cpe:/h:intel:d845pt_motherboard:p05-0024 + cpe:/h:intel:d845hv_motherboard:p07-0029 + cpe:/h:intel:d845wn_motherboard:p08-0031 + cpe:/h:intel:d845bg_motherboard:p04-0023 + + CVE-2002-2059 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:13.433-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:31:00.000-04:00 + + + + BID + 4610 + + + XF + intel-d845-change-device(8998) + + + BUGTRAQ + 20020503 Re: Intel D845HV/WN/PT series motherboard vulnerability + + + BUGTRAQ + 20020425 Intel D845HV/WN/PT series motherboard vulnerability + + BIOS D845BG, D845HV, D845PT and D845WN on Intel motherboards does not properly restrict access to configuration information when BIOS passwords are enabled, which could allow local users to change the default boot device via the F8 key. + + + + + + + + + cpe:/a:twibright_labs:links:2.0_pre4 + + CVE-2002-2060 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:13.637-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:34:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4921 + + + XF + links-png-image-bo(9287) + + + CONFIRM + http://atrey.karlin.mff.cuni.cz/~clock/twibright/links/download/ChangeLog + + Buffer overflow in Links 2.0 pre4 allows remote attackers to crash client browsers and possibly execute arbitrary code via gamma tables in large 16-bit PNG images. + + + + + + + + + + cpe:/a:netscape:navigator:6.2.3 + cpe:/a:mozilla:mozilla:1.0 + + CVE-2002-2061 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:16.743-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:40:00.000-04:00 + + + ALLOWS_USER_ACCESS + + CONFIRM + http://www.mozilla.org/releases/mozilla1.0.1/security-fixes-1.0.1.html + + + XF + links-png-image-bo(9287) + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=157202 + + + MANDRAKE + MDKSA-2002:074 + + Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel. + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + + CVE-2002-2062 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:13.930-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-15T15:43:00.000-04:00 + + + + BID + 4954 + + + XF + ie-ftp-name-xss(9290) + + + MISC + http://www.geocities.co.jp/SiliconValley/1667/advisory02e.html + + + BUGTRAQ + 20020606 Microsoft Internet Explorer + + Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL. + + + + + + + + + cpe:/a:atguard:atguard_personal_firewall:3.2 + + CVE-2002-2063 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.103-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:46:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4620 + + + XF + atguard-firewall-bypass(8962) + + + BUGTRAQ + 20020429 ITCP Advisory 13: Bypassing of ATGuard Firewall possible + + AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames. + + + + + + + + + cpe:/a:phpwebgallery:phpwebgallery:1.0 + + CVE-2002-2064 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.243-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-15T15:49:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4622 + + + MISC + http://www.ifrance.com/kitetoua/tuto/PWG.txt + + + VULN-DEV + 20020427 Security holes in 11 products... + + isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo. + + + + + + + + + + + + cpe:/a:webcalendar:webcalendar:0.9.34 + cpe:/a:webcalendar:webcalendar:0.9.33 + cpe:/a:webcalendar:webcalendar:0.9.32 + cpe:/a:webcalendar:webcalendar:0.9.31 + + CVE-2002-2065 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.387-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-15T15:50:00.000-04:00 + + + + CONFIRM + http://sourceforge.net/project/shownotes.php?group_id=3870&release_id=93295 + + + BID + 4961 + + + XF + webcalendar-inc-obtain-information(9296) + + WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root. + + + + + + + + + + + cpe:/a:jetico:bcwipe:2.35.1 + cpe:/a:jetico:bcwipe:2.0 + cpe:/a:jetico:bcwipe:1.0.7 + + CVE-2002-2066 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.540-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T08:18:00.000-04:00 + + + + CONFIRM + http://www.bcwipe.com/ + + + MISC + http://www.seifried.org/security/advisories/kssa-003.html + + + BID + 3912 + + + XF + ntfs-ads-file-wipe(7953) + + + CIAC + M-034 + + BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. + + + + + + + + + cpe:/a:east_technologies:east-tec_eraser:2002 + + CVE-2002-2067 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T08:21:00.000-04:00 + + + + MISC + http://www.seifried.org/security/advisories/kssa-003.html + + + BID + 3912 + + + XF + ntfs-ads-file-wipe(7953) + + + MISC + http://www.east-tec.com/eraser/faq.htm + + + CIAC + M-034 + + East-Tec Eraser 2002 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. + + + + + + + + + cpe:/a:sami_tolvanen:eraser:5.3 + + CVE-2002-2068 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T10:25:00.000-04:00 + + + + MISC + http://www.seifried.org/security/advisories/kssa-003.html + + + BID + 3912 + + + XF + ntfs-ads-file-wipe(7953) + + + CIAC + M-034 + + Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. + + + + + + + + + + + + + + + cpe:/a:pgp:pgp:7.0.3 + cpe:/a:pgp:pgp:7.0 + cpe:/a:pgp:pgp:6.5.1i + cpe:/a:pgp:pgp:6.5.3 + cpe:/a:pgp:pgp:6.5.1 + cpe:/a:pgp:pgp:6.5.2a + cpe:/a:pgp:pgp:6.5.8 + + CVE-2002-2069 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:14.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T10:37:00.000-04:00 + + + + MISC + http://www.seifried.org/security/advisories/kssa-003.html + + + BID + 3912 + + + XF + ntfs-ads-file-wipe(7953) + + + CIAC + M-034 + + PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. + + + + + + + + + cpe:/a:accessdata:secureclean:3_build_2.0 + + CVE-2002-2070 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.167-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T10:39:00.000-04:00 + + + + MISC + http://www.seifried.org/security/advisories/kssa-003.html + + + BID + 3912 + + + XF + ntfs-ads-file-wipe(7953) + + + CIAC + M-034 + + SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. + + + + + + + + + cpe:/o:compaq:tru64:4.0e + + CVE-2002-2071 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T10:44:00.000-04:00 + + + + BID + 4011 + + + XF + tru64-nmap-portscan-dos(8040) + + + BUGTRAQ + 20020130 DoS bug on Tru64 + + Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd, and possibly other services via a TCP SYN scan, as demonstrated using nmap. + + + + + + + + + + cpe:/a:sun:jre:1.3.1::linux + cpe:/a:sun:jre:1.2.2::linux_production + + CVE-2002-2072 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T10:49:00.000-04:00 + + + + BID + 3992 + + + XF + sun-jre-jvm-dos(8042) + + + SECTRACK + 1003418 + + java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument. + + + + + + + + + + + + + + + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0 + cpe:/o:microsoft:windows_nt:4.0 + + CVE-2002-2073 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.620-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-08-16T10:52:00.000-04:00 + + + + BID + 3999 + + + XF + siteserver-asp-css(8050) + + + VULNWATCH + 20020130 RFP2201: MS Site Server Evilness + + Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. + + + + + + + + + cpe:/a:erwin_lansing:mailidx:20010925 + + CVE-2002-2074 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.777-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-16T11:02:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 3822 + + + XF + mailidx-search-input-validation(7965) + + + SECTRACK + 1003269 + + SQL injection vulnerability in Mailidx before 20020105 allows remote attackers to execute arbitrary SQL commands via the search web page. + + + + + + + + + + cpe:/a:mirabilis:icq:2002b + cpe:/a:mirabilis:icq:2001a + + CVE-2002-2075 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:15.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T11:06:00.000-04:00 + + + + XF + icq-contacts-dos(8909) + + + BUGTRAQ + 20020419 DOS for Icq 2001&2002 + + ICQ 2001a and 2002b allows remote attackers to cause a denial of service (memory consumption and hang) via a contact message with a large contacts number. + + + + + + + + + + cpe:/a:summit_computer_networks:lil_http:2.2 + cpe:/a:summit_computer_networks:lil_http:2.1 + + CVE-2002-2076 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.073-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T11:22:00.000-04:00 + + + + BID + 4576 + + + XF + lilhttp-dotdot-directory-traversal(8913) + + + BUGTRAQ + 20020421 Lil' HTTP Server Directory Traversal Vulnerability + + Directory traversal vulnerability in Lil' HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + + CVE-2002-2077 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T11:25:00.000-04:00 + + + + BID + 4410 + + + XF + win2k-dcom-memory-leak(8739) + + + BINDVIEW + 20020402 Windows 2000 DCOM clients may leak sensitive information onto the network + + + MSKB + Q300367 + + The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session. + + + + + + + + + + cpe:/a:floosietek:ftgateoffice:1.05 + cpe:/a:floosietek:ftgatepro:1.05 + + CVE-2002-2078 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.400-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-16T11:31:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4427 + + + MISC + http://www.security.nnov.ru/advisories/ftgate.asp + + + XF + ftgate-apop-bo(8749) + + + BUGTRAQ + 20020403 SECURITY.NNO: FTGate PRO/Office hotfixes + + Heap-based buffer overflow in Floositek (1) FTGate Pro 1.05 and (2) FTGate Office 1.05 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long POP3 APOP USER command. + + + + + + + + + + + + + + cpe:/a:mosix_project:mosix:1.5.7 + cpe:/o:openmosix_project:openmosix:2.4.17 + + CVE-2002-2079 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T11:34:00.000-04:00 + + + + BID + 4580 + + + XF + mosix-malformed-packet-dos(8927) + + + BUGTRAQ + 20020423 Denial of Service in Mosix 1.5.x + + mosix-protocol-stack in Multicomputer Operating System for UnIX (MOSIX) 1.5.7 allows remote attackers to cause a denial of service via malformed packets. + + + + + + + + + cpe:/a:floosietek:ftgatepro:1.05 + + CVE-2002-2080 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.713-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T11:40:00.000-04:00 + + + + BID + 4428 + + + MISC + http://www.security.nnov.ru/advisories/ftgate.asp + + + XF + ftgate-rcpt-to-dos(8750) + + + BUGTRAQ + 20020403 SECURITY.NNO: FTGate PRO/Office hotfixes + + Floositek FTGate PRO 1.05 allows remote attackers to cause a denial of service (memory and CPU consumption) via a large number of RCPT TO: messages during an SMTP session. + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:site_server:3.0:sp1_alpha + cpe:/a:microsoft:site_server_commerce:3.0 + cpe:/a:microsoft:site_server:3.0::i386 + cpe:/a:microsoft:site_server:3.0:apha + cpe:/a:microsoft:site_server_commerce:3.0:alpha + cpe:/a:microsoft:site_server:3.0:sp2:i386 + cpe:/a:microsoft:site_server:3.0:sp2_alpha + cpe:/a:microsoft:site_server:3.0:sp1:i386 + cpe:/a:microsoft:site_server_commerce:3.0:sp3_alpha + cpe:/a:microsoft:site_server:3.0:sp3_alpha + cpe:/a:microsoft:site_server:3.0:sp4:i386 + cpe:/a:microsoft:site_server:3.0:sp3:i386 + cpe:/a:microsoft:site_server:3.0:sp4_alpha + cpe:/a:microsoft:site_server_commerce:3.0:sp4_alpha + cpe:/a:microsoft:site_server_commerce:3.0:sp2_alpha + cpe:/a:microsoft:site_server_commerce:3.0:sp1_alpha + + CVE-2002-2081 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:16.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-08-16T12:11:00.000-04:00 + + + + BID + 4002 + + + XF + siteserver-cphost-upload-dos(8053) + + + VULNWATCH + 20020129 RFP2201: MS Site Server Evilness + + cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp. + + + + + + + + + + cpe:/a:floosietek:ftgateoffice:1.05 + cpe:/a:floosietek:ftgatepro:1.05 + + CVE-2002-2082 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-08-16T12:13:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4429 + + + XF + ftgate-pop3-user-dos(8751) + + + BUGTRAQ + 20020403 SECURITY.NNO: FTGate PRO/Office hotfixes + + FTGate and FTGate Pro 1.05 lock user mailboxes before authentication succeeds, which allows remote attackers to lock the mailboxes of other users. + + + + + + + + + cpe:/o:novell:netware + + CVE-2002-2083 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.197-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T12:15:00.000-04:00 + + + + BUGTRAQ + 20020111 Novell Netware Login "bypass" to execute programs + + The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen. + + + + + + + + + cpe:/a:portix-php:portix-php:0.4.2 + + CVE-2002-2084 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T12:40:00.000-04:00 + + + + BID + 4038 + + + SECTRACK + 1003430 + + + VULN-DEV + 20020131 Big Security Holes in Portix-PHP Portal + + Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2) topic parameters. + + + + + + + + + cpe:/a:wwwebbb:wwwebbb_forum:3.82_beta + + CVE-2002-2085 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-08-16T12:47:00.000-04:00 + + + + SECTRACK + 1003456 + + + VULN-DEV + 20020205 Security Hole in WWWeBBB forum + + Directory traversal vulnerability in page.cgi of WWWeBBB Forum 3.82 beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. + + + + + + + + + + + + + + cpe:/a:squirrelmail:squirrelmail:1.2.0 + cpe:/a:squirrelmail:squirrelmail:1.2.4 + cpe:/a:squirrelmail:squirrelmail:1.2.3 + cpe:/a:squirrelmail:squirrelmail:1.2.2 + cpe:/a:squirrelmail:squirrelmail:1.2.1 + cpe:/a:squirrelmail:squirrelmail:1.2.5 + + CVE-2002-2086 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.633-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-12T08:03:00.000-04:00 + + + + XF + squirrelmail-html-attachment-xss(9009) + + + XF + squirrelmail-header-xss(9008) + + + BID + 4667 + + + BID + 4666 + + + CONFIRM + http://www.squirrelmail.org/changelog.php + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=545933&group_id=311&atid=100311 + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=544658&group_id=311&atid=100311 + + Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fields or (2) a javascript: URL in the src attribute of an IMG tag. + + + + + + + + + cpe:/a:borland_software:interbase:6.0 + + CVE-2002-2087 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.790-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-07T19:35:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5046 + + + BID + 5044 + + + XF + interbase-interbase-variable-bo(9392) + + + BUGTRAQ + 20020618 Interbase 6.0 malloc() issues + + Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) gds_inet_server. + + + + + + + + + cpe:/o:mosix_project:clump_os:5.4 + + CVE-2002-2088 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:17.930-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-07T19:34:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4581 + + + XF + mosix-clumpos-blank-password(8928) + + + BUGTRAQ + 20020423 Denial of Service in Mosix 1.5.x + + The MOSIX Project clump/os 5.4 creates a default VNC account without a password, which allows remote attackers to gain root access. + + + + + + + + + cpe:/o:sun:solaris:9.0::sparc + + CVE-2002-2089 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.087-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-12T08:20:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5085 + + + XF + solaris-rcp-bo(9411) + + + VULN-DEV + 20020621 solaris 9 sparc rcp + + Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument. + + + + + + + + + + cpe:/a:caucho_technology:resin:2.1.1 + cpe:/a:caucho_technology:resin:2.1.2 + + CVE-2002-2090 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.243-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-13T09:16:00.000-04:00 + + + + BUGTRAQ + 20020717 KPMG-2002033: Resin DOS device path disclosure + + + BID + 5252 + + Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp. + + + + + + + + + cpe:/a:decfingerd:decfingerd:0.7 + + CVE-2002-2091 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.400-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-12T10:52:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 5105 + + + XF + decfingerd-syslog-format-string(9434) + + + BUGTRAQ + 20020625 Formatstring Vulnerability in decfingerd 0.7 + + Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:freebsd:freebsd:4.4:releng + cpe:/o:freebsd:freebsd:4.3:releng + cpe:/o:freebsd:freebsd:4.4:stable + cpe:/o:freebsd:freebsd:4.2:stable + cpe:/o:freebsd:freebsd:4.3:stable + cpe:/o:freebsd:freebsd:3.5.1 + cpe:/o:netbsd:netbsd:1.3.3 + cpe:/o:netbsd:netbsd:1.3.2 + cpe:/o:netbsd:netbsd:1.3.1 + cpe:/o:netbsd:netbsd:1.5.2 + cpe:/o:netbsd:netbsd:1.5.1 + cpe:/o:netbsd:netbsd:1.3 + cpe:/o:netbsd:netbsd:1.4 + cpe:/o:netbsd:netbsd:1.5 + cpe:/o:netbsd:netbsd:1.4.3 + cpe:/o:netbsd:netbsd:1.4.1 + cpe:/o:netbsd:netbsd:1.4.2 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:openbsd:openbsd:2.9 + cpe:/o:openbsd:openbsd:2.8 + cpe:/o:freebsd:freebsd:4.3 + cpe:/o:freebsd:freebsd:4.2 + cpe:/o:freebsd:freebsd:4.4 + cpe:/o:freebsd:freebsd:2.2.2 + cpe:/o:freebsd:freebsd:2.2.3 + cpe:/o:freebsd:freebsd:4.1 + cpe:/o:freebsd:freebsd:4.0 + cpe:/o:freebsd:freebsd:2.2.6 + cpe:/o:freebsd:freebsd:3.0 + cpe:/o:freebsd:freebsd:2.2.4 + cpe:/o:freebsd:freebsd:3.2 + cpe:/o:freebsd:freebsd:2.2.5 + cpe:/o:freebsd:freebsd:3.1 + cpe:/o:freebsd:freebsd:3.4 + cpe:/o:freebsd:freebsd:3.3 + cpe:/o:freebsd:freebsd:2.0 + cpe:/o:freebsd:freebsd:2.2.8 + cpe:/o:freebsd:freebsd:3.5 + cpe:/o:freebsd:freebsd:2.2 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:freebsd:freebsd:4.1.1:stable + cpe:/o:freebsd:freebsd:4.1.1 + cpe:/o:freebsd:freebsd:4.3:release + cpe:/o:freebsd:freebsd:2.1.0 + cpe:/o:freebsd:freebsd:4.1.1:release + + CVE-2002-2092 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.557-04:00 + + + 3.7 + LOCAL + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-14T08:51:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + bsd-exec-race-condition(7945) + + + BID + 3891 + + + NETBSD + NetBSD-SA2002-001 + + + FREEBSD + FreeBSD-SA-02:08 + + + OSVDB + 19475 + + Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid. + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5.14 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.11m + cpe:/o:sgi:irix:6.5.12 + cpe:/o:sgi:irix:6.5.11f + cpe:/o:sgi:irix:6.5.12f + cpe:/o:sgi:irix:6.5.10f + cpe:/o:sgi:irix:6.5.13f + cpe:/o:sgi:irix:6.5.14m + cpe:/o:sgi:irix:6.5.13m + cpe:/o:sgi:irix:6.5.12m + cpe:/o:sgi:irix:6.5.10m + + CVE-2002-2093 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.823-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-16T02:31:00.000-04:00 + + + + XF + irix-o2-vcp-view-information(8016) + + + BID + 3974 + + + SGI + 20020103-01-I + + The Video Control Panel on SGI O2/IRIX 6.5, when the Default Input is set to "Output Video", allows attackers to access a console session by running videoout then videoin. + + + + + + + + + cpe:/a:joe_testa:hellbent:01 + + CVE-2002-2094 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:18.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-16T02:34:00.000-04:00 + + + + BID + 3908 + + + XF + hellbent-root-path-disclosure(7930) + + + BUGTRAQ + 20020118 Vulnerability in hellbent + + Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct. + + + + + + + + + cpe:/a:joe_testa:hellbent:0.1 + + CVE-2002-2095 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-19T09:24:00.000-04:00 + + + + BID + 3909 + + + XF + hellbent-prefs-obtain-info(7931) + + + BUGTRAQ + 20020118 Vulnerability in hellbent + + Joe Testa hellbent 01 webserver allows attackers to read files that are specified in the hellbent.prefs file by creating a file with a similar name in the web root, as demonstrated using (1) index.webroot and (2) index.ipallow. + + + + + + + + + + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-2096 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.290-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T09:26:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4405 + + + XF + netware-remote-manager-bo(8736) + + + CONFIRM + http://support.novell.com/servlet/tidfinder/2962026 + + + BUGTRAQ + 20020406 NetWare Remote Manager patches + + + BUGTRAQ + 20020402 iXsecurity.20020313.nw6remotemanager.a + + Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password. + + + + + + + + + + + + + cpe:/a:maradns:maradns:0.5.28 + cpe:/a:maradns:maradns:0.5.29 + cpe:/a:maradns:maradns:0.8.99 + cpe:/a:maradns:maradns:0.9.00 + cpe:/a:maradns:maradns:0.5.30 + + CVE-2002-2097 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T09:31:00.000-04:00 + + + + XF + maradns-malformed-packet-dos(7972) + + + BID + 3852 + + + SECTRACK + 1003252 + + The compression code in MaraDNS before 0.9.01 allows remote attackers to cause a denial of service via crafted DNS packets. + + + + + + + + + cpe:/a:axspawn:axspawn:0.2.4.1 + + CVE-2002-2098 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.603-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T09:34:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + axspawn-pam-login-bo(7974) + + + BID + 3824 + + + CONFIRM + http://www.dabo.de/software/axspawn.html + + + SECTRACK + 1003242 + + Buffer overflow in axspawn.c in Axspawn-pam before 0.2.1a allows remote attackers to execute arbitrary code via large packets. + + + + + + + + + cpe:/a:gnu:data_display_debugger:3.3.1 + + CVE-2002-2099 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.760-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2005-09-19T09:37:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + XF + ddd-home-bo(7979) + + + SECTRACK + 1003241 + + Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE. + + + + + + + + + + cpe:/a:microsoft:outlook:2002 + cpe:/a:microsoft:outlook:2000 + + CVE-2002-2100 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:19.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-19T09:41:00.000-04:00 + + + + BID + 4334 + + + XF + outlook-iframe-url(8611) + + + BUGTRAQ + 20020320 Questionable security policies in Outlook 2002 + + Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. + + + + + + + + + cpe:/a:microsoft:outlook:2002 + + CVE-2002-2101 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.073-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T09:43:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4337 + + + XF + outlook-href-url-javascript(8613) + + + BUGTRAQ + 20020320 Questionable security policies in Outlook 2002 + + Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag. + + + + + + + + + + + + + + cpe:/a:jcraft:jzlib:0.0.1 + cpe:/a:jcraft:jzlib:0.0.2 + cpe:/a:jcraft:jzlib:0.0.3 + cpe:/a:jcraft:jzlib:0.0.4 + cpe:/a:jcraft:jzlib:0.0.5 + cpe:/a:jcraft:jzlib:0.0.6 + + CVE-2002-2102 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T09:45:00.000-04:00 + + + + BID + 4359 + + + CONFIRM + http://www.jcraft.com/jzlib/ChangeLog + + + XF + jzlib-infblocks-dos(8627) + + InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data. + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.9 + cpe:/a:apache:http_server:1.3.19 + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.15 + cpe:/a:apache:http_server:1.3.16 + cpe:/a:apache:http_server:1.3.13 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:http_server:1.3.12 + + CVE-2002-2103 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.383-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-19T10:02:00.000-04:00 + + + + BID + 4358 + + + XF + apache-double-reverse-spoof(8629) + + + CONFIRM + http://www.apache.org/dist/httpd/CHANGES_1.3 + + Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities. + + + + + + + + + cpe:/a:ganglia:php_rrd_web_client:1.0.1 + + CVE-2002-2104 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.573-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T10:06:00.000-04:00 + + + ALLOWS_USER_ACCESS + + XF + ganglia-graph-command-execution(7999) + + + SECTRACK + 1003376 + + + BID + 3962 + + graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function. + + + + + + + + + + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + + CVE-2002-2105 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.713-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T10:11:00.000-04:00 + + + + XF + winxp-manifest-xml-dos(8000) + + + MISC + http://www.supernature-forum.de/vbb/printthread.php?threadid=6458 + + + BID + 3942 + + + SECTRACK + 1003308 + + Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file. + + + + + + + + + + + cpe:/a:wikkitikkitavi:wikkitikkitavi:0.20 + cpe:/a:wikkitikkitavi:wikkitikkitavi:0.10 + cpe:/a:wikkitikkitavi:wikkitikkitavi:0.5 + + CVE-2002-2106 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:20.870-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T10:14:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + wikkitikkitavi-include-template(8001) + + + BID + 3946 + + + SECTRACK + 1003307 + + + MLIST + [tavi-devel] 20020102 "Tavi security advisory + + PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php. + + + + + + + + + cpe:/a:veridis:openkeyserver:1.2 + + CVE-2002-2107 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.027-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-19T10:19:00.000-04:00 + + + + BID + 4369 + + + MISC + http://www.securiteam.com/securitynews/5BP0R1P6KE.html + + + XF + openkeyserver-web-interface-css(8651) + + Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. + + + + + + + + + + + cpe:/a:sony:vaio_manual_cybersupport:3.0 + cpe:/a:sony:vaio_manual_cybersupport + cpe:/a:sony:vaio_manual_cybersupport:3.1 + + CVE-2002-2108 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.180-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-19T10:51:00.000-04:00 + + + + BID + 3959 + + + XF + vaio-html-gain-access(8009) + + + CONFIRM + http://vaio-online.sony.com/announcement/technical_explain.html + + + CONFIRM + http://vaio-online.sony.com/announcement/announcement_content.html + + Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail. + + + + + + + + + + + + + + + + + + cpe:/a:matt_wright:formmail:1.8 + cpe:/a:matt_wright:formmail:1.9 + cpe:/a:matt_wright:formmail:1.6 + cpe:/a:matt_wright:formmail:1.7 + cpe:/a:matt_wright:formmail:1.4 + cpe:/a:matt_wright:formmail:1.5 + cpe:/a:matt_wright:formmail:1.2 + cpe:/a:matt_wright:formmail:1.3 + cpe:/a:matt_wright:formmail:1.1 + cpe:/a:matt_wright:formmail:1.0 + + CVE-2002-2109 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.337-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T10:58:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BUGTRAQ + 20020123 Anonymous Mail Forwarding Vulnerabilities in FormMail 1.9 + + + BID + 3954 + + + XF + formmail-referer-header-spoof(8012) + + + CONFIRM + http://worldwidemart.com/scripts/formmail.shtml + + Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer. + + + + + + + + + + cpe:/h:rca:digital_cable_modem:dcm225 + cpe:/h:rca:digital_cable_modem:dcm225e + + CVE-2002-2110 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.527-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:01:00.000-04:00 + + + + BID + 4375 + + + XF + rca-cablemodem-reset-dos(8661) + + + BUGTRAQ + 20020327 RCA cable modem Deny of Service + + The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device. + + + + + + + + + + + + cpe:/a:gianni_tedesco:fwmon:1.0.8 + cpe:/a:gianni_tedesco:fwmon:1.0.9 + cpe:/a:gianni_tedesco:fwmon:1.0.7 + cpe:/a:gianni_tedesco:fwmon:1.0.6 + + CVE-2002-2111 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:07:00.000-04:00 + + + + XF + fwmon-large-packet-bo(8104) + + + BID + 3984 + + + CONFIRM + http://www.scaramanga.co.uk/fwmon/fwmon-1.0.10.tar.gz + + Fwmon before 1.0.10 allows remote attackers to cause a denial of service (crash) by causing the kernel to return a large packet. + + + + + + + + + + cpe:/h:rca:digital_cable_modem:dcm225 + cpe:/h:rca:digital_cable_modem:dcm225e + + CVE-2002-2112 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-19T11:12:00.000-04:00 + + + + BID + 4377 + + + XF + rca-cablemodem-snmp-public(8662) + + + BUGTRAQ + 20020327 Re: RCA cable modem Deny of Service + + + BUGTRAQ + 20020327 RCA cable modem Deny of Service + + RCA Digital Cable Modem DCM225 and DCM225E, and other modems that must conform to the Data-over-Cable Service Interface Specifications DOCSIS standard, uses the "public" community string for SNMP access, which allows remote attackers to read or write MIB information. + + + + + + + + + cpe:/a:agh:htmlsearch:1.0 + + CVE-2002-2113 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:21.963-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:17:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3985 + + + MISC + http://www.securiteam.com/securitynews/5WP0R2K60O.html + + + XF + ahg-search-execute-commands(8032) + + search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter. + + + + + + + + + + + + + + cpe:/a:netjuke:netjuke:1.0_b6 + cpe:/a:netjuke:netjuke:1.0_b3 + cpe:/a:netjuke:netjuke:1.0_b2 + cpe:/a:netjuke:netjuke:1.0_b5 + cpe:/a:netjuke:netjuke:1.0_b4 + cpe:/a:netjuke:netjuke:1.0_b1 + + CVE-2002-2114 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:18.377-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:25:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 3988 + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=507312&group_id=42076&atid=432052 + + + XF + netjuke-section-command-execution(8101) + + Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call. + + + + + + + + + + + + + + + + + cpe:/a:hns:hns:2.10_pl1 + cpe:/a:hns:hns:2.00_pl2 + cpe:/a:hns:hns:2.00_pl1 + cpe:/a:hns:hns-lite:0.6 + cpe:/a:hns:hns:2.00_pl4 + cpe:/a:hns:hns:2.00_pl3 + cpe:/a:hns:hns:2.00_pl0 + cpe:/a:hns:hns-lite:0.7 + cpe:/a:hns:hns-lite:0.8 + + CVE-2002-2115 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:22.277-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2005-09-19T11:32:00.000-04:00 + + + + BID + 4102 + + + XF + hns-cgi-css(8204) + + + CONFIRM + http://www.h14m.org/SA/2002/hns-SA-2002-01.txt + + Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML. + + + + + + + + + + cpe:/h:netgear:rm356 + cpe:/h:netgear:rt338 + + CVE-2002-2116 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:22.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:35:00.000-04:00 + + + + BID + 4111 + + + XF + netgear-udp-portscan-dos(8206) + + + BUGTRAQ + 20020215 Re: Remote DoS in Netgear RM-356 + + + BUGTRAQ + 20020215 Remote DoS in Netgear RM-356 + + Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap. + + + + + + + + + cpe:/o:microsoft:windows_xp::gold + + CVE-2002-2117 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:22.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:39:00.000-04:00 + + + + MISC + http://www.safehack.com/Advisory/sh_XPDOS500.txt + + + XF + winxp-udp-dos(8207) + + Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP). + + + + + + + + + cpe:/a:blue_world_communications:lasso_web_data_engine:3.6.5 + + CVE-2002-2118 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:18.687-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:43:00.000-04:00 + + + + BID + 4110 + + + MISC + http://www.securiteam.com/windowsntfocus/5NP0B2A6AQ.html + + + XF + lasso-webdata-dos(8208) + + + VULN-DEV + 20020219 RE: Blueworld WebData Engine 1.6.5 + + Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL. + + + + + + + + + + cpe:/a:novell:edirectory:8.7 + cpe:/a:novell:edirectory:8.6.2 + + CVE-2002-2119 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:22.900-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-19T11:45:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 4893 + + + XF + novell-edirectory-insecure-passwords(9229) + + + BUGTRAQ + 20020530 Security Implications of Novell eDirectory. + + Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing. + + + + + + + + + cpe:/a:qnx:rtos:4.25 + + CVE-2002-2120 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.040-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T08:39:00.000-04:00 + + + ALLOWS_USER_ACCESS + + BID + 4906 + + + BID + 4905 + + + XF + qnx-rtos-int10-bo(9236) + + + XF + qnx-rtos-watcom-bo(9235) + + + BUGTRAQ + 20020601 Re: Multiple vulnerabilities in QNX + + + BUGTRAQ + 20020531 Multiple vulnerabilities in QNX + + Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10. + + + + + + + + + cpe:/a:surfcontrol:superscout_email_filter:3.5.1::smtp + + CVE-2002-2121 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:19.157-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2005-09-20T09:05:00.000-04:00 + + + + BID + 4257 + + + XF + surfcontrol-superscout-helo-dos(8424) + + + VULN-DEV + 20020309 DoS in SurfControl's EmailFilter + + SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow. + + + + + + + + + cpe:/a:pointsec_mobile_technologies:pointsec:1.0::palm_os + + CVE-2002-2122 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.400-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2005-09-20T09:18:00.000-04:00 + + + + BID + 4681 + + + XF + pointsec-palmos-plaintext-pin(9021) + + + BUGTRAQ + 20020507 KPMG-2002018: Pointsec for PalmOS PIN disclosure + + Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory. + + + + + + + + + cpe:/a:gallery_project:gallery:1.3.2 + + CVE-2002-2123 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2005-09-20T09:20:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6489 + + + BUGTRAQ + 20021228 Gallery v1.3.2 allows remote exploit (fixed in 1.3.3) + + + XF + gallery-winxppublishing-command-execution(10943) + + PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter. + + + + + + + + + cpe:/a:nylon:nylon:0.2 + + CVE-2002-2124 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-01-24T09:20:00.000-05:00 + + + + XF + nylon-recv-endless-dos(10334) + + + BID + 5938 + + + BUGTRAQ + 20021010 nylon 0.2 (0.3?) DoS + + The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing. + + + + + + + + + + + cpe:/a:microsoft:ie:6.0.2800.1106 + cpe:/a:microsoft:ie:6.0:sp1 + cpe:/a:microsoft:ie:6.0.2600 + + CVE-2002-2125 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.837-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-24T09:33:00.000-05:00 + + + + BID + 5778 + + + BUGTRAQ + 20020923 IE6 SSL Certificate Chain Verification + + + XF + ie-ssl-certificate-expired(10180) + + Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack. + + + + + + + + + cpe:/a:pedestal_software:integrity_protection_driver:1.2 + + CVE-2002-2126 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:23.993-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-24T09:41:00.000-05:00 + + + + BID + 6295 + + + XF + ipd-change-system-clock(10745) + + + NTBUGTRAQ + 20021203 New Integrity Protection Driver (IPD) Available + + + BUGTRAQ + 20021202 Bypassing Integrity Protection Driver (time vulnerability) + + restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time. + + + + + + + + + cpe:/a:pedestal_software:integrity_protection_driver:1.2 + + CVE-2002-2127 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.133-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-24T10:08:00.000-05:00 + + + + NTBUGTRAQ + 20021203 New Integrity Protection Driver (IPD) Available + + + XF + ipd-ntcreatesymboliclinkobject-symlink(10747) + + + MISC + http://www.phrack.org/show.php?p=59&a=16 + + Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink. + + + + + + + + + cpe:/a:w-agora:w-agora:4.1.5 + + CVE-2002-2128 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.290-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-24T12:58:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6463 + + + XF + wagora-editform-file-include(10919) + + + BUGTRAQ + 20021219 XSS and PHP include bug in W-Agora + + + BUGTRAQ + 20021220 Re: XSS and PHP include bug in W-Agora + + editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter. + + + + + + + + + cpe:/a:w-agora:w-agora:4.1.5 + + CVE-2002-2129 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.430-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-24T13:00:00.000-05:00 + + + + XF + wagora-editform-xss(10920) + + + BID + 6464 + + + BUGTRAQ + 20021219 XSS and PHP include bug in W-Agora + + + BUGTRAQ + 20021220 Re: XSS and PHP include bug in W-Agora + + Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form. + + + + + + + + + cpe:/a:gallery_project:gallery:1.3.2 + + CVE-2002-2130 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.587-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-24T13:06:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6489 + + + BUGTRAQ + 20021228 Gallery v1.3.2 allows remote exploit (fixed in 1.3.3) + + + XF + gallery-winxppublishing-command-execution(10943) + + + CONFIRM + http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=64&mode=thread&order=0&thold=0 + + publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code. + + + + + + + + + + cpe:/a:perl-httpd:perl-httpd:1.0 + cpe:/a:perl-httpd:perl-httpd:1.0.1 + + CVE-2002-2131 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-24T13:08:00.000-05:00 + + + + BID + 6497 + + + XF + perlhttpd-dotdot-directory-traversal(10992) + + + MISC + http://citrustech.net/~chrisj/perl-httpd/INFO.txt + + Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000:::server:jp + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_xp:::64-bit + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::sp1:64-bit + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_2000::sp3:advanced_server + + CVE-2002-2132 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:24.883-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-24T13:21:00.000-05:00 + + + + BID + 6483 + + + XF + wfp-security-catalogs(10957) + + + BUGTRAQ + 20021226 Full Disclosure: Windows File Protection Old Security Catalog Vulnerability + + Windows File Protection (WFP) in Windows 2000 and XP does not remove old security catalog .CAT files, which could allow local users to replace new files with vulnerable old files that have valid hash codes. + + + + + + + + + cpe:/h:telindus:1120_adsl_router:6.0.21b_firmware + + CVE-2002-2133 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:25.087-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-01-25T09:28:00.000-05:00 + + + + BUGTRAQ + 20021228 Telindus 112x ADSL Router - Weak Password Encryption + + + BID + 6919 + + + XF + telindus-adsl-weak-encryption(10951) + + + BUGTRAQ + 20030223 Weak Encryption Scheme in Telindus 112x + + + OSVDB + 4762 + + Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password. + + + + + + + + + cpe:/a:peel:peel:1.0b + + CVE-2002-2134 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:25.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-25T09:45:00.000-05:00 + + + + BUGTRAQ + 20021231 PEEL (PHP) + + + BID + 6496 + + + XF + peel-haut-file-include(10960) + + + SECTRACK + 1005869 + + haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file. + + + CVE-2002-2135 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:33.413-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1618. Reason: This candidate is a duplicate of CVE-2002-1618. Notes: All CVE users should reference CVE-2002-1618 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + CVE-2002-2136 + 2002-12-31T00:00:00.000-05:00 + 2008-04-09T00:00:00.000-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1590. Reason: This candidate is a duplicate of CVE-2002-1590. Notes: All CVE users should reference CVE-2002-1590 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + cpe:/h:alloy:gl-2422ap-s + cpe:/h:linksys:wap11:2.2 + cpe:/h:eusso:gl2422_ap + cpe:/h:wisecom:gl2422ap-0t + cpe:/h:d-link:dwl-900ap%2b:b1_2.2 + cpe:/h:d-link:dwl-900ap%2b:b1_2.1 + + CVE-2002-2137 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:25.650-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-27T07:42:00.000-05:00 + + + + BID + 6100 + + + XF + ieee80211b-ap-information-disclosure(10536) + + + BUGTRAQ + 20021103 Accesspoints disclose wep keys, password and mac filter (fwd) + + GlobalSunTech Wireless Access Points (1) WISECOM GL2422AP-0T, and possibly OEM products such as (2) D-Link DWL-900AP+ B1 2.1 and 2.2, (3) ALLOY GL-2422AP-S, (4) EUSSO GL2422-AP, and (5) LINKSYS WAP11-V2.2, allow remote attackers to obtain sensitive information like WEP keys, the administrator password, and the MAC filter via a "getsearch" request to UDP port 27155. + + + + + + + + + + + + + + + + + + + + cpe:/h:hp:advanced_server_9000:b.04.09 + cpe:/h:hp:advanced_server_9000:b.04.07 + cpe:/o:hp:hp-ux:11.4 + cpe:/o:hp:hp-ux:11.11 + cpe:/h:hp:advanced_server_9000:b.04.08 + cpe:/h:hp:advanced_server_9000:b.04.05 + cpe:/o:hp:hp-ux:11.00 + cpe:/h:hp:advanced_server_9000:b.04.06 + + CVE-2002-2138 + 2002-12-31T00:00:00.000-05:00 + 2009-03-04T00:16:03.890-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-01-27T09:48:00.000-05:00 + + + + + XF + hp-as-rfcnetbios-dos(9536) + + + HP + HPSBUX0207-198 + + + BID + 5195 + + + + + RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of sevrice (panic) via a malformed UDP packet on port 139. + + + + + + + + + + + + + + + cpe:/o:cisco:pix_firewall:6.1%282%29 + cpe:/o:cisco:pix_firewall:6.1 + cpe:/o:cisco:pix_firewall:6.0%282%29 + cpe:/o:cisco:pix_firewall:6.0%283%29 + cpe:/o:cisco:pix_firewall:6.0%281%29 + cpe:/o:cisco:pix_firewall:6.0 + cpe:/o:cisco:pix_firewall:6.1%283%29 + + CVE-2002-2139 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:25.977-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2006-01-27T09:54:00.000-05:00 + + + + BID + 6211 + + + CIAC + N-017 + + + XF + cisco-pix-isakmp-sa-mitm(10660) + + + CISCO + 20021120 Cisco PIX Multiple Vulnerabilities + + Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack. + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:cisco:pix_firewall:6.1%281%29 + cpe:/o:cisco:pix_firewall:6.1%282%29 + cpe:/o:cisco:pix_firewall:5.2%285%29 + cpe:/o:cisco:pix_firewall:5.2%286%29 + cpe:/o:cisco:pix_firewall:5.2%287%29 + cpe:/o:cisco:pix_firewall:5.2%288%29 + cpe:/o:cisco:pix_firewall:6.0 + cpe:/o:cisco:pix_firewall:6.2%281%29 + cpe:/o:cisco:pix_firewall:6.1 + cpe:/o:cisco:pix_firewall:6.0%282%29 + cpe:/o:cisco:pix_firewall:6.2 + cpe:/o:cisco:pix_firewall:6.0%283%29 + cpe:/o:cisco:pix_firewall:5.2 + cpe:/o:cisco:pix_firewall:6.0%281%29 + cpe:/o:cisco:pix_firewall:5.2%283%29 + cpe:/o:cisco:pix_firewall:5.2%282%29 + cpe:/o:cisco:pix_firewall:6.1%283%29 + cpe:/o:cisco:pix_firewall:5.2%281%29 + cpe:/o:cisco:pix_firewall:5.2%284%29 + + CVE-2002-2140 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:26.150-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-01-27T09:59:00.000-05:00 + + + + BID + 6212 + + + XF + cisco-pix-http-dos(10661) + + + CISCO + 20021120 Cisco PIX Multiple Vulnerabilities + + + CIAC + N-017 + + Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS. + + + + + + + + + + + + cpe:/a:bea:weblogic_server:7.0.0.1::express + cpe:/a:bea:weblogic_server:7.0::express + cpe:/a:bea:weblogic_server:7.0 + cpe:/a:bea:weblogic_server:7.0.0.1 + + CVE-2002-2141 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:33.790-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T08:58:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5846 + + + XF + weblogic-servlet-ejb-security-removal(10291) + + + BEA + BEA02-21.00 + + BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions. + + + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:7.0.0.1::express + cpe:/a:bea:weblogic_server:7.0::express + cpe:/a:bea:weblogic_integration:7.0 + cpe:/a:bea:weblogic_server:7.0 + cpe:/a:bea:weblogic_server:7.0.0.1 + cpe:/a:bea:weblogic_server:6.1::express + cpe:/a:bea:weblogic_server:6.0::express + cpe:/a:bea:weblogic_server:6.0 + cpe:/a:bea:weblogic_server:6.1 + cpe:/a:bea:weblogic_integration:7.0:sp1 + + CVE-2002-2142 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:33.853-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T09:06:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5971 + + + XF + weblogic-security-policy-ignored(10392) + + + BEA + BEA02-22.00 + + An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension. + + + + + + + + + cpe:/a:mysimplenews:mysimplenews:1.0 + + CVE-2002-2143 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:26.667-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:04:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5866 + + + BUGTRAQ + 20021002 MySimpleNews (PHP) + + + XF + mysimplenews-admin-plaintext-password(10298) + + The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html. + + + + + + + + + + cpe:/a:free_peers:bearshare:4.0.5 + cpe:/a:free_peers:bearshare:4.0.6 + + CVE-2002-2144 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:26.820-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-30T15:30:00.000-05:00 + + + + XF + bearshare-encoded-directory-traversal(10240) + + + BID + 5888 + + + BUGTRAQ + 20021003 BearShare Directory Traversal Issue Resurfaces + + Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot) characters. + + + + + + + + + cpe:/a:savant:savant_webserver:3.1 + + CVE-2002-2145 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:26.977-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:31:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5709 + + + XF + savant-protected-folder-access(10104) + + + BUGTRAQ + 20020913 Savant 3.1 multiple vulnerabilities + + Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename. + + + + + + + + + cpe:/a:savant:savant_webserver:3.1 + + CVE-2002-2146 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:27.117-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:33:00.000-05:00 + + + + BID + 5706 + + + XF + savant-cgitest-bo(10102) + + + BUGTRAQ + 20020913 Savant 3.1 multiple vulnerabilities + + cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request. + + + CVE-2002-2147 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:34.647-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1828. Reason: This candidate is a duplicate of CVE-2002-1828. Notes: All CVE users should reference CVE-2002-1828 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + + + + + cpe:/h:lucent:ascend_max_router:4.0 + cpe:/h:lucent:ascend_pipeline_router:5.0 + cpe:/h:lucent:ascend_pipeline_router:2.0 + cpe:/h:lucent:ascend_pipeline_router:3.0 + cpe:/h:lucent:ascend_pipeline_router:6.0.2 + cpe:/h:lucent:ascend_max_router:2.0 + cpe:/h:lucent:ascend_max_router:5.0_ap48 + cpe:/h:lucent:ascend_pipeline_router:4.0 + cpe:/h:lucent:dslterminator + cpe:/h:lucent:ascend_pipeline_router:1.0 + cpe:/h:lucent:ascend_max_router:3.0 + cpe:/h:lucent:ascend_max_router:5.0 + cpe:/h:lucent:ascend_pipeline_router:6.0 + + CVE-2002-2148 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:27.417-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-30T15:37:00.000-05:00 + + + + BID + 5335 + + + XF + lucent-port9-information-disclosure(9704) + + + BUGTRAQ + 20020727 Phenoelit ADvisory 0815 ++ ** Ascend + + Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response. + + + + + + + + + + + cpe:/h:lucent:access_point_service_router_1500 + cpe:/h:lucent:access_point_service_router_600 + cpe:/h:lucent:access_point_service_router_300 + + CVE-2002-2149 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:27.603-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:39:00.000-05:00 + + + + BID + 5333 + + + XF + lucent-ap-get-dos(9705) + + + BUGTRAQ + 20020727 Phenoelit Advisory 0815 ++ // Xedia + + Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrative interface. + + + + + + + + + + + + + + + + + cpe:/o:juniper:netscreen_screenos:3.0.1r1 + cpe:/o:juniper:netscreen_screenos:2.10_r4 + cpe:/o:juniper:netscreen_screenos:3.0.1r2 + cpe:/o:juniper:netscreen_screenos:2.10_r3 + cpe:/o:juniper:netscreen_screenos:2.7.1r2 + cpe:/o:juniper:netscreen_screenos:2.7.1r1 + cpe:/o:juniper:netscreen_screenos:2.7.1 + cpe:/o:juniper:netscreen_screenos:3.0.3_r1.1 + cpe:/o:juniper:netscreen_screenos:2.7.1r3 + + CVE-2002-2150 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:27.760-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:41:00.000-05:00 + + + + CERT-VN + VU#539363 + + + BID + 6023 + + + XF + firewall-state-table-dos(10449) + + Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall to refuse any new connections. + + + CVE-2002-2151 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:35.243-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1651. Reason: This candidate is a duplicate of CVE-2002-1651. Notes: All CVE users should reference CVE-2002-1651 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2002 + + CVE-2002-2152 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:28.087-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-01-30T15:44:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + 602pro-admin-priviliges(10408) + + + BID + 6006 + + + BUGTRAQ + 20021018 interSEC security advisory - Multiple bugs in Web602 web server + + The Czech edition of Software602's Web Server before 2002.0.02.0916 allows remote attackers to gain administrator privileges via direct HTTP requests to the /admin/ directory, which is not password protected. + + + + + + + + + + cpe:/a:oracle:application_server:4.0.8 + cpe:/a:oracle:application_server:4.0.8.2 + + CVE-2002-2153 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:28.227-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-30T15:47:00.000-05:00 + + + ALLOWS_USER_ACCESS + + CERT-VN + VU#467555 + + + XF + oracle-appserver-plsql-format-string(10183) + + + BID + 4844 + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdf + + + MISC + http://www.nextgenss.com/vna/ora-ias.txt + + Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code. + + + + + + + + + cpe:/a:monkey-project:monkey_http_daemon:0.1.4 + + CVE-2002-2154 + 2002-12-31T00:00:00.000-05:00 + 2012-10-24T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-30T15:48:00.000-05:00 + + + + + BID + 5792 + + + XF + monkey-dotdot-directory-traversal(10188) + + + BUGTRAQ + 20020925 IIL Advisory: Reverse traversal vulnerability in Monkey (0.1.4) HTTP server + + Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.725 + cpe:/a:cerulean_studios:trillian:0.73 + + CVE-2002-2155 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:28.540-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-31T10:30:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5388 + + + BUGTRAQ + 20020801 Two more exploitable holes in the trillian irc module + + + XF + trillian-irc-format-string(9761) + + Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name. + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.73 + + CVE-2002-2156 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:28.680-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-01-31T10:37:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BUGTRAQ + 20020801 Two more exploitable holes in the trillian irc module + + + BUGTRAQ + 20020801 trillian buffer overflow + + Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response. + + + CVE-2002-2157 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:36.383-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1660. Reason: This candidate is a duplicate of CVE-2002-1660. Notes: All CVE users should reference CVE-2002-1660 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + cpe:/a:zendocs:zentrack:2.0.3 + cpe:/a:zendocs:zentrack:2.0.2c_beta + cpe:/a:zendocs:zentrack:2.0.1c_beta + + CVE-2002-2158 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:28.993-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-01-31T15:29:00.000-05:00 + + + + BID + 4973 + + + XF + zentrack-ticketid-path-disclosure(9312) + + + BUGTRAQ + 20020610 [ARL02-A14] ZenTrack System Information Path Disclosure Vulnerability + + zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. + + + + + + + + + + + cpe:/h:linksys:befsr41:1.42.7 + cpe:/h:linksys:befsr11:1.42.7 + cpe:/h:linksys:befsru31:1.42.7 + + CVE-2002-2159 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:29.150-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-02-01T15:25:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 4987 + + + MISC + http://www.securiteam.com/securitynews/5OP022K7GE.html + + + XF + linksys-etherfast-admin-enabled(9330) + + Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers go gain access. + + + CVE-2002-2160 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:36.807-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1798. Reason: This candidate is a duplicate of CVE-2002-1798. Notes: All CVE users should reference CVE-2002-1798 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + cpe:/a:kerio:personal_firewall:2.1.4 + cpe:/a:kerio:personal_firewall:2.1 + cpe:/a:kerio:personal_firewall:2.1.1 + cpe:/a:kerio:personal_firewall:2.1.2 + cpe:/a:kerio:personal_firewall:2.1.3 + + CVE-2002-2161 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:29.463-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-02-03T14:38:00.000-05:00 + + + + BID + 5570 + + + XF + kerio-pf-synflood-dos(9963) + + + BUGTRAQ + 20020826 Kerio Personal Firewall DOS Vulnerability + + Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood. + + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.725 + cpe:/a:cerulean_studios:trillian:0.73 + cpe:/a:cerulean_studios:trillian:0.6351 + + CVE-2002-2162 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:29.617-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-02-03T14:39:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5677 + + + BUGTRAQ + 20020909 Trillian weakly encrypts saved passwords + + + XF + trillian-insecure-password-storage(10092) + + Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts. + + + + + + + + + cpe:/a:killervault:kvpoll:1.1 + + CVE-2002-2163 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:29.773-04:00 + + + 4.0 + NETWORK + LOW + SINGLE_INSTANCE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-02-03T14:41:00.000-05:00 + + + + BID + 4736 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes5.txt + + KvPoll 1.1 allows remote authenticated users to vote more than once by setting the "already_voted" cookie by various methods, including a direct call to clear_cookies.php. + + + + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + cpe:/a:microsoft:outlook_express:5.0 + cpe:/a:microsoft:outlook_express:5.0.1 + cpe:/a:microsoft:outlook_express:5.5 + + CVE-2002-2164 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:29.917-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-02-03T14:42:00.000-05:00 + + + + BUGTRAQ + 20020909 Small correction... + + + BID + 5682 + + + XF + outlook-express-href-dos(10067) + + + BUGTRAQ + 20020909 Small bug crashes OE + + Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. + + + + + + + + + + + + + + + + + cpe:/a:imho:imho_webmail:0.98.2 + cpe:/a:imho:imho_webmail:0.96.3 + cpe:/a:imho:imho_webmail:0.96.2 + cpe:/a:imho:imho_webmail:0.96.1 + cpe:/a:imho:imho_webmail:0.96 + cpe:/a:imho:imho_webmail:0.98 + cpe:/a:imho:imho_webmail:0.98.3 + cpe:/a:imho:imho_webmail:0.97 + cpe:/a:imho:imho_webmail:0.97.1 + + CVE-2002-2165 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.070-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-02-07T13:10:00.000-05:00 + + + + BID + 5238 + + + MISC + http://www.securitybugware.org/Other/5537.html + + + XF + imho-roxen-session-hijacking(9615) + + The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox. + + + + + + + + + + cpe:/a:e-zone_media_inc.:fusetalk:3.0 + cpe:/a:e-zone_media_inc.:fusetalk:2.0 + + CVE-2002-2166 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.243-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-02-13T11:03:00.000-05:00 + + + + BID + 5236 + + + XF + fusetalk-search-xss(9637) + + Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. + + + + + + + + + + cpe:/a:thorsten_korner:123tkshop:0.3 + cpe:/a:thorsten_korner:123tkshop:0.2 + + CVE-2002-2167 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.400-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-02-13T11:05:00.000-05:00 + + + + BID + 5243 + + + XF + 123tkshop-include-read-files(9581) + + + BUGTRAQ + 20020715 Again NULL and addslashes() (now in 123tkshop) + + Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call. + + + + + + + + + + cpe:/a:thorsten_korner:123tkshop:0.3 + cpe:/a:thorsten_korner:123tkshop:0.2 + + CVE-2002-2168 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.557-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-02-13T11:06:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5244 + + + XF + 123tkshop-sql-injection(9582) + + + CONFIRM + http://www.123tkshop.org/index.php + + + BUGTRAQ + 20020715 Again NULL and addslashes() (now in 123tkshop) + + SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php. + + + + + + + + + + + cpe:/a:aol:instant_messenger:4.5 + cpe:/a:aol:instant_messenger:4.7 + cpe:/a:aol:instant_messenger:4.7.2480 + + CVE-2002-2169 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.713-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-02-13T11:08:00.000-05:00 + + + + BID + 5246 + + + MISC + http://www.mindflip.org/aim.html + + + XF + aim-http-refresh-functions(9616) + + + BUGTRAQ + 20020716 AIM forced behavior "issue" + + Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL. + + + + + + + + + + + + cpe:/a:working_resources_inc.:badblue:enterprise_1.7.4 + cpe:/a:working_resources_inc.:badblue:enterprise_1.7.3 + cpe:/a:working_resources_inc.:badblue:enterprise_1.7.2 + cpe:/a:working_resources_inc.:badblue:enterprise_1.7 + + CVE-2002-2170 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:30.867-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-02-14T08:26:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5276 + + + XF + badblue-unauth-admin-access(9642) + + + BUGTRAQ + 20020720 BadBlue - Unauthorized Administrative Command Execution + + Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared. + + + + + + + + + + cpe:/a:andrey_cherezov:acweb:1.8 + cpe:/a:andrey_cherezov:acweb:1.14 + + CVE-2002-2171 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:39.807-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-02-14T08:30:00.000-05:00 + + + + BID + 5793 + + + XF + acweb-xss(10191) + + + BUGTRAQ + 20020925 IIL Advisory: Vulnerabilities in acWEB HTTP server + + Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL. + + + + + + + + + + cpe:/a:shana:informed_filler:3.5 + cpe:/a:shana:informed_designer:3.5 + + CVE-2002-2172 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:31.167-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-02-14T08:32:00.000-05:00 + + + + BID + 5795 + + + MISC + http://www.cirt.net/advisories/shana.shtml + + + XF + informed-document-information-disclosure(10192) + + + BUGTRAQ + 20020925 Shana Informed 3.05 information disclosure + + Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information. + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.725 + cpe:/a:cerulean_studios:trillian:0.73 + + CVE-2002-2173 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:31.320-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-02-14T08:33:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 5389 + + + BUGTRAQ + 20020801 Two more exploitable holes in the trillian irc module + + + XF + trillian-irc-dcc-bo(9764) + + Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message. + + + + + + + + + cpe:/a:software602:602pro_lan_suite:2002 + + CVE-2002-2174 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:31.477-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-02-14T08:34:00.000-05:00 + + + + XF + 602pro-telnet-proxy-dos(9768) + + + BUGTRAQ + 20020804 Advisory: Multiple 602Pro LAN SUITE 2002 Denial of Service Attacks + + The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections. + + + + + + + + + cpe:/a:php:phpsquidpass + + CVE-2002-2175 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:41.617-04:00 + + + 4.0 + NETWORK + LOW + SINGLE_INSTANCE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-03-01T12:33:00.000-05:00 + + + + BID + 5090 + + + XF + phpsquidpass-user-deletion(9417) + + + CONFIRM + http://sourceforge.net/forum/forum.php?forum_id=188359 + + + BUGTRAQ + 20020623 phpsquidpass: unauthorized user deleting + + phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username. + + + + + + + + + + cpe:/a:phpbb_group:phpbb:2.0.1 + cpe:/a:phpbb_group:phpbb:2.0.0 + + CVE-2002-2176 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:31.773-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-03-01T12:45:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5342 + + + XF + phpbb-gendermod-admin-privileges(9692) + + + BUGTRAQ + 20020727 phpBB/gender mod allows get admin privilege, exploit/patch + + SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page. + + + + + + + + + + + + + + + + cpe:/a:bea:weblogic_server:6.1:sp1 + cpe:/a:bea:weblogic_server:7.0.0.1::express + cpe:/a:bea:weblogic_server:6.1:sp1:express + cpe:/a:bea:weblogic_server:7.0::express + cpe:/a:bea:weblogic_server:7.0 + cpe:/a:bea:weblogic_server:7.0.0.1 + cpe:/a:bea:weblogic_server:6.1::express + cpe:/a:bea:weblogic_server:6.1 + + CVE-2002-2177 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:41.757-04:00 + + + 2.6 + NETWORK + HIGH + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-01T13:52:00.000-05:00 + + + + BID + 5819 + + + XF + weblogic-http-response-information(10221) + + + BEA + BEA02-20.00 + + BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users. + + + + + + + + + cpe:/a:phpwebsite:phpwebsite:0.8.3 + + CVE-2002-2178 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.103-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-03-03T14:54:00.000-05:00 + + + + BID + 5864 + + + BUGTRAQ + 20021002 phpWebSite XSS Vulnerability + + + XF + phpwebsite-img-article-xss(10256) + + Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag. + + + + + + + + + cpe:/h:unisys:clearpath_mcp + + CVE-2002-2179 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.260-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2006-03-03T15:02:00.000-05:00 + + + + BID + 5863 + + + XF + clearpath-port-scan-dos(10260) + + The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap. + + + + + + + + + + + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + cpe:/o:openbsd:openbsd:2.1 + cpe:/o:openbsd:openbsd:2.0 + cpe:/o:openbsd:openbsd:2.3 + cpe:/o:openbsd:openbsd:2.2 + cpe:/o:openbsd:openbsd:2.5 + cpe:/o:openbsd:openbsd:2.4 + cpe:/o:openbsd:openbsd:2.7 + cpe:/o:openbsd:openbsd:2.6 + cpe:/o:openbsd:openbsd:2.9 + cpe:/o:openbsd:openbsd:2.8 + + CVE-2002-2180 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.400-04:00 + + + 6.8 + LOCAL + LOW + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-03-03T15:14:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5861 + + + OPENBSD + 20021002 Incorrect argument checking in the setitimer(2) system call may allow an attacker to write to kernel memory. + + + XF + openbsd-setitimer-memory-overwrite(10278) + + + CONFIRM + ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/032_kerntime.patch + + The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error. + + + + + + + + + cpe:/a:sonicwall:content_filtering + + CVE-2002-2181 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-03T15:58:00.000-05:00 + + + + BID + 6063 + + + BUGTRAQ + 20021029 Bypassing website filter in SonicWall + + + XF + sonicwall-content-ip-bypass(10531) + + SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name. + + + + + + + + + + cpe:/a:seunghyun_seo:msn666:1.0.1 + cpe:/a:seunghyun_seo:msn666:1.0 + + CVE-2002-2182 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.727-04:00 + + + 6.4 + NETWORK + LOW + NONE + NONE + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-06T15:13:00.000-05:00 + + + + BID + 5015 + + Buffer overflow in Seunghyun Seo's MSN666 MSN Sniffer 1.0 and 1.0.1 allows remote attackers to execute arbitrary code via a long MSN packet. + + + + + + + + + + + cpe:/a:phpshare:phpshare:0.6_beta_1 + cpe:/a:phpshare:phpshare:0.6_beta_2 + cpe:/a:phpshare:phpshare:0.5.2 + + CVE-2002-2183 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:32.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T09:10:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5049 + + phpShare.php in phpShare before 0.6 beta 3 allows remote attackers to include and execute arbitrary PHP scripts from remote servers. + + + + + + + + + cpe:/a:digi-net_technologies:digichat:3.5 + + CVE-2002-2184 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:33.023-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-17T09:17:00.000-05:00 + + + + BID + 5019 + + Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:sgi:irix:6.5.13 + cpe:/o:sgi:irix:6.5 + cpe:/o:sgi:irix:6.5.11 + cpe:/o:sgi:irix:6.5.12 + cpe:/o:debian:debian_linux:2.2::alpha + cpe:/o:debian:debian_linux:2.2::sparc + cpe:/o:sgi:irix:6.5.10 + cpe:/o:redhat:enterprise_linux:4.0::enterprise_server + cpe:/o:debian:debian_linux:2.2::arm + cpe:/o:redhat:linux_advanced_workstation:2.1::ia64 + cpe:/o:redhat:linux:7.2::i386 + cpe:/o:redhat:linux:7.3::i386 + cpe:/o:redhat:linux:7.0::i386 + cpe:/o:redhat:linux:7.1::i386 + cpe:/o:redhat:linux:6.2::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.0 + cpe:/o:redhat:linux:7.1::alpha + cpe:/o:redhat:linux:6.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.1 + cpe:/o:redhat:linux:7.0::alpha + cpe:/o:mandrakesoft:mandrake_linux:8.2 + cpe:/o:redhat:linux:7.2::ia64 + cpe:/o:microsoft:windows_98se + cpe:/o:redhat:enterprise_linux_desktop:3.0 + cpe:/o:redhat:linux:7.1::ia64 + cpe:/o:mandrakesoft:mandrake_linux:8.1::ia64 + cpe:/o:redhat:linux:6.2::sparc + cpe:/o:suse:suse_linux:7.1::x86 + cpe:/o:redhat:enterprise_linux:3.0::enterprise_server + cpe:/o:suse:suse_linux:7.0::sparc + cpe:/o:suse:suse_linux:7.1::sparc + cpe:/o:sgi:irix:6.5.18f + cpe:/o:redhat:enterprise_linux:3.0::advanced_servers + cpe:/o:suse:suse_linux:7.3::sparc + cpe:/o:sgi:irix:6.5.18m + cpe:/o:microsoft:windows_xp::gold:professional + cpe:/o:debian:debian_linux:2.2::powerpc + cpe:/o:debian:debian_linux:2.2::ia-32 + cpe:/o:suse:suse_linux:7.0::i386 + cpe:/o:sgi:irix:6.5.14f + cpe:/o:suse:suse_linux:6.4::i386 + cpe:/o:microsoft:windows_98::gold + cpe:/o:redhat:linux:7.0::sparc + cpe:/o:suse:suse_linux:8.0::i386 + cpe:/o:sgi:irix:6.5.14m + cpe:/o:suse:suse_linux:7.2::i386 + cpe:/o:mandrakesoft:mandrake_linux:8.0::ppc + cpe:/o:suse:suse_linux:7.3::i386 + cpe:/o:suse:suse_linux:7.1:alpha + cpe:/o:suse:suse_linux:6.4::ppc + cpe:/o:sgi:irix:6.5.1 + cpe:/o:suse:suse_linux:7.0:alpha + cpe:/o:sgi:irix:6.5.3 + cpe:/o:sgi:irix:6.5.17f + cpe:/o:sgi:irix:6.5.2 + cpe:/o:sgi:irix:6.5.5 + cpe:/o:sgi:irix:6.5.4 + cpe:/o:sgi:irix:6.5.7 + cpe:/o:sgi:irix:6.5.6 + cpe:/o:sgi:irix:6.5.9 + cpe:/o:sgi:irix:6.5.8 + cpe:/o:microsoft:windows_xp:::home + cpe:/o:suse:suse_linux:7.3::ppc + cpe:/o:suse:suse_linux:7.0::ppc + cpe:/o:suse:suse_linux:6.4:alpha + cpe:/o:sgi:irix:6.5.17m + cpe:/o:sgi:irix:6.5.15f + cpe:/o:debian:debian_linux:2.2::68k + cpe:/o:suse:suse_linux:7.1::spa + cpe:/o:redhat:enterprise_linux_desktop:4.0 + cpe:/o:sgi:irix:6.5.15m + cpe:/o:redhat:enterprise_linux:4.0::advanced_server + cpe:/o:redhat:linux_advanced_workstation:2.1::itanium_processor + cpe:/o:sgi:irix:6.5.16f + cpe:/o:redhat:enterprise_linux:3.0::workstation + cpe:/o:sgi:irix:6.5.16m + cpe:/o:redhat:enterprise_linux:4.0::workstation + + CVE-2002-2185 + 2002-12-31T00:00:00.000-05:00 + 2010-08-21T00:13:59.383-04:00 + + + 4.9 + LOCAL + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2006-03-17T10:12:00.000-05:00 + + + + + BID + 5020 + + + REDHAT + RHSA-2006:0191 + + + REDHAT + RHSA-2006:0190 + + + REDHAT + RHSA-2006:0140 + + + REDHAT + RHSA-2006:0101 + + + MISC + http://www.cs.ucsb.edu/~krishna/igmp_dos/ + + + XF + igmp-spoofed-report-dos(9436) + + + FEDORA + FLSA:157459-2 + + + FEDORA + FLSA:157459-1 + + + FEDORA + FLSA:157459-4 + + + FEDORA + FLSA:157459-3 + + + + + The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network. + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-2186 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:33.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-17T11:38:00.000-05:00 + + + + BID + 6126 + + + CONFIRM + http://www.macromedia.com/v1/Handlers/index.cfm?ID=23500 + + + XF + jrun-unicode-source-disclosure(10570) + + Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL. + + + + + + + + + + + cpe:/a:macromedia:jrun:4.0 + cpe:/a:macromedia:jrun:3.1 + cpe:/a:macromedia:jrun:3.0 + + CVE-2002-2187 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:33.697-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-17T10:29:00.000-05:00 + + + + BID + 6125 + + + CONFIRM + http://www.macromedia.com/v1/Handlers/index.cfm?ID=23500 + + + XF + jrun-log-file-disclosure(10571) + + Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact. + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:openbsd:openbsd:3.0 + + CVE-2002-2188 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:33.853-04:00 + + + 4.9 + LOCAL + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2006-03-17T10:44:00.000-05:00 + + + + BID + 6124 + + + CONFIRM + http://www.openbsd.org/errata31.html#kernresource + + + CONFIRM + http://www.openbsd.org/errata30.html#kernresource + + + XF + openbsd-getrlimit-dos(10572) + + + CONFIRM + ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/018_kernresource.patch + + OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error. + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2003_server:r2 + cpe:/a:activxperts_software:activwebserver + + CVE-2002-2189 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.007-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T10:57:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + MISC + http://www.securiteam.com/windowsntfocus/5MP0C0K7PM.html + + + XF + activwebserver-html-xss(9540) + + Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link. + + + + + + + + + cpe:/a:artscore_studios:cutecast_forum:1.2 + + CVE-2002-2190 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.150-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T10:57:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 6127 + + + XF + cutecast-forum-plaintext-passwords(10556) + + + BUGTRAQ + 20021107 Vulnerability in Cutecast Forum v1.2 + + ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file. + + + + + + + + + + + cpe:/a:lotus:domino:5.0.9a + cpe:/a:lotus:domino:5.0.8 + cpe:/a:lotus:domino:5.0.9 + + CVE-2002-2191 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.307-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-03-17T11:01:00.000-05:00 + + + + BUGTRAQ + 20021107 Lotus Domino HTTP Server security issue + + + BID + 6128 + + + XF + lotus-domino-version-disclosure(10557) + + Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner. + + + + + + + + + cpe:/a:perception:liteserve:2.0.1 + + CVE-2002-2192 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.463-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-03-17T11:10:00.000-05:00 + + + + BID + 6143 + + + BID + 6131 + + + XF + liteserve-directory-index-xss(10561) + + + BUGTRAQ + 20021108 LiteServe Directory Index Cross-Site Scripting + + + VULNWATCH + 20021107 LiteServe Directory Index Cross-Site Scripting + + Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders. + + + + + + + + + cpe:/a:mojo_mail:mojo_mail:2.7 + + CVE-2002-2193 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.603-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-03-17T11:54:00.000-05:00 + + + + BID + 6040 + + + XF + mojo-mail-mojo-xss(10477) + + + BUGTRAQ + 20021024 XSS vulnerability in Mojo Mail Sign-Up Form + + Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter. + + + CVE-2002-2194 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:44.320-04:00 + ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1589. Reason: This candidate is a duplicate of CVE-2002-1589. Notes: All CVE users should reference CVE-2002-1589 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:nullsoft:winamp:2.60::lite + cpe:/a:nullsoft:winamp:2.70 + cpe:/a:nullsoft:winamp:2.80 + cpe:/a:nullsoft:winamp:2.71 + cpe:/a:nullsoft:winamp:2.62::standard + cpe:/a:nullsoft:winamp:2.64::standard + cpe:/a:nullsoft:winamp:2.73::full + cpe:/a:nullsoft:winamp:2.61::full + cpe:/a:nullsoft:winamp:2.70::full + cpe:/a:nullsoft:winamp:2.73 + cpe:/a:nullsoft:winamp:2.72 + cpe:/a:nullsoft:winamp:2.75 + cpe:/a:nullsoft:winamp:2.74 + cpe:/a:nullsoft:winamp:2.76 + cpe:/a:nullsoft:winamp:2.79 + cpe:/a:nullsoft:winamp:2.78 + cpe:/a:nullsoft:winamp:2.65 + + CVE-2002-2195 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:34.900-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-03-17T12:12:00.000-05:00 + + + + BID + 5170 + + + XF + winamp-auto-update-bo(9488) + + Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:samba:samba:2.2.1 + cpe:/a:samba:samba:2.0.5a + cpe:/a:samba:samba:1.9.18:p8 + cpe:/a:samba:samba:2.2.4 + cpe:/a:samba:samba:2.2.3a + cpe:/a:samba:samba:1.9.18:p10 + cpe:/a:samba:samba:1.9.18:p4 + cpe:/a:samba:samba:1.9.18:p7 + cpe:/a:samba:samba:1.9.17 + cpe:/a:samba:samba:1.9.18:p6 + cpe:/a:samba:samba:1.9.17:p3 + cpe:/a:samba:samba:2.2a + cpe:/a:samba:samba:1.9.18:p3 + cpe:/a:samba:samba:2.0.0 + cpe:/a:samba:samba:1.9.17:p5 + cpe:/a:samba:samba:1.9.18:p2 + cpe:/a:samba:samba:2.2.1a + cpe:/a:samba:samba:1.9.17:p4 + cpe:/a:samba:samba:1.9.18:p5 + cpe:/a:samba:samba:1.9.17:p1 + cpe:/a:samba:samba:1.9.18:p1 + + CVE-2002-2196 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:35.087-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T12:30:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + + BID + 5587 + + + XF + samba-memory-structure-bo(10010) + + + REDHAT + RHBA-2002:209 + + + MLIST + [samba-technical] 20020613 struct enum_csc_policy isn't terminated + + + FREEBSD + FreeBSD-SN-02:05 + + Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack. + + + + + + + + + + cpe:/o:sun:solaris:8.0::x86 + cpe:/o:sun:solaris:8.0 + + CVE-2002-2197 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:35.273-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-03-17T13:04:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5171 + + + XF + solaris-poll-dos(9489) + + + SUNALERT + 45300 + + Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference. + + + + + + + + + + + + + + + cpe:/a:zmailer:zmailer:2.99.50 + cpe:/a:zmailer:zmailer:2.99.51 + cpe:/a:zmailer:zmailer:2.99.45 + cpe:/a:zmailer:zmailer:2.99.47 + cpe:/a:zmailer:zmailer:2.99.46 + cpe:/a:zmailer:zmailer:2.99.49 + cpe:/a:zmailer:zmailer:2.99.48 + + CVE-2002-2198 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:35.430-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-03-17T12:49:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5592 + + + XF + zmailer-ipv6-helo-bo(10013) + + + FREEBSD + FreeBSD-SN-02:05 + + Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname. + + + + + + + + + cpe:/a:freebsd:aide + + CVE-2002-2199 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:35.587-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T13:25:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5588 + + + XF + aide-conf-bypass-detection(10015) + + + FREEBSD + FreeBSD-SN-02:05 + + The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection. + + + + + + + + + + + + + cpe:/a:benjamin_lefevre:dobermann_forum:0.1 + cpe:/a:benjamin_lefevre:dobermann_forum:0.2 + cpe:/a:benjamin_lefevre:dobermann_forum:0.3 + cpe:/a:benjamin_lefevre:dobermann_forum:0.4 + cpe:/a:benjamin_lefevre:dobermann_forum:0.5 + + CVE-2002-2200 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:46.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T13:41:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6057 + + + XF + dobermann-php-file-include(10492) + + + BUGTRAQ + 20021027 dobermann FORUM (php) + + Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php. + + + + + + + + + cpe:/a:webmin:webmin:0.99 + + CVE-2002-2201 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:35.900-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-03-17T14:02:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://www.webmin.com/updates.html + + + XF + webmin-printer-shell-commands(10052) + + + FREEBSD + FreeBSD-SN-02:05 + + The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name. + + + + + + + + + cpe:/a:microsoft:outlook_express:6.0 + + CVE-2002-2202 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.040-04:00 + + + 3.8 + LOCAL + HIGH + SINGLE_INSTANCE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2006-03-17T14:26:00.000-05:00 + + + + NTBUGTRAQ + 20021027 OE DBX Exposure + + + XF + outlook-express-dbx-messages(10500) + + Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. + + + + + + + + + + + + + + cpe:/o:sun:solaris:2.6::x86 + cpe:/o:sun:solaris:7.0::x86 + cpe:/o:sun:solaris:2.6 + cpe:/o:sun:solaris:7.0 + cpe:/o:sun:solaris:2.5.1::x86 + cpe:/o:sun:solaris:2.5.1 + + CVE-2002-2203 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:16:46.867-04:00 + + + 4.9 + LOCAL + LOW + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2006-03-17T14:32:00.000-05:00 + + + + BID + 5161 + + + XF + solaris-serial-console-information(9492) + + + SUNALERT + 45502 + + Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information. + + + + + + + + + + + + cpe:/a:redhat:redhat_package_manager:4.0.3 + cpe:/a:redhat:redhat_package_manager:4.0.4 + cpe:/a:redhat:redhat_package_manager:4.0.2-72 + cpe:/a:redhat:redhat_package_manager:4.0.2-71 + + CVE-2002-2204 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.353-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-03-17T14:47:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + BID + 5594 + + + XF + rpm-improper-sig-verification(10011) + + The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source. + + + + + + + + + + + cpe:/a:webresolve:webresolve:0.0.2 + cpe:/a:webresolve:webresolve:0.0.1 + cpe:/a:webresolve:webresolve:0.1 + + CVE-2002-2205 + 2002-07-07T00:00:00.000-04:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-05-01T11:43:00.000-04:00 + + + + BID + 5175 + + + XF + webresolve-hostname-bo(9503) + + + CONFIRM + http://siag.nu/webresolve/news-0.2.0.shtml + + Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname. + + + + + + + + + cpe:/a:symantec:norton_antivirus:2001 + + CVE-2002-2206 + 2002-09-11T00:00:00.000-04:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.650-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2006-05-01T11:45:00.000-04:00 + + + + BID + 5692 + + + XF + nav-poproxy-username-dos(10085) + + + BUGTRAQ + 20020919 http://online.securityfocus.com/archive/1/291358/2002-09-08/2002-09-14/0, Subj: Norton AintiVirus 2001 POPROXY DoS + + The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries. + + + + + + + + + + cpe:/a:eric_rescorla:ssldump:0.9b2 + cpe:/a:eric_rescorla:ssldump:0.9b1 + + CVE-2002-2207 + 2002-09-11T00:00:00.000-04:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-05-01T11:48:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5690 + + + CONFIRM + http://www.rtfm.com/ssldump/ + + + XF + ssldump-rsa-premastersecret-bo(10086) + + Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret. + + + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1 + cpe:/o:cisco:ios:12.2 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.3 + cpe:/a:extended_interior_gateway_routing_protocol:extended_interior_gateway_routing_protocol:1.2 + + CVE-2002-2208 + 2002-12-19T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:36.960-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2006-05-01T11:55:00.000-04:00 + + + + BUGTRAQ + 20021219 Re: Cisco IOS EIGRP Network DoS + + + CISCO + 20021220 Cisco's Response to the EIGRP Issue + + + XF + cisco-ios-eigrp-dos(10903) + + + BID + 6443 + + + BUGTRAQ + 20051220 Re: Unauthenticated EIGRP DoS + + + BUGTRAQ + 20021219 Cisco IOS EIGRP Network DoS + + + OSVDB + 18055 + + + CONFIRM + http://www.cisco.com/warp/public/707/eigrp_issue.pdf + + + SECTRACK + 1005840 + + + FULLDISC + 20051220 RE: Authenticated EIGRP DoS / Information leak + + + FULLDISC + 20051219 Unauthenticated EIGRP DoS + + Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network. + + + + + + + + + cpe:/a:pablo_software_solutions:baby_ftp_server + + CVE-2002-2209 + 2002-11-07T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:37.117-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-05-01T11:57:00.000-04:00 + + + + CONFIRM + http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html + + Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors. + + + + + + + + + cpe:/a:openoffice:openoffice:1.0.1 + + CVE-2002-2210 + 2002-10-11T00:00:00.000-04:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:37.257-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-05-01T12:00:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 5950 + + + XF + openofficeorg-tmpfile-symlink(10346) + + + BUGTRAQ + 20021011 OpenOffice 1.0.1 Race condition during installation. + + The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:isc:bind:8.2.2:p1 + cpe:/a:isc:bind:8.2.2:p2 + cpe:/a:isc:bind:8.2.2:p3 + cpe:/a:isc:bind:4.9.10 + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:8.2.2:p5 + cpe:/a:isc:bind:8.2.2:p4 + cpe:/a:isc:bind:8.2.2:p7 + cpe:/a:isc:bind:8.2.2:p6 + cpe:/a:isc:bind:4.9 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.4 + cpe:/a:isc:bind:8.2.5 + cpe:/a:isc:bind:8.2.6 + cpe:/a:isc:bind:8.2.7 + cpe:/a:isc:bind:4.9.9 + cpe:/a:isc:bind:8.3.4 + cpe:/a:isc:bind:8.3.3 + cpe:/a:isc:bind:4.9.4 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.2 + cpe:/a:isc:bind:4.9.8 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2.3 + cpe:/a:isc:bind:8.2.2 + + CVE-2002-2211 + 2002-11-21T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:34.453-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-05-26T11:27:00.000-04:00 + + + + CERT-VN + VU#457875 + + + MISC + http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.html + + + VUPEN + ADV-2006-1923 + + + HP + HPSBUX02117 + + + MISC + http://www.kb.cert.org/vuls/id/IAFY-5FZSLQ + + + MISC + http://www.kb.cert.org/vuls/id/IAFY-5FDT4U + + + MISC + http://www.kb.cert.org/vuls/id/IAFY-5FDPYP + + + MISC + http://www.imconf.net/imw-2002/imw2002-papers/198.pdf + + + APPLE + 2002-11-21 + + BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/h:fujitsu:uxp_v + cpe:/a:isc:bind:8.2.2:p1 + cpe:/a:isc:bind:8.2.2:p2 + cpe:/a:isc:bind:8.2.2:p3 + cpe:/a:isc:bind:4.9.10 + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:8.2.2:p5 + cpe:/a:isc:bind:8.2.2:p4 + cpe:/a:isc:bind:8.2.2:p7 + cpe:/a:isc:bind:8.2.2:p6 + cpe:/a:isc:bind:4.9 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.4 + cpe:/a:isc:bind:8.2.5 + cpe:/a:isc:bind:8.2.6 + cpe:/a:isc:bind:8.2.7 + cpe:/a:isc:bind:4.9.9 + cpe:/a:isc:bind:8.3.4 + cpe:/a:isc:bind:8.3.3 + cpe:/a:isc:bind:4.9.4 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.2 + cpe:/a:isc:bind:4.9.8 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2.3 + cpe:/a:isc:bind:8.2.2 + + CVE-2002-2212 + 2002-11-19T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:37.633-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-05-26T11:31:00.000-04:00 + + + + CERT-VN + VU#457875 + + + MISC + http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.html + + + CONFIRM + http://www.kb.cert.org/vuls/id/IAFY-5FDT5K + + + MISC + http://www.imconf.net/imw-2002/imw2002-papers/198.pdf + + The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:isc:bind:8.2.2:p1 + cpe:/a:isc:bind:8.2.2:p2 + cpe:/a:isc:bind:8.2.2:p3 + cpe:/a:isc:bind:4.9.10 + cpe:/a:isc:bind:4.9.5:p1 + cpe:/a:isc:bind:8.2.2:p5 + cpe:/a:isc:bind:8.2.2:p4 + cpe:/a:isc:bind:8.2.2:p7 + cpe:/a:isc:bind:8.2.2:p6 + cpe:/a:isc:bind:4.9 + cpe:/a:isc:bind:8.2 + cpe:/a:isc:bind:8.2.4 + cpe:/a:isc:bind:8.2.5 + cpe:/a:isc:bind:8.2.6 + cpe:/a:isc:bind:8.2.7 + cpe:/a:isc:bind:4.9.9 + cpe:/a:isc:bind:8.3.4 + cpe:/a:isc:bind:8.3.3 + cpe:/a:isc:bind:4.9.4 + cpe:/a:isc:bind:4.9.3 + cpe:/a:isc:bind:4.9.2 + cpe:/a:infoblox:dns_one + cpe:/a:isc:bind:4.9.8 + cpe:/a:isc:bind:4.9.7 + cpe:/a:isc:bind:4.9.6 + cpe:/a:isc:bind:4.9.5 + cpe:/a:isc:bind:8.3.0 + cpe:/a:isc:bind:8.3.1 + cpe:/a:isc:bind:8.3.2 + cpe:/a:isc:bind:8.2.1 + cpe:/a:isc:bind:8.2.3 + cpe:/a:isc:bind:8.2.2 + + CVE-2002-2213 + 2002-11-19T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:37.853-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2006-05-26T11:44:00.000-04:00 + + + + CERT-VN + VU#457875 + + + MISC + http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.html + + + CONFIRM + http://www.kb.cert.org/vuls/id/IAFY-5FDPYJ + + + MISC + http://www.imconf.net/imw-2002/imw2002-papers/198.pdf + + The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods. + + + + + + + + + + + cpe:/a:php:php:4.2::dev + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + + CVE-2002-2214 + 2002-02-18T00:00:00.000-05:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:38.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-06-15T12:46:00.000-04:00 + + + + CONFIRM + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040 + + + CONFIRM + http://bugs.php.net/bug.php?id=15595 + + + REDHAT + RHSA-2006:0567 + + The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0:beta_4_patch1 + cpe:/a:php:php:4.0.1:patch1 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:4.0.2 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:4.2.3 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:4.2.0 + cpe:/a:php:php:4.0.7:rc3 + cpe:/a:php:php:4.0:beta1 + cpe:/a:php:php:4.0:beta3 + cpe:/a:php:php:4.2::dev + cpe:/a:php:php:4.0:beta2 + cpe:/a:php:php:4.0.7:rc1 + cpe:/a:php:php:4.0.7:rc2 + cpe:/a:php:php:4.0:beta4 + cpe:/a:php:php:4.0 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.3:patch1 + cpe:/a:php:php:3.0 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.0.4:patch1 + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:3.0.16 + cpe:/a:php:php:3.0.17 + cpe:/a:php:php:3.0.14 + cpe:/a:php:php:3.0.15 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:4.0:rc2 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:4.0:rc1 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2002-2215 + 2002-09-07T00:00:00.000-04:00 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:38.227-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2006-06-15T12:55:00.000-04:00 + + + + CONFIRM + https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040 + + + CONFIRM + http://bugs.php.net/bug.php?id=19280 + + The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function. + + + + + + + + + cpe:/a:soft3304:04webserver:1.20 + + CVE-2002-2216 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:38.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2006-08-18T16:02:00.000-04:00 + + + + CONFIRM + http://www.soft3304.net/04WebServer/Security.html + + Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information. + + + + + + + + + cpe:/a:comscripts:web_server_creator:0.1 + + CVE-2002-2217 + 2002-12-31T00:00:00.000-05:00 + 2009-02-07T00:21:57.657-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-09-12T11:30:00.000-04:00 + + + ALLOWS_OTHER_ACCESS + + XF + webservercreator-customize-file-include(28815) + + + BID + 19896 + + + SECTRACK + 1005712 + + + XF + webservercreator-php-file-include(10689) + + + BID + 6251 + + + MILW0RM + 2318 + + + BUGTRAQ + 20021125 Web Server Creator - Web Portal 0.1 (PHP) + + Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php. + + + + + + + + + cpe:/a:sips:sips + + CVE-2002-2218 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:38.790-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-09-22T12:35:00.000-04:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://sips.cvs.sourceforge.net/sips/sips/sipssys/code/site.inc.php?view=log + + + CONFIRM + http://sips.cvs.sourceforge.net/sips/sips/sipssys/code/site.inc.php?r1=1.13&r2=1.14 + + CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gaining privileges or modifying critical configuration, via a CRLF sequence in a key value. + + + + + + + + + cpe:/a:chetcpasswd:chetcpasswd:2.1 + + CVE-2002-2219 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:38.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2006-12-21T16:20:00.000-05:00 + + + ALLOWS_USER_ACCESS + + BID + 6472 + + + CONFIRM + http://sourceforge.net/project/shownotes.php?group_id=68912&release_id=466649 + + + XF + chetcpasswd-shadow-file-disclosure(10946) + + + MISC + http://www.securiteam.com/unixfocus/6C00N0K6AO.html + + + SECTRACK + 1005847 + + chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field. + + + + + + + + + cpe:/a:chetcpasswd:chetcpasswd:1.12 + + CVE-2002-2220 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.087-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-12-21T16:21:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + CONFIRM + http://sourceforge.net/project/shownotes.php?group_id=68912&release_id=466649 + + Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors. + + + + + + + + + + + cpe:/a:chetcpasswd:chetcpasswd:2.4.1 + cpe:/a:chetcpasswd:chetcpasswd:2.3.3 + cpe:/a:chetcpasswd:chetcpasswd:2.3.1 + + CVE-2002-2221 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.243-04:00 + + + 6.2 + LOCAL + HIGH + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2006-12-21T16:22:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 21644 + + + SECTRACK + 1005847 + + Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639. + + + + + + + + + + cpe:/o:openbsd:openbsd:3.1 + cpe:/o:freebsd:ports_collection:2002-08-28 + + CVE-2002-2222 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.383-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-02-28T12:06:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#287771 + + + OPENBSD + [3.1] 010: RELIABILITY FIX: July 5, 2002 + + + XF + ike-response-bo(9850) + + + FREEBSD + FreeBSD-SN-02:05 + + isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out of sequence. + + + + + + + + + + cpe:/a:juniper:netscreen_remote_security_client:8.0 + cpe:/a:juniper:netscreen_remote_vpn_client:8.0 + + CVE-2002-2223 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.540-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-02-28T12:22:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#287771 + + + XF + ike-response-bo(9850) + + + BID + 5668 + + + MISC + http://www.netscreen.com/support/alerts/9_6_02.htm + + Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload. + + + + + + + + + cpe:/a:network_associates:pgp_freeware:7.03 + + CVE-2002-2224 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.697-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-02-28T12:27:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#287771 + + + XF + ike-response-bo(9850) + + + BID + 5449 + + + MISC + http://www.kb.cert.org/vuls/id/AAMN-5A5RXM + + Buffer overflow in PGPFreeware 7.03 running on Windows NT 4.0 SP6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload. + + + + + + + + + cpe:/a:safenet:softremote_vpn_client + + CVE-2002-2225 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:39.837-04:00 + + + 5.1 + NETWORK + HIGH + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-02-28T12:57:00.000-05:00 + + + ALLOWS_OTHER_ACCESS + + CERT-VN + VU#287771 + + + MISC + http://www.safenet-inc.com/knowledgebase/read_item.asp?ID=375 + + + MISC + http://www.kb.cert.org/vuls/id/AAMN-59VTUQ + + SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflows using (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload. + + + + + + + + + cpe:/a:tftpd32:tftpd32:2.21 + + CVE-2002-2226 + 2002-12-31T00:00:00.000-05:00 + 2009-11-24T00:15:20.813-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-10-02T10:57:00.000-04:00 + + + ALLOWS_USER_ACCESS + + + CERT-VN + VU#632633 + + + XF + tftp32-filename-bo(10647) + + + BID + 6199 + + + BUGTRAQ + 20021118 TFTPD32 Buffer Overflow Vulnerability (Long filename) + + + MISC + http://www.securiteam.com/windowsntfocus/6C00C2061A.html + + + MISC + http://tftpd32.jounin.net/ + + + SREASON + 3160 + + Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. + + + + + + + + + cpe:/a:rtfm:ssldump:0.9b2 + + CVE-2002-2227 + 2002-12-31T00:00:00.000-05:00 + 2010-06-24T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-10-02T11:10:00.000-04:00 + + + + + CONFIRM + http://www.rtfm.com/ssldump/ + + + XF + ssldump-sslv2-memory-corruption(10087) + + + BID + 5693 + + + BUGTRAQ + 20020911 Buffer over/underflows in ssldump prior to 0.9b3 + + Buffer underflow in ssldump 0.9b2 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted SSLv2 challenge value. + + + + + + + + + + cpe:/a:mailscanner:mailscanner:3.2_6-1 + cpe:/a:mailscanner:mailscanner:4.0_4-1 + + CVE-2002-2228 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:40.290-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-18T14:46:00.000-05:00 + + + + + XF + mailscanner-filename-protection-bypass(10609) + + + BID + 6148 + + MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner. + + + + + + + + + cpe:/a:sapio_design_ltd:webreflex:1.53 + + CVE-2002-2229 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:40.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-18T14:54:00.000-05:00 + + + + + BID + 6327 + + + XF + webreflex-dotdot-directory-traversal(10782) + + + BUGTRAQ + 20021206 WebReflex Directory Traversal Vulnerability + + Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request. + + + + + + + + + cpe:/a:ikonboard:ikonboard:3.1.1 + + CVE-2002-2230 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T00:00:00.000-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-10-17T11:27:00.000-04:00 + + + + + XF + ikonboard-html-image-xss(10268) + + + BUGTRAQ + 20021004 SECURITY.NNOV: ikonboard 3.1.1 CSS + + Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328. + + + + + + + + + cpe:/a:ikonboard:ikonboard:3.1.1 + + CVE-2002-2231 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:40.743-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-18T14:57:00.000-05:00 + + + + + XF + ikonboard-xforwardedfor-header-xss(10799) + + + BID + 6343 + + + BID + 6342 + + + XF + ikonboard-html-photo-xss(10797) + + + BUGTRAQ + 20021209 SECURITY.NNOV: more Ikonboard 3.1.1 crossite scriptings + + Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header. + + + + + + + + + cpe:/a:mollensoft_software:enceladus_server_suite:3.9 + + CVE-2002-2232 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:40.900-04:00 + + + 8.5 + NETWORK + MEDIUM + SINGLE_INSTANCE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-18T15:06:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6345 + + + BUGTRAQ + 20021219 Multiple vulnerability in Enceladus Server + + + XF + enceladus-cd-bo(10802) + + + VULNWATCH + 20021209 [SecurityOffice] Enceladus Server Suite v3.9 Buffer Overflow Vulnerability + + + BUGTRAQ + 20021209 [SecurityOffice] Enceladus Server Suite v3.9 Buffer Overflow Vulnerability + + Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command. + + + + + + + + + cpe:/a:mollensoft_software:enceladus_server_suite:3.9 + + CVE-2002-2233 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.040-04:00 + + + 8.3 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + COMPLETE + http://nvd.nist.gov + 2007-12-18T15:10:00.000-05:00 + + + + + XF + enceladus-cd-dos(11020) + + + XF + enceladus-cd-directory-traversal(11019) + + + BUGTRAQ + 20021219 Multiple vulnerability in Enceladus Server + + Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..". + + + + + + + + + + + + + cpe:/a:netscreen:screenos:2.7.1 + cpe:/a:netscreen:screenos:4.0 + cpe:/a:netscreen:screenos:2.8 + cpe:/a:netscreen:screenos:3.0 + cpe:/a:netscreen:screenos:3.1 + + CVE-2002-2234 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.180-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-18T15:23:00.000-05:00 + + + + + BID + 6245 + + + XF + netscreen-fragmented-url-bypass(10699) + + + BUGTRAQ + 20021125 'Malicious-URL' Feature may be Circumvented Using IP Fragmentation + + + BUGTRAQ + 20021125 Netscreen Malicious URL feature can be bypassed by fragmenting the request + + + VULNWATCH + 20021125 'Malicious-URL' Feature may be Circumvented Using IP Fragmentation + + + VULNWATCH + 20021125 Netscreen Malicious URL feature can be bypassed by fragmenting the request + + NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:jelsoft:vbulletin:2.2.2 + cpe:/a:jelsoft:vbulletin:2.2.9_can + cpe:/a:jelsoft:vbulletin:2.2.3 + cpe:/a:jelsoft:vbulletin:2.2.0 + cpe:/a:jelsoft:vbulletin:2.2.1 + cpe:/a:jelsoft:vbulletin:2.2.6 + cpe:/a:jelsoft:vbulletin:2.2.7 + cpe:/a:jelsoft:vbulletin:2.2.4 + cpe:/a:jelsoft:vbulletin:2.2.5 + cpe:/a:jelsoft:vbulletin:2.2.9 + cpe:/a:jelsoft:vbulletin:2.2.8 + cpe:/a:jelsoft:vbulletin:2.0.2 + cpe:/a:jelsoft:vbulletin:2.0.1 + cpe:/a:jelsoft:vbulletin:2.0 + + CVE-2002-2235 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-19T10:58:00.000-05:00 + + + + + BID + 6246 + + + XF + vbulletin-member2-perpage-xss(10701) + + + SREASON + 3229 + + + BUGTRAQ + 20021123 vBulletin XSS Injection Vulnerability + + member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks. + + + + + + + + + cpe:/a:apt-www-proxy:apt-www-proxy:1.0 + + CVE-2002-2236 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.523-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T11:11:00.000-05:00 + + + + + BID + 6340 + + + XF + apt-www-proxy-format-string(10815) + + + BUGTRAQ + 20021210 Remote multiple vulnerability in apt-www-proxy. + + Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code. + + + + + + + + + cpe:/a:tftp:tftp_server:2.21 + + CVE-2002-2237 + 2002-12-31T00:00:00.000-05:00 + 2009-11-24T00:15:21.920-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T11:10:00.000-05:00 + + + + + CERT-VN + VU#632633 + + + XF + tftp32-dos-device-dos(10817) + + + BUGTRAQ + 20021210 TFTP32 DOS + + tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux. + + + + + + + + + cpe:/a:kunani:kunani_odbc_ftp_server:1.0.10 + + CVE-2002-2238 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.807-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T11:14:00.000-05:00 + + + + + XF + kunani-dotdot-directory-traversal(10819) + + + BID + 6355 + + + BUGTRAQ + 20021210 KunaniFTP-Server v.1.0.10 allows dictionary traversal + + Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request. + + + + + + + + + + + + + + + cpe:/o:cisco:ios:12.1e + + CVE-2002-2239 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:41.960-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-19T11:20:00.000-05:00 + + + + + CISCO + 20021211 OSM Line Card Header Corruption Vulnerability + + + XF + cisco-catalyst-osm-dos(10823) + + + BID + 6358 + + The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet. + + + + + + + + + + cpe:/a:myserver:myserver:0.2 + cpe:/a:myserver:myserver:0.11 + + CVE-2002-2240 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.103-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-19T11:53:00.000-05:00 + + + + + BID + 6359 + + + XF + myserver-dotdot-directory-traversal(10827) + + + BUGTRAQ + 20021211 Directory traversing bug in 'myServer' webserver. + + Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request. + + + + + + + + + cpe:/a:deerfield:visnetic_website:3.5.13 + + CVE-2002-2241 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.257-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T11:44:00.000-05:00 + + + + + BID + 6364 + + + XF + visnetic-website-url-dos(10840) + + + BUGTRAQ + 20021211 Denial of Service vulnerability in VisNetic Website + + Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request. + + + + + + + + + cpe:/a:kismac:kismac:0.2a + + CVE-2002-2242 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.400-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T11:47:00.000-05:00 + + + + + BID + 6336 + + + XF + kismac-installer-overwrite-permissions(10813) + + + SECTRACK + 1005764 + + The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to conduct unauthorized activities on those files. + + + + + + + + + cpe:/a:akfingerd:akfingerd:0.5 + + CVE-2002-2243 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.557-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T11:50:00.000-05:00 + + + + XF + akfingerd-connect-dos(10794) + + + BID + 6323 + + + BUGTRAQ + 20021205 Multiple vulnerabilities in akfingerd + + Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it. + + + + + + + + + cpe:/a:akfingerd:akfingerd:0.5 + + CVE-2002-2244 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.697-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T12:03:00.000-05:00 + + + + + XF + akfingerd-plan-symlink-dos(10795) + + + BID + 6324 + + + BUGTRAQ + 20021205 Multiple vulnerabilities in akfingerd + + Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle. + + + + + + + + + + + + + cpe:/a:netbsd:ftpd:1.5 + cpe:/a:netbsd:ftpd:1.6 + cpe:/a:netbsd:ftpd:1.5.1 + cpe:/a:netbsd:ftpd:1.5.2 + cpe:/a:netbsd:ftpd:1.5.3 + + CVE-2002-2245 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.837-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T13:05:00.000-05:00 + + + + + NETBSD + NetBSD-SA2002-027 + + ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session. + + + + + + + + + cpe:/a:deerfield:visnetic_website:3.5.13 + + CVE-2002-2246 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:42.993-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T13:20:00.000-05:00 + + + + + BID + 6369 + + + XF + visnetic-website-referer-xss(10852) + + + CONFIRM + http://www.deerfield.com/products/visnetic_website/ + + + BUGTRAQ + 20021212 VisNetic WebSite XSS vulnerability through HTTP referer header + + Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page. + + + + + + + + + cpe:/a:mambo:mambo_site_server:4.0.11 + + CVE-2002-2247 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.133-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-19T13:25:00.000-05:00 + + + + + BID + 6376 + + + XF + mambo-phpinfo-disclose-path(10853) + + + BUGTRAQ + 20021212 Multiple Mambo Site Server sec-weaknesses + + The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.78 + cpe:/a:netscape:communicator:4.77 + cpe:/a:netscape:communicator:4.79 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.75 + cpe:/a:netscape:communicator:4.76 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.72 + + CVE-2002-2248 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.290-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T13:22:00.000-05:00 + + + + + XF + netscape-applet-canconvert-bo(10706) + + + BID + 6256 + + + BUGTRAQ + 20021126 Netscape 4 Java buffer overflow + + Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method. + + + + + + + + + + cpe:/a:php_evolution:news_evolution:2.0 + cpe:/a:php_evolution:news_evolution:1.0 + + CVE-2002-2249 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.460-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-19T13:33:00.000-05:00 + + + + + BUGTRAQ + 20021126 FreeNews & News Evolution (PHP) + + + XF + newsevolution-php-file-include(10709) + + + BID + 6260 + + PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php. + + + + + + + + + + cpe:/a:sybase:adaptive_server:12.5 + cpe:/a:sybase:adaptive_server:12.0 + + CVE-2002-2250 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.650-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T13:44:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BUGTRAQ + 20021127 ASI Sybase Security Alert: Buffer overflow in DBCC CHECKVERIFY + + + XF + sybase-dbcc-checkverify-bo(10721) + + + BID + 6269 + + + BID + 6266 + + + XF + sybase-xpfreedll-dll-bo(10719) + + + MISC + http://www.appsecinc.com/resources/alerts/sybase/02-0003.html + + + MISC + http://www.appsecinc.com/resources/alerts/sybase/02-0001.html + + + BUGTRAQ + 20021127 ASI Sybase Security Alert: Buffer overflow in xp_freedll + + + NTBUGTRAQ + 20021127 ASI Sybase Security Alert: Buffer overflow in DBCC CHECKVERIFY + + + NTBUGTRAQ + 20021127 ASI Sybase Security Alert: Buffer overflow in xp_freedll + + Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function. + + + + + + + + + cpe:/a:marcos_luiz_onisto:lib_cgi:0.1 + + CVE-2002-2251 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.807-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T13:40:00.000-05:00 + + + + + XF + libcgi-libcgih-changevalue-bo(10715) + + + BID + 6264 + + + BUGTRAQ + 20021127 Remote Frame Pointer Overwrite vulnerability in LIB CGI in Language C. + + Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument. + + + + + + + + + cpe:/a:atthat.com:thatware:0.5 + + CVE-2002-2252 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:43.947-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-19T13:43:00.000-05:00 + + + + + XF + thatware-authinc-sql-injection(10759) + + + SECTRACK + 1005733 + + + BUGTRAQ + 20021201 Thatware (PHP) + + SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter. + + + + + + + + + cpe:/a:cyrus:libsieve:2.1.2 + + CVE-2002-2253 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.087-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T13:50:00.000-05:00 + + + + + XF + cyrus-sieve-script-bo(10780) + + + XF + cyrus-sieve-imap-bo(10779) + + + XF + cyrus-sieve-header-bo(10743) + + + BID + 6300 + + + BID + 6299 + + + BID + 6294 + + + BUGTRAQ + 20021202 Cyrus Sieve / libSieve buffer overflow + + Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a script that generates a large number of errors that overflow the resulting error string. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:linux:linux_kernel:2.4.0:test11 + cpe:/o:linux:linux_kernel:2.4.0:test12 + cpe:/o:linux:linux_kernel:2.4.0:test10 + cpe:/o:linux:linux_kernel:2.5.2 + cpe:/o:linux:linux_kernel:2.4.0:test4 + cpe:/o:linux:linux_kernel:2.4.0:test5 + cpe:/o:linux:linux_kernel:2.5.1 + cpe:/o:linux:linux_kernel:2.4.0:test6 + cpe:/o:linux:linux_kernel:2.5.0 + cpe:/o:linux:linux_kernel:2.4.0:test7 + cpe:/o:linux:linux_kernel:2.4.0 + cpe:/o:linux:linux_kernel:2.4.0:test2 + cpe:/o:linux:linux_kernel:2.4.1 + cpe:/o:linux:linux_kernel:2.4.0:test3 + cpe:/o:linux:linux_kernel:2.5.10 + cpe:/o:linux:linux_kernel:2.5.11 + cpe:/o:linux:linux_kernel:2.5.14 + cpe:/o:linux:linux_kernel:2.5.15 + cpe:/o:linux:linux_kernel:2.5.12 + cpe:/o:linux:linux_kernel:2.5.13 + cpe:/o:linux:linux_kernel:2.5.18 + cpe:/o:linux:linux_kernel:2.5.19 + cpe:/o:linux:linux_kernel:2.5.16 + cpe:/o:linux:linux_kernel:2.5.17 + cpe:/o:linux:linux_kernel:2.4.11:pre3 + cpe:/o:linux:linux_kernel:2.4.18:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre6 + cpe:/o:linux:linux_kernel:2.4.19:pre3 + cpe:/o:linux:linux_kernel:2.4.18:pre3 + cpe:/o:linux:linux_kernel:2.4.19:pre4 + cpe:/o:linux:linux_kernel:2.4.18:pre9 + cpe:/o:linux:linux_kernel:2.5.3 + cpe:/o:linux:linux_kernel:2.5.20 + cpe:/o:linux:linux_kernel:2.5.21 + cpe:/o:linux:linux_kernel:2.5.22 + cpe:/o:linux:linux_kernel:2.4.18:pre5 + cpe:/o:linux:linux_kernel:2.4.19:pre6 + cpe:/o:linux:linux_kernel:2.4.18:pre8 + cpe:/o:linux:linux_kernel:2.4.19:pre5 + cpe:/o:linux:linux_kernel:2.4.18:pre7 + cpe:/o:linux:linux_kernel:2.5.27 + cpe:/o:linux:linux_kernel:2.5.28 + cpe:/o:linux:linux_kernel:2.5.29 + cpe:/o:linux:linux_kernel:2.4.0:test9 + cpe:/o:linux:linux_kernel:2.4.0:test8 + cpe:/o:linux:linux_kernel:2.5.23 + cpe:/o:linux:linux_kernel:2.5.24 + cpe:/o:linux:linux_kernel:2.5.25 + cpe:/o:linux:linux_kernel:2.5.26 + cpe:/o:linux:linux_kernel:2.4.19 + cpe:/o:linux:linux_kernel:2.4.15 + cpe:/o:linux:linux_kernel:2.4.16 + cpe:/o:linux:linux_kernel:2.4.17 + cpe:/o:linux:linux_kernel:2.4.18 + cpe:/o:linux:linux_kernel:2.4.11 + cpe:/o:linux:linux_kernel:2.4.12 + cpe:/o:linux:linux_kernel:2.4.13 + cpe:/o:linux:linux_kernel:2.4.14 + cpe:/o:linux:linux_kernel:2.4.10 + cpe:/o:linux:linux_kernel:2.4.0:test1 + cpe:/o:linux:linux_kernel:2.5.30 + cpe:/o:linux:linux_kernel:2.5.31 + cpe:/o:linux:linux_kernel:2.4.18:pre1 + cpe:/o:linux:linux_kernel:2.4.19:pre2 + cpe:/o:linux:linux_kernel:2.4.19:pre1 + cpe:/o:linux:linux_kernel:2.4.18:pre2 + + CVE-2002-2254 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.243-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T13:56:00.000-05:00 + + + + + BID + 6305 + + + XF + linux-netfilter-obtain-information(10756) + + + BUGTRAQ + 20021203 Local Netfilter / IPTables IP Queue PID Wrap Flaw + + The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network traffic that would otherwise be restricted. + + + + + + + + + cpe:/a:phpbb:phpbb:2.0.3 + + CVE-2002-2255 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.523-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T14:03:00.000-05:00 + + + + + XF + phpbb-search-username-xss(10773) + + + BID + 6311 + + + BUGTRAQ + 20021203 Cross-site Scripting Vulnerability in phpBB 2.0.3 + + Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode. + + + + + + + + + cpe:/a:pwins:pwins:0.2.5 + + CVE-2002-2256 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T14:07:00.000-05:00 + + + + + XF + pwins-dotdot-directory-traversal(10724) + + + BID + 6271 + + + BUGTRAQ + 20021127 pWins Perl Web Server Directory Transversal Vulnerability + + Directory traversal vulnerability in pWins Webserver 0.2.5 and earlier allows remote attackers to read arbitrary files via Unicode characters. + + + + + + + + + + cpe:/a:tuxbr:libcgi:1.0.3 + cpe:/a:tuxbr:libcgi:1.0.2 + + CVE-2002-2257 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.820-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T14:11:00.000-05:00 + + + + + XF + libcgi-cgilibc-parsefield-bo(10722) + + + BID + 6270 + + + BUGTRAQ + 20021128 Remote Multiple Buffer Overflow(s) vulnerability in Libcgi-tuxbr. + + Stack-based buffer overflow in the parse_field function in cgi_lib.c for LIBCGI 1.0.2 and 1.0.3 allows remote attackers to execute arbitrary code via a long argument. + + + + + + + + + cpe:/a:mobydisk:netsuite + + CVE-2002-2258 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:44.960-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T14:13:00.000-05:00 + + + + + XF + netsuite-post-contentlength-bo(10725) + + + BID + 6277 + + + BUGTRAQ + 20021128 Moby NetSuite POST Denial of Service Vulnerability + + Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value in the Content-Length header, which causes an access violation after a failed atoi function call. + + + + + + + + + + + + + + cpe:/a:gnuplot:gnuplot:3.7 + + CVE-2002-2259 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:45.117-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T14:28:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + gnuplot-french-documentation-bo(10801) + + + SUSE + SuSE-SA:2002:047 + + + BID + 6329 + + Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:bugzilla:2.17.6 + cpe:/a:mozilla:bugzilla:2.17.7 + cpe:/a:mozilla:bugzilla:2.16:rc1 + cpe:/a:mozilla:bugzilla:2.16.3 + cpe:/a:mozilla:bugzilla:2.16.4 + cpe:/a:mozilla:bugzilla:2.16.5 + cpe:/a:mozilla:bugzilla:2.16.6 + cpe:/a:mozilla:bugzilla:2.16.1 + cpe:/a:mozilla:bugzilla:2.16.2 + cpe:/a:mozilla:bugzilla:2.14.3 + cpe:/a:mozilla:bugzilla:2.14.4 + cpe:/a:mozilla:bugzilla:2.14.1 + cpe:/a:mozilla:bugzilla:2.14.2 + cpe:/a:mozilla:bugzilla:2.17 + cpe:/a:mozilla:bugzilla:2.16.9 + cpe:/a:mozilla:bugzilla:2.14.5 + cpe:/a:mozilla:bugzilla:2.16.8 + cpe:/a:mozilla:bugzilla:2.16.7 + cpe:/a:mozilla:bugzilla:2.12 + cpe:/a:mozilla:bugzilla:2.16.11 + cpe:/a:mozilla:bugzilla:2.10 + cpe:/a:mozilla:bugzilla:2.16.10 + cpe:/a:mozilla:bugzilla:2.16 + cpe:/a:mozilla:bugzilla:2.14 + cpe:/a:mozilla:bugzilla:2.17.1 + cpe:/a:mozilla:bugzilla:2.17.5 + cpe:/a:mozilla:bugzilla:2.17.4 + cpe:/a:mozilla:bugzilla:2.17.3 + + CVE-2002-2260 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:45.257-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T14:37:00.000-05:00 + + + + + XF + bugzilla-quips-xss(10707) + + + BID + 6257 + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=179329 + + + DEBIAN + DSA-218 + + + BUGTRAQ + 20021126 XSS vulnerability in Bugzilla if upgraded from 2.10 or earlier + + Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.9.0 + cpe:/a:sendmail:sendmail:8.9.1 + cpe:/a:sendmail:sendmail:8.9.2 + cpe:/a:sendmail:sendmail:8.12:beta7 + cpe:/a:sendmail:sendmail:8.9.3 + cpe:/a:sendmail:sendmail:8.12:beta5 + cpe:/a:sendmail:sendmail:8.11.6 + cpe:/a:sendmail:sendmail:8.11.7 + cpe:/a:sendmail:sendmail:8.11.2 + cpe:/a:sendmail:sendmail:8.11.3 + cpe:/a:sendmail:sendmail:8.11.4 + cpe:/a:sendmail:sendmail:8.11.5 + cpe:/a:sendmail:sendmail:8.11.0 + cpe:/a:sendmail:sendmail:8.11.1 + cpe:/a:sendmail:sendmail:8.12:beta10 + cpe:/a:sendmail:sendmail:8.12.5 + cpe:/a:sendmail:sendmail:8.12.6 + cpe:/a:sendmail:sendmail:8.10 + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.12.2 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/a:sendmail:sendmail:8.12.4 + cpe:/a:sendmail:sendmail:8.12:beta12 + cpe:/a:sendmail:sendmail:8.12.0 + cpe:/a:sendmail:sendmail:8.10.0 + cpe:/a:sendmail:sendmail:8.12:beta16 + cpe:/a:sendmail:sendmail:8.10.2 + cpe:/a:sendmail:sendmail:8.10.1 + + CVE-2002-2261 + 2002-12-31T00:00:00.000-05:00 + 2011-07-18T21:13:49.187-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-19T14:46:00.000-05:00 + + + + + + + XF + sendmail-check-relay-bypass(10775) + + + CONFIRM + http://www.sendmail.org/8.12.7.html + + + BID + 6548 + + + SECTRACK + 1005748 + + + VUPEN + ADV-2009-3539 + + + SGI + 20030101-01-P + + + + + + + + Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname. + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.11 + cpe:/o:hp:hp-ux:10 + cpe:/o:hp:hp-ux:11 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.24 + cpe:/o:hp:hp-ux:10.34 + cpe:/o:hp:hp-ux:10.30 + cpe:/o:hp:hp-ux:11.11i + cpe:/o:hp:hp-ux:10.26 + cpe:/o:hp:hp-ux:11.04 + cpe:/o:hp:hp-ux:11.0.4 + cpe:/o:hp:hp-ux:10.03 + cpe:/o:hp:hp-ux:10.09 + cpe:/o:hp:hp-ux:10.08 + + CVE-2002-2262 + 2002-12-31T00:00:00.000-05:00 + 2009-03-04T00:16:26.063-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T14:52:00.000-05:00 + + + + + BID + 6356 + + + XF + hp-xnptd-dos(10836) + + + HP + HPSBUX0212-232 + + + + + Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors. + + + + + + + + + + + + + + + cpe:/a:hp:visualize_conference_ftp:b.11.00.11 + + CVE-2002-2263 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:45.867-04:00 + + + 6.6 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-19T14:57:00.000-05:00 + + + + + XF + hp-vizualizeconf-insecure-permissions(10838) + + + BID + 6357 + + + HP + HPSBUX0212-232 + + The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files. + + + + + + + + + + + + + + cpe:/a:hp:secure_web_server_for_tru64:5.1:apk3 + cpe:/a:hp:secure_web_server_for_tru64:5.1:pk5 + cpe:/a:hp:secure_web_server_for_tru64:5.0:a_pk3 + cpe:/a:hp:secure_web_server_for_tru64:5.1:pk6 + cpe:/a:hp:secure_web_server_for_tru64:4.0:f + cpe:/a:hp:secure_web_server_for_tru64:4.0:g + + CVE-2002-2264 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.023-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T15:03:00.000-05:00 + + + + HP + SSRT2266 + + Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain. + + + + + + + + + + + + + + + cpe:/a:open_source_internet_solutions:open_source_internet_solutions:5.4 + + CVE-2002-2265 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.180-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-19T15:09:00.000-05:00 + + + + + BID + 6174 + + + XF + tru64-osis-ldap-file-access(10703) + + + HP + SSRT2385 + + Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors. + + + + + + + + + + + + cpe:/a:netscreen:screenos:4.0 + cpe:/a:netscreen:screenos:2.8 + cpe:/a:netscreen:screenos:3.0 + cpe:/a:netscreen:screenos:3.1 + + CVE-2002-2266 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-19T15:15:00.000-05:00 + + + + BID + 6250 + + + XF + netscreen-h323-dos(10700) + + + BUGTRAQ + 20021125 Potential H.323 Denial of Service + + NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not time out for 36 hours. + + + + + + + + + cpe:/a:bogofilter:bogopass_email_filter:0.9.0.4 + + CVE-2002-2267 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.477-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-19T15:19:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + BID + 6278 + + + XF + bogofilter-bogopass-symlink(10726) + + + BUGTRAQ + 20021129 bogofilter contrib/bogopass temp file vulnerability + + bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. + + + + + + + + + cpe:/a:netdave:webster_http_server + + CVE-2002-2268 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.633-04:00 + + + 9.4 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-19T15:40:00.000-05:00 + + + + + XF + webster-url-bo(10727) + + + BID + 6289 + + + MISC + http://www.securiteam.com/windowsntfocus/6R0030A6AY.html + + + BUGTRAQ + 20021201 Advisory: Webster HTTP Server + + Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. + + + + + + + + + cpe:/a:webster:webster_http_server + + CVE-2002-2269 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:46.773-04:00 + + + 9.4 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-20T14:47:00.000-05:00 + + + + + XF + webster-dotdot-directory-traversal(10728) + + + BID + 6291 + + + BUGTRAQ + 20021201 Advisory: Webster HTTP Server + + + SREASON + 3262 + + Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. + + + + + + + + + + + cpe:/o:hp:hp-ux:10.20 + cpe:/o:hp:hp-ux:11.00 + cpe:/o:hp:hp-ux:10.10 + + CVE-2002-2270 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:39.250-05:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-20T14:51:00.000-05:00 + + + + + + BID + 6317 + + + XF + hp-ied-information-disclosure(10777) + + + HP + SSRT2421 + + + + + Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors. + + + + + + + + + cpe:/a:bigfun:bigfun:1.5.1 + + CVE-2002-2271 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.070-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-20T14:57:00.000-05:00 + + + + + XF + bigfun-irc-dcc-dos(10757) + + + MISC + http://www.securiteam.com/exploits/6G003156AE.html + + Buffer overflow in BigFun 1.51b IRC client, when the Direct Client Connection (DCC) option is used, allows remote attackers to cause a denial of service (crash) via a long string. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:apache:http_server:1.3.10 + cpe:/a:apache:tomcat:4.1.3:beta + cpe:/a:apache:http_server:1.3.17 + cpe:/a:apache:http_server:1.3.18 + cpe:/a:apache:http_server:1.3.15 + cpe:/a:apache:http_server:1.3.16 + cpe:/a:apache:http_server:1.3.13 + cpe:/a:apache:http_server:1.3.2 + cpe:/a:apache:http_server:1.3.14 + cpe:/a:apache:http_server:1.3.11 + cpe:/a:apache:http_server:1.3.0 + cpe:/a:apache:http_server:1.3.12 + cpe:/a:apache:http_server:1.3.1 + cpe:/a:apache:tomcat:4.0.6 + cpe:/a:apache:http_server:1.3 + cpe:/a:apache:tomcat:4.1.3 + cpe:/a:apache:tomcat:4.1.9:beta + cpe:/a:apache:tomcat:4.1.1 + cpe:/a:apache:tomcat:4.1.2 + cpe:/a:apache:tomcat:4.1.0 + cpe:/a:apache:http_server:1.3.23 + cpe:/a:apache:http_server:1.3.22 + cpe:/a:apache:http_server:1.3.25 + cpe:/a:apache:http_server:1.3.24 + cpe:/a:apache:http_server:1.3.27 + cpe:/a:apache:http_server:1.3.26 + cpe:/a:apache:tomcat:4.0.0 + cpe:/a:apache:tomcat:4.0.1 + cpe:/a:apache:tomcat:4.0.2 + cpe:/a:apache:tomcat:4.0.3 + cpe:/a:apache:tomcat:4.0.4 + cpe:/a:apache:tomcat:4.0.5 + cpe:/a:apache:http_server:1.3.20 + cpe:/a:apache:tomcat:4.1.12 + cpe:/a:apache:tomcat:4.1.10 + cpe:/a:apache:http_server:1.3.19 + + CVE-2002-2272 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.227-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-20T15:00:00.000-05:00 + + + + + BID + 6320 + + + BUGTRAQ + 20021204 Apache/Tomcat Denial Of Service And Information Leakage Vulnerability + + + XF + tomcat-modjk-get-bo(10771) + + Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values. + + + + + + + + + cpe:/a:webster:webster_http_server + + CVE-2002-2273 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.447-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-20T15:05:00.000-05:00 + + + + + XF + webster-path-name-xss(10729) + + + BID + 6292 + + + BUGTRAQ + 20021201 Advisory: Webster HTTP Server + + + SREASON + 3262 + + Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL. + + + + + + + + + cpe:/a:akfingerd:akfingerd:0.5 + + CVE-2002-2274 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.600-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-20T15:07:00.000-05:00 + + + + XF + akfingerd-read-files(10796) + + + BID + 6325 + + + BUGTRAQ + 20021205 Multiple vulnerabilities in akfingerd + + akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file. + + + + + + + + + cpe:/a:fortres_grand_corporation:fortres:4.1 + + CVE-2002-2275 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.743-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-20T15:10:00.000-05:00 + + + + XF + fortres-101-bypass-restrictions(10807) + + + SECTRACK + 1005766 + + + NTBUGTRAQ + 20021204 How to disable Fortres 4.1 + + Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe. + + + + + + + + + cpe:/a:ultimate_php_board:ultimate_php_board:1.0 + + CVE-2002-2276 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:47.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-20T15:11:00.000-05:00 + + + + + XF + upb-add-path-disclosure(10788) + + + BID + 6333 + + + BUGTRAQ + 20021207 XSS and Path Disclosure in UPB + + Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message. + + + + + + + + + cpe:/a:portail_web_php:portail_web_php:0.99 + + CVE-2002-2277 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.040-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-20T15:13:00.000-05:00 + + + + + BUGTRAQ + 20021128 Security Patch for PortailPHP 0.99 + + + XF + portailphp-modsearch-sql-injection(10735) + + + BID + 6273 + + SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables. + + + + + + + + + cpe:/a:portail_web_php:portail_web_php:0.99 + + CVE-2002-2278 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.180-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-20T15:15:00.000-05:00 + + + + + BUGTRAQ + 20021128 Security Patch for PortailPHP 0.99 + + + XF + portailphp-modsearch-index-xss(10738) + + Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables. + + + + + + + + + cpe:/a:aldap:aldap:0.09 + + CVE-2002-2279 + 2002-12-31T00:00:00.000-05:00 + 2009-08-03T00:00:00.000-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-20T15:19:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6310 + + + XF + aldap-bind-manager-access(10733) + + + CONFIRM + http://alcastle.com/index.php?id=6&subject=%2Faldap%2F&view=CHANGE.LOG.txt + + Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions. + + + + + + + + + + + + cpe:/a:openbsd:openbsd:3.0 + cpe:/a:openbsd:openbsd:3.2 + cpe:/a:openbsd:openbsd:2.9 + cpe:/a:openbsd:openbsd:3.1 + + CVE-2002-2280 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.477-04:00 + + + 2.1 + LOCAL + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-20T15:18:00.000-05:00 + + + + + XF + openbsd-syslogd-incorrect-reporting(10702) + + + BID + 6219 + + + BUGTRAQ + 20021120 [OpenBSD] [syslogd] false src-IP when logging to remote syslogd + + syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:symantec:java:4.6 + cpe:/a:symantec:java:4.7 + cpe:/a:symantec:java:4.4 + cpe:/a:symantec:java:4.5 + cpe:/a:symantec:java:4.78 + cpe:/a:symantec:java:4.77 + cpe:/a:symantec:java:4.76 + cpe:/a:symantec:java:4.75 + cpe:/a:symantec:java:4.79 + cpe:/a:symantec:java:4.51 + cpe:/a:symantec:java:4.73 + cpe:/a:symantec:java:4.74 + cpe:/a:symantec:java:4.61 + cpe:/a:symantec:java:4.72 + cpe:/a:symantec:java:4.0 + cpe:/a:symantec:java:4.08 + cpe:/a:symantec:java:4.06 + cpe:/a:symantec:java:4.07 + + CVE-2002-2281 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.633-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-26T08:48:00.000-05:00 + + + + XF + symantec-jit-bypass-security(10711) + + + BID + 6222 + + + BUGTRAQ + 20021121 [LSD] Java and JVM security vulnerabilities + + Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler. + + + + + + + + + cpe:/a:mcafee:virusscan:4.5.1 + + CVE-2002-2282 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.820-04:00 + + + 6.9 + LOCAL + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-26T08:57:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + XF + virusscan-webscanx-dll-execution(10741) + + + BID + 6288 + + + BUGTRAQ + 20021129 Potential Vuln in McAfee VirusScan 451 + + McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs. + + + + + + + + + + + + cpe:/o:microsoft:windows_xp:::pro + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_xp::sp1:pro + cpe:/o:microsoft:windows_xp:::home + + CVE-2002-2283 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:48.977-04:00 + + + 1.9 + LOCAL + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-26T10:10:00.000-05:00 + + + + + XF + winxp-fus-processes-disclosure(10736) + + + BID + 6280 + + + BUGTRAQ + 20021129 User downgraded from Administrator to User retains the ability to list other user + + Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view prosesses of other users. + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:communicator:4.78 + cpe:/a:netscape:communicator:4.77 + cpe:/a:netscape:communicator:4.79 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.75 + cpe:/a:netscape:communicator:4.76 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.72 + + CVE-2002-2284 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.133-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-26T11:48:00.000-05:00 + + + + XF + netscape-java-insecure-classes(10714) + + + BID + 6223 + + + MISC + http://www.lsd-pl.net/documents/javasecurity-1.0.0.pdf + + + BUGTRAQ + 20021121 [LSD] Java and JVM security vulnerabilities + + Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes. + + + + + + + + + cpe:/a:ca:inoculateit:6.0 + + CVE-2002-2285 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.303-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-26T13:06:00.000-05:00 + + + + + XF + etrust-inoculateit-protection-bypass(10770) + + + NTBUGTRAQ + 20021129 CA InoculateIT 6.0 Realtime Scanner may fail to detect vira + + + SECTRACK + 1005740 + + eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection. + + + + + + + + + cpe:/a:apt-www-proxy:apt-www-proxy:0.1 + + CVE-2002-2286 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.447-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-26T13:09:00.000-05:00 + + + + + XF + apt-www-proxy-dos(10816) + + + BID + 6339 + + + BUGTRAQ + 20021210 Remote multiple vulnerability in apt-www-proxy. + + The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference. + + + + + + + + + + cpe:/a:phpbb:advanced_quick_reply_hack:1.0.0 + cpe:/a:phpbb:advanced_quick_reply_hack:1.1.0 + + CVE-2002-2287 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.600-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T13:16:00.000-05:00 + + + + + XF + phpbb-quickreply-file-include(10617) + + + BID + 6173 + + + BUGTRAQ + 20021113 Code Injection in phpBB Advanced Quick Reply Mod + + PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. + + + + + + + + + cpe:/a:mambo:site_server:4.0.11 + + CVE-2002-2288 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.743-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-26T13:21:00.000-05:00 + + + + + BID + 6387 + + + XF + mambo-index-path-disclosure(10856) + + + BUGTRAQ + 20021212 Multiple Mambo Site Server sec-weaknesses + + Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message. + + + + + + + + + cpe:/a:working_resources_inc.:badblue:1.7.1 + + CVE-2002-2289 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:49.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-26T16:48:00.000-05:00 + + + + + XF + badblue-soinfo-odbc-passwords(10690) + + + BID + 6243 + + + FULLDISC + 20021124 BadBlue XSS/Information Disclosure Vulnerabilities + + + SREASON + 3243 + + + BUGTRAQ + 20021124 BadBlue XSS/Information Disclosure Vulnerabilities + + soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords. + + + + + + + + + cpe:/a:mambo:mambo_site_server:4.0.11 + + CVE-2002-2290 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.040-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-26T16:51:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + mambo-default-admin-password(10857) + + + BUGTRAQ + 20021212 Multiple Mambo Site Server sec-weaknesses + + Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges. + + + + + + + + + cpe:/a:calisto:calisto_internet_talker:0.04 + + CVE-2002-2291 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.197-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-26T16:55:00.000-05:00 + + + + + BID + 6238 + + + XF + calisto-dos(10694) + + + SREASON + 3241 + + + BUGTRAQ + 20021125 SFAD02-002: Calisto Internet Talker Remote DOS + + + VULNWATCH + 20021125 SFAD02-002: Calisto Internet Talker Remote DOS + + Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow. + + + + + + + + + cpe:/a:halycon_software:iasp:1.0.9 + + CVE-2002-2292 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.350-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-26T17:02:00.000-05:00 + + + + + XF + iasp-dotdot-directory-traversal(10860) + + + BID + 6394 + + + BUGTRAQ + 20021213 Advisory Title: iASP Remote Console Applet Allows Remote + + Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095. + + + + + + + + + cpe:/a:twofold_photos:webshots_desktop + + CVE-2002-2293 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.507-04:00 + + + 4.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:07:00.000-05:00 + + + ALLOWS_USER_ACCESS + + XF + webshots-desktop-screenlock-bypass(10863) + + + BID + 6385 + + + BUGTRAQ + 20021212 Password Hole Found In Webshots + + Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager. + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:symantec:velociraptor:model_1100 + cpe:/a:symantec:raptor_firewall:6.5.3::solaris + cpe:/a:symantec:velociraptor:model_1000 + cpe:/a:symantec:enterprise_firewall:6.5.2::windows_2000_nt + cpe:/a:symantec:velociraptor:model_700 + cpe:/a:symantec:velociraptor:model_1300 + cpe:/a:symantec:enterprise_firewall:7.0::windows_2000_nt + cpe:/a:symantec:raptor_firewall:6.5::windows_nt + cpe:/a:symantec:enterprise_firewall:7.0::solaris + cpe:/a:symantec:velociraptor:model_500 + cpe:/a:symantec:velociraptor:model_1200 + + CVE-2002-2294 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:13:00.000-05:00 + + + + + BID + 6389 + + + XF + sef-realaudio-proxy-bo(10862) + + + CONFIRM + http://www.symantec.com/avcenter/security/Content/2002.12.12.html + + Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not properly handled by the RealAudio Proxy, or (2) crafted packets to the statistics service (statsd). + + + + + + + + + + + + cpe:/a:pico_server:pico_server:2.0_beta_2 + cpe:/a:pico_server:pico_server:2.0_beta_3 + cpe:/a:pico_server:pico_server:2.0_beta_5 + cpe:/a:pico_server:pico_server:2.0_beta_1 + + CVE-2002-2295 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:50.897-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:30:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + XF + pserv-version-specifier-bo(10789) + + + XF + pserv-data-stream-bo(10783) + + + XF + pserv-http-bo(10734) + + + BID + 6285 + + + BID + 6284 + + + BID + 6283 + + + MISC + http://www.securiteam.com/securitynews/6Q0020A6AS.html + + + BUGTRAQ + 20021201 Multiple pServ Remote Buffer Overflow Vulnerabilities + + + FULLDISC + 20021130 Multiple pServ Remote Buffer Overflow Vulnerabilities + + Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an HTTP request, (3) a long version number in an HTTP request, (4) a long User-Agent header, or (5) a long file path. + + + + + + + + + cpe:/a:yabb:yabb:1_gold_-_sp_1 + + CVE-2002-2296 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.053-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-26T17:34:00.000-05:00 + + + + + XF + yabb-xphp-xss(10737) + + + BID + 6272 + + + BUGTRAQ + 20021201 Cross-site Scripting Vulnerability in YaBB 1 Gold - SP1! + + Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter. + + + + + + + + + + cpe:/a:atthat.com:thatware:0.5.3 + cpe:/a:atthat.com:thatware:0.5.2 + + CVE-2002-2297 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.197-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:38:00.000-05:00 + + + + + XF + thatware-php-file-include(10758) + + + SECTRACK + 1005733 + + + BUGTRAQ + 20021201 Thatware (PHP) + + PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. + + + + + + + + + cpe:/a:atthat.com:thatware:0.5.3 + + CVE-2002-2298 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.350-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:40:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + XF + thatware-php-file-include(10758) + + + SECTRACK + 1005733 + + + BUGTRAQ + 20021201 Thatware (PHP) + + PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. + + + + + + + + + cpe:/a:atthat.com:thatware:0.5.2 + + CVE-2002-2299 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.493-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-26T17:44:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + XF + thatware-php-file-include(10758) + + + SECTRACK + 1005733 + + + BUGTRAQ + 20021201 Thatware (PHP) + + PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter. + + + + + + + + + + + cpe:/h:3com:webbngss3nbxnts:4.0.17 + cpe:/h:3com:webbngss3nbxnts:4.1.4 + cpe:/h:3com:webbngss3nbxnts:4.1.21 + + CVE-2002-2300 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-27T09:17:00.000-05:00 + + + + + XF + 3com-nbx-cel-bo(10739) + + + BID + 6297 + + + MISC + http://www.secnap.com/alerts.php?pg=6 + + + SECTRACK + 1005732 + + + BUGTRAQ + 20030427 3com NBX IP Phone Call manager Denial of Service - Update + + + BUGTRAQ + 20021202 [VU#317417] Denial of Service condition in vxworks ftpd/3com nbx + + Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command. + + + + + + + + + cpe:/a:lawson_software:lawson_financials:8.0 + + CVE-2002-2301 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.803-04:00 + + + 3.3 + LOCAL + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T09:31:00.000-05:00 + + + + + XF + lawson-financials-insecure-authentication(10742) + + + BID + 6293 + + + BUGTRAQ + 20021202 Advisory: Lawson Financials RDBMS Insecurity + + Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database. + + + + + + + + + + + cpe:/a:3d3.com:shopfactory:5.6 + cpe:/a:3d3.com:shopfactory:5.5 + cpe:/a:3d3.com:shopfactory:5.8 + + CVE-2002-2302 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:51.960-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T09:42:00.000-05:00 + + + + + XF + shopfactory-price-modification(10746) + + + BID + 6296 + + + BUGTRAQ + 20030305 shopfactory shopping cart + + + BUGTRAQ + 20021202 ShopFactory shopping cart price manipulation + + 3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field. + + + + + + + + + cpe:/a:3d3.com:shopfactory:5.8 + + CVE-2002-2303 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.147-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-27T09:43:00.000-05:00 + + + + + XF + shopfactory-price-modification(10746) + + + BID + 6296 + + + BUGTRAQ + 20021202 ShopFactory shopping cart price manipulation + + + SREASON + 3263 + + + BUGTRAQ + 20030305 shopfactory shopping cart + + 3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data. + + + + + + + + + + cpe:/a:myphpsoft:myphplinks:2.2.0 + cpe:/a:myphpsoft:myphplinks:2.1.9 + + CVE-2002-2304 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.303-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-27T09:45:00.000-05:00 + + + + + XF + myphplinks-index-sql-injection(10864) + + + BID + 6395 + + + BUGTRAQ + 20021214 MyPHPLinks (PHP) : SQL Injection + + SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter. + + + + + + + + + cpe:/a:phpsecure.org:immobilier:1.0 + + CVE-2002-2305 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.493-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-27T09:50:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + XF + immobilier-agentadmin-sql-injection(10705) + + + BUGTRAQ + 20021125 Immobilier 1 (PHP) + + SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter. + + + + + + + + + cpe:/a:kazaa:kazaa_media_desktop:1.7.1 + + CVE-2002-2306 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.633-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T09:48:00.000-05:00 + + + + + BID + 5317 + + + XF + kazaa-large-msg-dos(9672) + + Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. + + + + + + + + + cpe:/a:pyramid:benhur_software_update:66_r3 + + CVE-2002-2307 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.790-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T09:51:00.000-05:00 + + + + BID + 5279 + + + XF + benhur-protected-port-scan(9644) + + + MISC + http://www.aerasec.de/security/advisories/txt/ae-200207-028-BenHur-activeFTPruleset.txt + + The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20. + + + + + + + + + cpe:/a:netscape:communicator:6.2.1 + + CVE-2002-2308 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:52.947-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T10:04:00.000-05:00 + + + + XF + netscape-meta-refresh-dos(9645) + + Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:php:php:4.0.7:rc3 + cpe:/a:php:php:4.0.1:patch1 + cpe:/a:php:php:4.0.7:rc1 + cpe:/a:php:php:4.0.7:rc2 + cpe:/a:php:php:4.0 + cpe:/a:php:php:3.0.9 + cpe:/a:php:php:4.0.6 + cpe:/a:php:php:4.0.7 + cpe:/a:php:php:4.0.4 + cpe:/a:php:php:4.0.5 + cpe:/a:php:php:3.0.18 + cpe:/a:php:php:4.0.3:patch1 + cpe:/a:php:php:4.0.2 + cpe:/a:php:php:4.0.3 + cpe:/a:php:php:4.0.1 + cpe:/a:php:php:4.0.1:patch2 + cpe:/a:php:php:4.1.1 + cpe:/a:php:php:3.0.12 + cpe:/a:php:php:4.1.2 + cpe:/a:php:php:3.0.13 + cpe:/a:php:php:3.0.10 + cpe:/a:php:php:4.2.2 + cpe:/a:php:php:4.1.0 + cpe:/a:php:php:3.0.11 + cpe:/a:php:php:4.2.1 + cpe:/a:php:php:3.0.16 + cpe:/a:php:php:4.2.0 + cpe:/a:php:php:3.0.17 + cpe:/a:php:php:3.0.14 + cpe:/a:php:php:3.0.15 + cpe:/a:php:php:3.0.7 + cpe:/a:php:php:3.0.8 + cpe:/a:php:php:3.0.5 + cpe:/a:php:php:3.0.6 + cpe:/a:php:php:3.0.3 + cpe:/a:php:php:3.0.4 + cpe:/a:php:php:3.0.1 + cpe:/a:php:php:3.0.2 + + CVE-2002-2309 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:53.117-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T09:59:00.000-05:00 + + + + + BID + 5280 + + + XF + php-no-argument-dos(9646) + + php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments. + + + + + + + + + cpe:/a:kryptronic:clickcartpro:4.0 + + CVE-2002-2310 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:53.397-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T10:06:00.000-05:00 + + + + + MISC + http://www.securiteam.com/securitynews/5DP0T0K7PY.html + + + XF + clickcartpro-unauth-database-access-access(9648) + + + SECTRACK + 1004825 + + ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. + + + + + + + + + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0.1::win32 + cpe:/a:opera_software:opera_web_browser:6.0.1 + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:opera_software:opera_web_browser:6.0.1::linux + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:5.0.1 + + CVE-2002-2311 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:53.570-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T10:11:00.000-05:00 + + + + + BID + 5290 + + + XF + ie-ctrl-file-upload(9653) + + + BUGTRAQ + 20020724 RE: Pressing CTRL in IE is dangerous - Sandblad advisory #8 + + + BUGTRAQ + 20020723 Pressing CTRL in IE is dangerous - Sandblad advisory #8 + + Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue. + + + + + + + + + cpe:/a:opera_software:opera:6.0.1 + + CVE-2002-2312 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:53.773-04:00 + + + 5.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T10:22:00.000-05:00 + + + + BID + 5290 + + Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. + + + + + + + + + cpe:/a:qualcomm:eudora:5.1.1 + + CVE-2002-2313 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:53.960-04:00 + + + 8.8 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-27T10:27:00.000-05:00 + + + + XF + eudora-mhtml-execute-files(9654) + + + FULLDISC + 20020724 REFRESH: EUDORA MAIL 5.1.1 + + Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program, which is processed by Internet Explorer. + + + + + + + + + cpe:/a:mozilla:mozilla:1.0 + + CVE-2002-2314 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.100-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T10:32:00.000-05:00 + + + + + XF + mozilla-javascript-steal-cookies(9656) + + + BID + 5293 + + + CONFIRM + http://www.mozilla.org/releases/mozilla1.0.1/security-fixes-1.0.1.html + + + BUGTRAQ + 20020724 Mozilla cookie stealing - Sandblad advisory #9 + + + BUGTRAQ + 20020918 Mozilla vulnerabilities, an update + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=152725 + + Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail. + + + + + + + + + + + + cpe:/o:cisco:ios:11.0 + cpe:/o:cisco:ios:12.0 + cpe:/o:cisco:ios:11.1 + cpe:/o:cisco:ios:11.3 + + CVE-2002-2315 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.257-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T10:38:00.000-05:00 + + + + BID + 4786 + + + XF + cisco-ios-icmp-redirect-dos(9129) + + + BUGTRAQ + 20020521 Cisco IOS ICMP redirect DoS - Cisco's response + + + BUGTRAQ + 20020521 Cisco IOS ICMP redirect DoS + + Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router. + + + + + + + + + + + cpe:/o:cisco:catos:6.3%285%29 + cpe:/o:cisco:catos:7.1%282%29 + cpe:/o:cisco:catos:5.5%285%29 + + CVE-2002-2316 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T10:35:00.000-05:00 + + + + BID + 4790 + + + XF + cisco-catalyst-unicast-traffic(9148) + + + BUGTRAQ + 20020618 Re: Catalyst 4000 - Cisco's Response + + + BUGTRAQ + 20020520 Catalyst 4000 + + Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by sniffing. + + + + + + + + + cpe:/a:symantec:velociraptor:1.0 + + CVE-2002-2317 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.570-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T10:38:00.000-05:00 + + + + + CONFIRM + http://www.symantec.com/techsupp/enterprise/products/sym_velociraptor/sym_velociraptor_1/files.html + + + BID + 5909 + + + XF + velociraptor-memory-leak(10317) + + Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method. + + + + + + + + + + + + cpe:/a:blueface:falcon_web_server:2.0.0.1009 + cpe:/a:blueface:falcon_web_server:2.0.0.1021_ssl + cpe:/a:blueface:falcon_web_server:2.0.0.1021 + cpe:/a:blueface:falcon_web_server:2.0.0.1020 + + CVE-2002-2318 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.727-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T10:43:00.000-05:00 + + + + + BID + 5435 + + + XF + falcon-error-msg-xss(9812) + + + BUGTRAQ + 20020808 Cross-Site Scripting Issues in Falcon Web Server + + + FULLDISC + 20020808 Cross-Site Scripting Issues in Falcon Web Server + + Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages. + + + + + + + + + cpe:/a:mysimplenews:mysimplenews:1.0 + + CVE-2002-2319 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:54.883-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-27T10:43:00.000-05:00 + + + + + BID + 5865 + + + XF + mysimplenews-users-news-php(10296) + + + BUGTRAQ + 20021002 MySimpleNews (PHP) + + Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3. + + + + + + + + + cpe:/a:mysimplenews:mysimplenews:1.0 + + CVE-2002-2320 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.037-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + COMPLETE + NONE + http://nvd.nist.gov + 2007-12-27T10:47:00.000-05:00 + + + + + XF + mysimplenews-vider-delete-news(10299) + + + BUGTRAQ + 20021002 MySimpleNews (PHP) + + MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3. + + + + + + + + + cpe:/a:phplinkat:phplinkat:0.1.0 + + CVE-2002-2321 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.180-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T10:48:00.000-05:00 + + + + + BID + 5890 + + + XF + phplinkat-url-showcat-xss(10269) + + + BUGTRAQ + 20021003 phpLinkat XSS Security Bug + + Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter. + + + + + + + + + cpe:/a:ultimate_php_board:ultimate_php_board:1.0_beta + + CVE-2002-2322 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.337-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T10:50:00.000-05:00 + + + + + BID + 5858 + + + XF + upb-url-view-php(10300) + + + BUGTRAQ + 20021002 Multiple Web Security Holes + + Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. + + + + + + + + + + + cpe:/a:sun:solaris_pc_netlink:1.0 + cpe:/a:sun:solaris_pc_netlink:1.1 + cpe:/a:sun:solaris_pc_netlink:1.2 + + CVE-2002-2323 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.493-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T10:55:00.000-05:00 + + + + + BID + 5281 + + + XF + sun-pcnetlink-acl-permissions(9665) + + + SUNALERT + 27807 + + Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions. + + + + + + + + + cpe:/o:microsoft:windows_xp + + CVE-2002-2324 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.663-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-27T10:54:00.000-05:00 + + + + + BID + 5894 + + + XF + winxp-systemrestore-directory-access(10279) + + + BUGTRAQ + 20021004 WinXP Pro(Gold) Insecure System Restore File Permissions + + The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify registry settings. + + + + + + + + + + + + + cpe:/a:university_of_washington:pine:4.30 + cpe:/a:university_of_washington:pine:4.21 + cpe:/a:university_of_washington:pine:4.20 + cpe:/a:university_of_washington:pine:4.33 + cpe:/a:university_of_washington:pine:4.44 + + CVE-2002-2325 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.820-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T11:04:00.000-05:00 + + + + + XF + pine-blank-boundary-dos(9668) + + + BID + 5301 + + + BUGTRAQ + 20020724 Denial of Service bug in Pine 4.44 + + The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field. + + + + + + + + + + + + + + + + + + + cpe:/o:apple:mac_os_x:10.1 + cpe:/o:apple:mac_os_x:10.0.4 + cpe:/o:apple:mac_os_x:10.0 + cpe:/o:apple:mac_os_x:10.1.1 + cpe:/o:apple:mac_os_x:10.1.2 + cpe:/o:apple:mac_os_x:10.1.3 + cpe:/o:apple:mac_os_x:10.0.1 + cpe:/o:apple:mac_os_x:10.1.4 + cpe:/o:apple:mac_os_x:10.1.5 + cpe:/o:apple:mac_os_x:10.0.3 + cpe:/o:apple:mac_os_x:10.0.2 + + CVE-2002-2326 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:55.977-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T11:02:00.000-05:00 + + + + + BID + 5303 + + + XF + macos-idisk-insecure-password(9670) + + + BUGTRAQ + 20020724 Re: Apple OSX and iDisk and Mail.app + + + BUGTRAQ + 20020724 Apple OSX and iDisk and Mail.app + + The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic. + + + + + + + + + + + + + + + + cpe:/o:sun:solaris:8 + + CVE-2002-2327 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:56.147-04:00 + + + 4.9 + LOCAL + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T11:06:00.000-05:00 + + + + + BID + 5288 + + + XF + sun-fire-subsystem-dos(9675) + + + SUNALERT + 43908 + + Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties. + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000:::datacenter_server + + CVE-2002-2328 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:56.320-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T11:08:00.000-05:00 + + + + + BID + 4804 + + + XF + ms-active-directory-dos(9159) + + + BUGTRAQ + 20020523 Microsoft Active Directory security vulnerability + + Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request. + + + + + + + + + + + cpe:/a:mirabilis:icq:2002a + cpe:/a:mirabilis:icq:2001b + cpe:/a:mirabilis:icq:2002b + + CVE-2002-2329 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:56.460-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-27T11:16:00.000-05:00 + + + + + BID + 5295 + + + XF + icq-emoticons-dos(9677) + + + BUGTRAQ + 20020724 Icq 2001&2002 vulnerability + + ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons. + + + + + + + + + cpe:/a:uninet:statsplus:1.25 + + CVE-2002-2330 + 2002-12-31T00:00:00.000-05:00 + 2010-08-30T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T11:20:00.000-05:00 + + + + + BID + 5316 + + + XF + statsplus-stat-script-injection(9678) + + + BUGTRAQ + 20020725 Uninets StatsPlus 1.25 script injection vulnerabilities + + Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers. + + + + + + + + + + + + cpe:/a:cascadesoft:w3mail:1.0.4 + cpe:/a:cascadesoft:w3mail:1.0.5 + cpe:/a:cascadesoft:w3mail:1.0.2 + cpe:/a:cascadesoft:w3mail:1.0.3 + + CVE-2002-2331 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:56.773-04:00 + + + 5.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T11:27:00.000-05:00 + + + + + BID + 5314 + + + XF + w3mail-mime-attachment-execution(9680) + + + BUGTRAQ + 20020725 Medium security hole affecting W3Mail + + W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments. + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0.1::linux + + CVE-2002-2332 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:56.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T11:35:00.000-05:00 + + + + + BID + 5717 + + + XF + opera-konqueror-image-dos(10126) + + + BUGTRAQ + 20020915 Bug in Opera and Konqueror + + Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attributes. + + + + + + + + + + + + + + + + cpe:/o:kde:kde:2.2.2 + cpe:/o:kde:kde:2.2 + cpe:/o:kde:kde:2.1.1 + cpe:/o:kde:kde:2.1.2 + cpe:/o:kde:kde:2.1 + cpe:/o:kde:kde:3.0 + cpe:/o:kde:kde:2.2.1 + cpe:/o:kde:kde:3.0.2 + + CVE-2002-2333 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.087-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T11:40:00.000-05:00 + + + + + BID + 5721 + + + XF + opera-konqueror-image-dos(10126) + + + BUGTRAQ + 20020917 Re: Bug in Opera and Konqueror + + + BUGTRAQ + 20020915 Bug in Opera and Konqueror + + Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attributes. + + + + + + + + + + + + + + + + cpe:/a:joseph_allen:joe:2.9.2 + cpe:/a:joseph_allen:joe:2.8 + cpe:/a:joseph_allen:joe:2.9.1 + cpe:/a:joseph_allen:joe:2.9 + cpe:/a:joseph_allen:joe:2.9.4 + cpe:/a:joseph_allen:joe:2.9.7 + cpe:/a:joseph_allen:joe:2.9.6 + cpe:/a:joseph_allen:joe:2.9.5 + + CVE-2002-2334 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.240-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T12:00:00.000-05:00 + + + + + BID + 5732 + + + XF + joe-backup-suid-files(10125) + + + BUGTRAQ + 20020917 joe editor backup problem + + Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users. + + + + + + + + + cpe:/a:john_drake:killer_protection:1.0 + + CVE-2002-2335 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.413-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T12:07:00.000-05:00 + + + + + BID + 5905 + + + XF + killer-protection-vars-password(10315) + + + BUGTRAQ + 20021006 phpSecurePages & Killer Protection ( PHP ) + + Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php. + + + + + + + + + cpe:/a:symantec:norton_personal_firewall:2002:4.0 + + CVE-2002-2336 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.570-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T13:38:00.000-05:00 + + + + + BID + 5917 + + + XF + firewall-autoblock-spoofing-dos(10314) + + + BUGTRAQ + 20021008 Multiple Vendor PC firewall remote denial of services Vulnerability + + + BUGTRAQ + 20021008 Re: Multiple Vendor PC firewall remote denial of services Vulnerability + + Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. + + + + + + + + + cpe:/a:kaspersky_lab:kaspersky_anti-hacker:1.0 + + CVE-2002-2337 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.727-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T13:51:00.000-05:00 + + + + BID + 5917 + + + BUGTRAQ + 20030319 Easy DoS on Kaspersky Anti-Hacker v1.0 + + + BUGTRAQ + 20021008 Multiple Vendor PC firewall remote denial of services Vulnerability + + Kaspersky Anti-Hacker 1.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:netscape:navigator:6.0 + cpe:/a:mozilla:mozilla:0.9.6 + cpe:/a:netscape:navigator:6.1 + cpe:/a:mozilla:mozilla:0.9.5 + cpe:/a:netscape:navigator:6.2 + cpe:/a:mozilla:mozilla:0.9.4 + cpe:/a:mozilla:mozilla:0.9.3 + cpe:/a:mozilla:mozilla:1.0:rc2 + cpe:/a:mozilla:mozilla:0.9.9 + cpe:/a:mozilla:mozilla:0.9.8 + cpe:/a:mozilla:mozilla:1.0:rc1 + cpe:/a:mozilla:mozilla:0.9.7 + cpe:/a:netscape:communicator:4.0 + cpe:/a:netscape:communicator:4.08 + cpe:/a:netscape:communicator:4.7 + cpe:/a:netscape:communicator:4.6 + cpe:/a:netscape:communicator:4.5 + cpe:/a:netscape:communicator:4.4 + cpe:/a:netscape:navigator:6.0::mac + cpe:/a:mozilla:mozilla:1.0 + cpe:/a:netscape:navigator:6.01 + cpe:/a:mozilla:mozilla:0.9.2 + cpe:/a:netscape:communicator:4.61 + cpe:/a:netscape:communicator:4.06 + cpe:/a:netscape:communicator:4.07 + cpe:/a:netscape:communicator:4.77 + cpe:/a:netscape:navigator:6.2.2 + cpe:/a:mozilla:mozilla:0.9.2.1 + cpe:/a:netscape:navigator:6.2.1 + cpe:/a:mozilla:mozilla:0.9.4.1 + cpe:/a:netscape:communicator:4.73 + cpe:/a:netscape:communicator:4.74 + cpe:/a:netscape:communicator:4.75 + cpe:/a:netscape:communicator:4.76 + cpe:/a:netscape:communicator:4.51 + cpe:/a:netscape:communicator:4.72 + + CVE-2002-2338 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:57.883-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-27T13:57:00.000-05:00 + + + + + BID + 5002 + + + XF + mozilla-netscape-pop3-dos(9343) + + + CONFIRM + http://mozilla.org/releases/mozilla1.0.1/security-fixes-1.0.1.html + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=144228 + + The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message. + + + + + + + + + cpe:/a:script_shed:ssgbook:1.0 + + CVE-2002-2339 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.117-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T14:09:00.000-05:00 + + + + + BID + 5915 + + + XF + ss-guestbook-img-xss(10331) + + + BUGTRAQ + 20021008 SSGbook (ASP) + + + BUGTRAQ + 20031001 Re: SSGbook (ASP) + + Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags. + + + + + + + + + cpe:/a:phorum:phorum:3.3.2a + + CVE-2002-2340 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.273-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T14:33:00.000-05:00 + + + + + BID + 4739 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes5.txt + + + VULN-DEV + 20020512 Security holes : Pseudo-Frame, PG, KvPoll, Phorum, BanMat + + Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response. + + + + + + + + + cpe:/h:sonicwall:soho3:6.3.0.0 + + CVE-2002-2341 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.430-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T14:37:00.000-05:00 + + + + + BID + 4755 + + + XF + sonicwall-soho3-script-injection(9103) + + Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML via a blocked URL. + + + + + + + + + + + cpe:/a:joe_depasquale:bannermatic:1.0 + cpe:/a:joe_depasquale:bannermatic:3.0 + cpe:/a:joe_depasquale:bannermatic:2.0 + + CVE-2002-2342 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.570-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T14:43:00.000-05:00 + + + + + BID + 4738 + + + MISC + http://www.ifrance.com/kitetoua/tuto/5holes5.txt + + + VULN-DEV + 20020512 Security holes : Pseudo-Frame, PG, KvPoll, Phorum, BanMat + + Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient access control, which allows attackers to obtain sensitive information via a direct request for the files. + + + + + + + + + + + + + + cpe:/a:nocc:nocc:0.9 + cpe:/a:nocc:nocc:0.9.2 + cpe:/a:nocc:nocc:0.9.1 + cpe:/a:nocc:nocc:0.9.4 + cpe:/a:nocc:nocc:0.9.3 + cpe:/a:nocc:nocc:0.9.5 + + CVE-2002-2343 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.740-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T15:00:00.000-05:00 + + + + + BID + 4740 + + + XF + nocc-webmail-css(9071) + + + CONFIRM + http://sourceforge.net/tracker/index.php?func=detail&aid=555897&group_id=12177&atid=112177 + + + BUGTRAQ + 20020514 NOCC: cross-site-scripting bug + + Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages. + + + + + + + + + + cpe:/a:ensim:webppliance:3.0 + cpe:/a:ensim:webppliance:3.1 + + CVE-2002-2344 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:58.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T15:05:00.000-05:00 + + + + + BID + 5418 + + + SECTRACK + 1004938 + + Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address. + + + + + + + + + cpe:/a:oracle:application_server:9.0.2 + + CVE-2002-2345 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.053-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-27T15:32:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 7395 + + + XF + oracle-appserver-webcachepw-unencrypted(9841) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert39rev1.pdf + + Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access. + + + + + + + + + + + + cpe:/a:phpbb:phpbb:2.0.1 + cpe:/a:phpbb:phpbb:2.0 + cpe:/a:phpbb:phpbb:2.0.2 + cpe:/a:phpbb:phpbb:2.0.3 + + CVE-2002-2346 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.197-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-27T15:59:00.000-05:00 + + + + + BID + 5923 + + + XF + phpbb-avatar-ip-address(10323) + + + BUGTRAQ + 20021009 phpBB2 Showing users ip adresses + + phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses. + + + + + + + + + + + + cpe:/a:oracle:application_server:1.0.2.1s + cpe:/a:oracle:application_server:1.0.2.2 + cpe:/a:oracle:application_server:9.0.2 + cpe:/a:oracle:application_server:1.0.2 + + CVE-2002-2347 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.367-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-27T16:02:00.000-05:00 + + + + + BID + 5452 + + + XF + oracle-appserver-ojsp-xss(9842) + + + CONFIRM + http://otn.oracle.com/deploy/security/pdf/2002alert41rev1.pdf + + Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field. + + + + + + + + + cpe:/a:authoria:authoria:authoria_hr_suite + + CVE-2002-2348 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.523-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T10:58:00.000-05:00 + + + + + BID + 5932 + + + BUGTRAQ + 20021009 XSS in Authoria HR Suite + + + XF + authoria-hr-athcgi-xss(10324) + + Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter. + + + + + + + + + cpe:/a:phpbb:phpbbmod:1.3.3 + + CVE-2002-2349 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.680-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-28T13:58:00.000-05:00 + + + + + BID + 5942 + + + XF + phpbbmod-phpinfo-information-disclosure(10335) + + phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information. + + + + + + + + + cpe:/a:phpoutsourcing:zorum:2.4 + + CVE-2002-2350 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.837-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T14:01:00.000-05:00 + + + + + XF + zorum-zusershow-xss(10337) + + + BUGTRAQ + 20021010 XSS bug in Zorum 2.4 + + Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web script or HTML via the class parameter. + + + + + + + + + + + + + + cpe:/a:qualcomm:eudora:5.2 + cpe:/a:qualcomm:eudora:6.1.1 + cpe:/a:qualcomm:eudora:5.1 + cpe:/a:qualcomm:eudora:6.0.1 + cpe:/a:qualcomm:eudora:6.0 + cpe:/a:qualcomm:eudora:5.2.1 + + CVE-2002-2351 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:32:59.977-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T14:06:00.000-05:00 + + + + + BID + 5432 + + + CONFIRM + http://www.eudora.com/download/eudora/windows/5.2/RelNotes.txt + + Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot). + + + + + + + + + cpe:/a:neosoft:neobook:4 + + CVE-2002-2352 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:00.147-04:00 + + + 5.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T14:18:00.000-05:00 + + + + BID + 6191 + + + XF + neobook-nbaactivex-execute-programs(10645) + + + SREASON + 3317 + + + BUGTRAQ + 20021116 NBActiveX Sure ActiveX Big Vulnerability + + The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs. + + + + + + + + + + cpe:/a:tftpd32:tftpd32:2.50 + cpe:/a:tftpd32:tftpd32:2.50.2 + + CVE-2002-2353 + 2002-12-31T00:00:00.000-05:00 + 2009-11-24T00:15:50.437-05:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T14:45:00.000-05:00 + + + + + CERT-VN + VU#632633 + + + BID + 6198 + + + MISC + http://www.securiteam.com/windowsntfocus/6D00D2061G.html + + + XF + tftp32-directory-traversal(10646) + + + CONFIRM + http://tftpd32.jounin.net/ + + tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. + + + + + + + + + cpe:/h:netgear:fm114p + + CVE-2002-2354 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:00.443-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-28T14:49:00.000-05:00 + + + + + BID + 5940 + + + BUGTRAQ + 20021010 TCP flood against NetGear FM114P + + + XF + netgear-fm114p-tcp-dos(10340) + + Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests. + + + + + + + + + cpe:/h:netgear:fm114p + + CVE-2002-2355 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:00.600-04:00 + + + 7.1 + NETWORK + MEDIUM + NONE + COMPLETE + NONE + NONE + http://nvd.nist.gov + 2007-12-28T14:53:00.000-05:00 + + + + + BID + 5943 + + + BUGTRAQ + 20021010 Plain text DDNS password in NetGear FM114P backups + + + XF + netgear-fm114p-plaintext-ddns(10341) + + Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other information in cleartext, which could allow local users to obtain sensitive information. + + + + + + + + + cpe:/a:hamweather:hamweather + + CVE-2002-2356 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:00.740-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:03:00.000-05:00 + + + + + XF + hamweather-hwadmin-web-admin(10182) + + + CONFIRM + http://www.hamweather.net/hw3/hw2securityalert.shtml + + + SECTRACK + 1005270 + + HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi. + + + + + + + + + + + + cpe:/a:mailenable:mailenable:1.5015 + cpe:/a:mailenable:mailenable:1.5016 + cpe:/a:mailenable:mailenable:1.5017 + cpe:/a:mailenable:mailenable:1.5018 + + CVE-2002-2357 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:00.897-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-28T15:09:00.000-05:00 + + + + + BID + 6197 + + + XF + mailenable-pop3-server-dos(10652) + + + BUGTRAQ + 20021117 MailEnable POP3 Server remote shutdown !:/ -newest ~ (and previous) bufferoverflow- + + MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overflow. + + + + + + + + + + + + + + + + cpe:/a:opera_software:opera_web_browser:6.0.1::win32 + cpe:/a:opera_software:opera_web_browser:6.0.1 + cpe:/a:opera_software:opera_web_browser:6.0::win32 + cpe:/a:opera_software:opera_web_browser:6.0 + cpe:/a:opera_software:opera_web_browser:6.0.1::linux + cpe:/a:opera_software:opera_web_browser:6.0.4::win32 + cpe:/a:opera_software:opera_web_browser:6.0.3::win32 + cpe:/a:opera_software:opera_web_browser:6.0.2::win32 + + CVE-2002-2358 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.053-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:16:00.000-05:00 + + + + + BID + 5401 + + + MISC + http://www.opera.com/windows/changelogs/605/?session=b2a9ea38c710788c23970ba2c9a34d47 + + + XF + multiple-ftp-view-xss(9757) + + + VULNWATCH + 20020806 Opera FTP View Cross-Site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL. + + + + + + + + + + + + cpe:/a:mozilla:mozilla:1.0:rc2 + cpe:/a:mozilla:mozilla:1.0:rc1 + cpe:/a:mozilla:mozilla:1.0 + cpe:/a:mozilla:mozilla:1.1:alpha + + CVE-2002-2359 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.227-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:21:00.000-05:00 + + + + + BID + 5403 + + + XF + multiple-ftp-view-xss(9757) + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=154030 + + + VULNWATCH + 20020806 Mozilla FTP View Cross-Site Scripting Vulnerability + + Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:webmin:webmin:0.960 + cpe:/a:webmin:webmin:0.970 + cpe:/a:webmin:webmin:0.950 + cpe:/a:webmin:webmin:0.76 + cpe:/a:webmin:webmin:0.78 + cpe:/a:webmin:webmin:0.88 + cpe:/a:webmin:webmin:0.77 + cpe:/a:webmin:webmin:0.79 + cpe:/a:webmin:webmin:0.42 + cpe:/a:webmin:webmin:0.92 + cpe:/a:webmin:webmin:0.22 + cpe:/a:webmin:webmin:0.31 + cpe:/a:webmin:webmin:0.41 + cpe:/a:webmin:webmin:0.980 + cpe:/a:webmin:webmin:0.91 + cpe:/a:webmin:webmin:0.21 + cpe:/a:webmin:webmin:0.51 + cpe:/a:webmin:webmin:0.80 + cpe:/a:webmin:webmin:0.990 + cpe:/a:webmin:webmin:0.94 + cpe:/a:webmin:webmin:0.85 + cpe:/a:webmin:webmin:0.93 + + CVE-2002-2360 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.383-04:00 + + + 9.3 + NETWORK + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-28T15:26:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5591 + + + MISC + http://www.securiteam.com/unixfocus/5CP0R1P80G.html + + + XF + webmin-cgi-improper-permissions(9983) + + + BUGTRAQ + 20020828 Webmin Vulnerability Leads to Remote Compromise (RPC CGI) + + The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests. + + + + + + + + + + + cpe:/a:yahoo:messenger:4.0 + cpe:/a:yahoo:messenger:5.0 + cpe:/a:yahoo:messenger:5.5 + + CVE-2002-2361 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.570-04:00 + + + 5.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:36:00.000-05:00 + + + + + BID + 5579 + + + XF + yahoo-installer-insecure-connection(9984) + + The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing. + + + + + + + + + cpe:/a:sourceforge:mymarket:1.71 + + CVE-2002-2362 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.727-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:39:00.000-05:00 + + + + + BID + 6035 + + + XF + mymarket-formheader-xss(10470) + + Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter. + + + + + + + + + cpe:/o:hp:hp-ux:11.00 + + CVE-2002-2363 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:01.883-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-28T15:43:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5583 + + + XF + hp-vje-gain-privileges(9993) + + + HP + HPSBUX0208-214 + + VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges. + + + + + + + + + cpe:/a:sourceforge:php_ticket:0.5 + + CVE-2002-2364 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.023-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-28T15:45:00.000-05:00 + + + + + BID + 5124 + + + XF + phpticket-html-xss(9452) + + Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket. + + + + + + + + + cpe:/a:springer_verlag_berlin_heidelberg:simple_wais:1.11 + + CVE-2002-2365 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.180-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-28T15:52:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5127 + + + XF + swais-command-execution(9453) + + + BUGTRAQ + 20020630 Simple Wais 1.11 allows users to execute commands as SWAIS deamon. + + Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character. + + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.725 + cpe:/a:cerulean_studios:trillian:0.73 + cpe:/a:cerulean_studios:trillian:0.6351 + + CVE-2002-2366 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.337-04:00 + + + 6.8 + NETWORK + MEDIUM + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-28T15:58:00.000-05:00 + + + + + BID + 5601 + + + XF + trillian-xml-parser-bo(9999) + + + BUGTRAQ + 20020831 Trillian XML parser buffer overflow + + Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml. + + + + + + + + + cpe:/a:socks5:socks5:1.0_r11 + + CVE-2002-2367 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.477-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-28T16:00:00.000-05:00 + + + + + + BID + 5149 + + + XF + socks5-hostname-offbyone-bo(9484) + + + BUGTRAQ + 20020703 NEC's socks5 (Re: Foundstone Advisory - Buffer Overflow in AnalogX Proxy (fwd)) + + Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hostname. + + + + + + + + + cpe:/a:nec:socks_5:1.0r11 + + CVE-2002-2368 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.633-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-31T09:02:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5147 + + + BID + 5145 + + + XF + socks-username-bo(9485) + + + BUGTRAQ + 20020703 NEC's socks5 (Re: Foundstone Advisory - Buffer Overflow in AnalogX Proxy (fwd)) + + Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function in proxy.c for the SOCKS5 module or (2) the HandleS4Connection function in proxy.c for the SOCKS4 module. + + + + + + + + + cpe:/a:perception:liteserve:2.0 + + CVE-2002-2369 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.787-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-31T09:07:00.000-05:00 + + + + + BID + 6042 + + + MISC + http://www.securityoffice.net/articles/liteserve/ + + + XF + perception-liteserve-file-access(10468) + + + BUGTRAQ + 20021024 [SecurityOffice] Liteserve Web Server v2.0 Authorization Bypass Vulnerability + + Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL. + + + + + + + + + + + cpe:/a:sws:sws_simple_web_server:0.0.3 + cpe:/a:sws:sws_simple_web_server:0.1.0 + cpe:/a:sws:sws_simple_web_server:0.0.4 + + CVE-2002-2370 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:02.930-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-31T09:13:00.000-05:00 + + + + BID + 5664 + + + XF + sws-webserver-newline-dos(10005) + + + BUGTRAQ + 20020902 SWS Web Server v0.1.0 Exploit + + SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline. + + + + + + + + + + cpe:/h:linksys:wet11:1.32 + cpe:/h:linksys:wet11:1.31 + + CVE-2002-2371 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.087-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-31T09:55:00.000-05:00 + + + + + BID + 6046 + + + CONFIRM + http://www.linksys.com/download/vertxt/WET11_fw_ver.TXT + + + XF + linksys-wet11-ethernet-dos(10472) + + + BUGTRAQ + 20021025 Linksys WET11 crashes when sent an ethernet frame from its own MAC address + + + VULNWATCH + 20021025 Linksys WET11 crashes when sent an ethernet frame from its own MAC address + + Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header. + + + + + + + + + + + + + + cpe:/a:ibm:infoprint_21:1.047012 + + CVE-2002-2372 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.240-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-31T10:04:00.000-05:00 + + + + + BID + 6047 + + + XF + ibm-infoprint-telnet-dos(10474) + + + BUGTRAQ + 20021025 IBM Infoprint Remote Management Simple DoS + + The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow. + + + + + + + + + + + + + + cpe:/a:apple:tcp_ip_configuration_utility:12_640 + + CVE-2002-2373 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.397-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-31T10:09:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 6052 + + + BUGTRAQ + 20021026 TCP/IP Printer Configuration Utility for Apple.LaserWriter 12/640 PS security problem + + + XF + apple-laserwriter-telnet-access(10476) + + The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access. + + + + + + + + + cpe:/a:sun:patchpro:2.0 + + CVE-2002-2374 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.553-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-31T10:22:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + + BID + 5540 + + + CONFIRM + http://sunsolve.sun.com/search/document.do?assetkey=1-21-113176-01-1&searchclause=113176 + + Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files." + + + + + + + + + cpe:/a:stalker:communigate_pro:4.0b4 + + CVE-2002-2375 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-31T10:28:00.000-05:00 + + + + + XF + communigatepro-view-dir-listings(9463) + + + BUGTRAQ + 20020702 CommuniGate Pro directory listings + + Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information. + + + + + + + + + cpe:/a:leung:e-guest:1.1 + + CVE-2002-2376 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:03.850-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T10:39:00.000-05:00 + + + + + BID + 5129 + + + BID + 5128 + + + XF + eguest-ssi-command-execution(9470) + + + XF + eguest-html-xss(9469) + + + BUGTRAQ + 20020629 SSI & CSS execution in E-Guest (1.1) & ZAP Book (v1.0.3) + + Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605. + + + + + + + + + cpe:/a:sephiroth32:zap_book:1.0.3 + + CVE-2002-2377 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.053-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T11:11:00.000-05:00 + + + + + BID + 5131 + + + BID + 5130 + + + XF + zapbook-ssi-command-execution(9472) + + + XF + zapbook-entry-xss(9471) + + Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field. + + + + + + + + + cpe:/a:nakata:an_httpd:1.41d + + CVE-2002-2378 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.210-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T11:17:00.000-05:00 + + + + + BID + 6054 + + + BUGTRAQ + 20021028 [SNS Advisory No.57] AN HTTPD Cross-site Scripting Vulnerability + + + XF + an-http-colon-xss(10487) + + Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page. + + + + + + + + + cpe:/h:cisco:as5350:12.2%2811t%29 + + CVE-2002-2379 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.350-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2007-12-31T11:30:00.000-05:00 + + + + + BID + 6059 + + + XF + cisco-as5350-portscan-dos(10522) + + + CISCO + 20021029 Response to BugTraq - Cisco AS5350 Crashes with nmap Connect Scan + + + BUGTRAQ + 20021029 Re: CISCO as5350 crashes with nmap connect scan + + + BUGTRAQ + 20021029 Re: CISCO as5350 crashes with nmap connect scan + + + BUGTRAQ + 20021029 Re: CISCO as5350 crashes with nmap connect scan + + + BUGTRAQ + 20021028 CISCO as5350 crashes with nmap connect scan + + ** DISPUTED ** Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor. + + + + + + + + + + + + + + cpe:/a:microsoft:network_firmware:5.5.11 + + CVE-2002-2380 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.490-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T11:42:00.000-05:00 + + + + + BID + 6064 + + + XF + netdsl-msn-default-account(10498) + + + BUGTRAQ + 20021029 Further problems with Arescom NetDSL-800 MSN Firmware version 5.4.x and up + + NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic. + + + + + + + + + + + + cpe:/a:ka-shu_wong:gtetrinet:0.4.3 + cpe:/a:ka-shu_wong:gtetrinet:0.4 + cpe:/a:ka-shu_wong:gtetrinet:0.4.1 + cpe:/a:ka-shu_wong:gtetrinet:0.4.2 + + CVE-2002-2381 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.647-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-31T11:49:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 6062 + + + SECTRACK + 1005497 + + + XF + gtetrinet-multiple-functions-bo(10511) + + + GENTOO + 200211-006 + + + DEBIAN + DSA-205 + + Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code. + + + + + + + + + cpe:/a:cvsup:cvsup:1.2 + + CVE-2002-2382 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.803-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-31T11:56:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6150 + + + XF + cvsup-cvsupd-out-symlink(10610) + + + MLIST + [freebsd-security] 20021109 Security issue in net/cvsup-mirror port + + cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out. + + + + + + + + + + + + cpe:/a:f2html.pl:f2html.pl:0.2 + cpe:/a:f2html.pl:f2html.pl:0.3 + cpe:/a:f2html.pl:f2html.pl:0.1 + cpe:/a:f2html.pl:f2html.pl:0.4 + + CVE-2002-2383 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:04.960-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-31T12:01:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 5123 + + + XF + f2html-sql-injection(9596) + + SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names. + + + + + + + + + cpe:/a:hotfoon_corporation:hotfoon:4.0 + + CVE-2002-2384 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.117-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T12:07:00.000-05:00 + + + + + BID + 6155 + + + XF + hotfoon-plaintext-passwords(10591) + + + BUGTRAQ + 20021110 Multiple Vuln. in Hotfoon.com + + hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service. + + + + + + + + + cpe:/a:hotfoon_corporation:hotfoon:4.0 + + CVE-2002-2385 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.257-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-31T12:49:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + BID + 6156 + + + XF + hotfoon-phone-number-bo(10593) + + + BUGTRAQ + 20021110 Multiple Vuln. in Hotfoon.com + + Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL containing a long voice phone number. + + + + + + + + + cpe:/a:xoops:xoops:1.0_rc3 + + CVE-2002-2386 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.413-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T13:02:00.000-05:00 + + + + + XF + xoops-quiz-module-xss(10594) + + + MISC + http://www.blocus-zone.com/modules/news/article.php?storyid=180 + + + BUGTRAQ + 20021110 xoops Quizz Module IMG bug + + Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS 1.0, when allowing on-line question development, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the SRC attribute of an IMG tag. + + + + + + + + + cpe:/a:mollensoft_software:hyperion_ftp_server:2.8.1 + + CVE-2002-2387 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.553-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-31T13:11:00.000-05:00 + + + + + XF + hyperion-dotdot-directory-traversal(10599) + + + VULNWATCH + 20021112 [SecurityOffice] Hyperion Ftp Server v2.8.1 Directory Traversal Vulnerability + + Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command. + + + + + + + + + cpe:/a:inweb:mail_server:2.01 + + CVE-2002-2388 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.710-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-31T13:22:00.000-05:00 + + + + + XF + inweb-helo-command-bo(10601) + + + VULNWATCH + 20021112 [SecurityOffice] INweb Mail Server v2.01 Denial of Service Vulnerability + + Buffer overflow in INweb POP3 mail server 2.01 allows remote attackers to cause a denial of service (crash) via a long HELO command. + + + + + + + + + cpe:/a:fastlink_software:the_server:1.74 + + CVE-2002-2389 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:05.850-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2007-12-31T13:29:00.000-05:00 + + + + + BID + 5250 + + + BUGTRAQ + 20021014 TheServer log file access password in cleartext w/vendor resolution. + + + XF + fastlink-theserver-plaintext-passwords(9624) + + + SECTRACK + 1004799 + + + FULLDISC + 20020717 TheServer cleartext password sillyness. + + TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows remote attackers to obtain cleartext passwords and gain access to server log files. + + + + + + + + + + + cpe:/a:cerulean_studios:trillian:0.73 + cpe:/a:cerulean_studios:trillian:0.74 + cpe:/a:cerulean_studios:trillian_pro:1.0 + + CVE-2002-2390 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.007-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2007-12-31T13:44:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 5733 + + + XF + trillian-identd-bo(10118) + + + FULLDISC + 20020917 Trillian .74 and below, ident flaw. + + + BUGTRAQ + 20020918 trillian DoS: trillian 1.0 pro also vulnerable + + + BUGTRAQ + 20020918 Trillian .74 and below, ident flaw. + + Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request. + + + + + + + + + + cpe:/a:webchat.org:webchat:1.5 + cpe:/a:xoops:xoops:1.0 + + CVE-2002-2391 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.163-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2007-12-31T13:48:00.000-05:00 + + + ALLOWS_USER_ACCESS + + + XF + xoops-webchat-sql-injection(10606) + + + BID + 6165 + + + BUGTRAQ + 20021116 XOOPS WebChat module - patch UPDATE + + + BUGTRAQ + 20021112 WebChat for XOOPS RC3 SQL INJECTION + + SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter. + + + + + + + + + + + + + + + + + + + + + cpe:/a:nullsoft:winamp:3.1 + cpe:/a:nullsoft:winamp:2.70 + cpe:/a:nullsoft:winamp:2.80 + cpe:/a:nullsoft:winamp:2.71 + cpe:/a:nullsoft:winamp:2.73 + cpe:/a:nullsoft:winamp:2.72 + cpe:/a:nullsoft:winamp:2.75 + cpe:/a:nullsoft:winamp:2.74 + cpe:/a:nullsoft:winamp:2.77 + cpe:/a:nullsoft:winamp:2.76 + cpe:/a:nullsoft:winamp:2.79 + cpe:/a:nullsoft:winamp:2.78 + cpe:/a:nullsoft:winamp:2.65 + + CVE-2002-2392 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.320-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T13:55:00.000-05:00 + + + + BID + 5266 + + + XF + winamp-wsz-code-execution(9630) + + + BUGTRAQ + 20020717 WINAMP also allows execution of arbitrary code (probably a lot more programs aswell) + + Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code. + + + + + + + + + + cpe:/a:serv-u:serv-u:4.0.0.4 + cpe:/a:serv-u:serv-u:3.1.0.0 + + CVE-2002-2393 + 2002-12-31T00:00:00.000-05:00 + 2010-04-28T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2007-12-31T17:33:00.000-05:00 + + + + + BID + 6112 + + + XF + servu-mkd-command-dos(10573) + + + BUGTRAQ + 20021106 RhinoSoft Serv-U FTP Anonymous Remote DoS Vulnerability + + Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands. + + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.52::windows + cpe:/a:trend_micro:interscan_viruswall:3.6::linux + + CVE-2002-2394 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.647-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T17:59:00.000-05:00 + + + + + BID + 5697 + + + BUGTRAQ + 20020912 Bypassing TrendMicro InterScan VirusWall + + + XF + interscan-chunked-transfer-bypass(10106) + + InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 chunked transfer encoding. + + + + + + + + + cpe:/a:trend_micro:interscan_viruswall:3.52::windows + + CVE-2002-2395 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.803-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2007-12-31T18:03:00.000-05:00 + + + + + BID + 5701 + + + XF + interscan-gzip-content-bypass(10107) + + InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content encoding. + + + + + + + + + + cpe:/a:remi_lefebvre:advanced_tftp:0.5 + cpe:/a:remi_lefebvre:advanced_tftp:0.6 + + CVE-2002-2396 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:06.943-04:00 + + + 7.2 + LOCAL + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T08:14:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + atftp-strcpy-bo(10142) + + Buffer overflow in Advanced TFTP (atftp) 0.5 and 0.6, if installed setuid or setgid, may allow local users to execute arbitrary code via a long argument to the -g option. + + + + + + + + + cpe:/a:symantec:sygate_personal_firewall:5.0 + + CVE-2002-2397 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:07.100-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T08:19:00.000-05:00 + + + + + MISC + http://www.securiteam.com/windowsntfocus/5WP0I2A8AI.html + + + XF + sygate-firewall-ip-spoofing(10108) + + + VULNWATCH + 20020916 NSSI-2002-sygatepfw5: Sygate Personal Firewall IP Spoofing Vulnerability + + Sygate personal firewall 5.0 could allow remote attackers to bypass firewall filters via spoofed (1) source IP address of 127.0.0.1 or (2) network address of 127.0.0.0. + + + + + + + + + + cpe:/a:app:apboard:2.03 + cpe:/a:app:apboard:2.02 + + CVE-2002-2398 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:07.240-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T08:33:00.000-05:00 + + + + BID + 6167 + + + XF + apboard-protected-forum-bypass(10611) + + + SREASON + 3332 + + + BUGTRAQ + 20021112 APBoard - post threads to protected forums and possibility to hijack forum-password + + The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter. + + + + + + + + + cpe:/a:cascadesoft:w3mail:1.0.6 + + CVE-2002-2399 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:07.397-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T08:39:00.000-05:00 + + + + + BID + 6170 + + + XF + w3mail-argument-read-files(10612) + + + BUGTRAQ + 20021112 Fresh hole in W3Mail (fwd) + + Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. + + + + + + + + + cpe:/a:hughes_technologies:libhttpd:1.2 + + CVE-2002-2400 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:07.553-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T08:46:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6172 + + + BUGTRAQ + 20021124 LibHTTPD Vulnerability and fix + + + MISC + http://www.securiteam.com/unixfocus/6H00I2060I.html + + + XF + libhttpd-httpdprocessrequest-bo(10615) + + + BUGTRAQ + 20021113 Remote Buffer Overflow vulnerability in Lib HTTPd. + + Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/o:microsoft:windows_2000:::advanced_server + cpe:/o:microsoft:windows_2000:::datacenter_server + cpe:/o:microsoft:windows_2000:::professional + cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise + cpe:/o:microsoft:windows_xp::sp1:pro + cpe:/o:microsoft:windows_nt:4.0:sp4:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6a:workstation + cpe:/o:microsoft:windows_2000::sp2:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp1:workstation + cpe:/o:microsoft:windows_2000::sp3:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp2:workstation + cpe:/o:microsoft:windows_xp::sp1:home + cpe:/o:microsoft:windows_2000::sp1:datacenter_server + cpe:/o:microsoft:windows_nt:4.0:sp5:workstation + cpe:/o:microsoft:windows_nt:4.0:sp6:workstation + cpe:/o:microsoft:windows_nt:4.0:sp3:server + cpe:/o:microsoft:windows_nt:4.0:sp4:server + cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise + cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise + cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise + cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise + cpe:/o:microsoft:windows_2000::sp2:professional + cpe:/o:microsoft:windows_2000::sp1:professional + cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise + cpe:/o:microsoft:windows_nt:4.0:sp6:server + cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise + cpe:/o:microsoft:windows_nt:4.0:sp5:server + cpe:/o:microsoft:windows_2000::sp3:professional + cpe:/o:microsoft:windows_2000:::server + cpe:/o:microsoft:windows_2000::sp2:advanced_server + cpe:/o:microsoft:windows-nt:4.0 + cpe:/o:microsoft:windows_2000::sp1:advanced_server + cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_srv + cpe:/o:microsoft:windows_2000::sp3:advanced_server + cpe:/o:microsoft:windows_xp:::home + cpe:/o:microsoft:windows_nt:4.0:sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp1:server + cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_srv + cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_srv + cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_srv + cpe:/o:microsoft:windows_2000::sp2:server + cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_srv + cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_srv + cpe:/o:microsoft:windows_nt:4.0:sp6a:server + cpe:/o:microsoft:windows_2000::sp3:server + cpe:/o:microsoft:windows_2000::sp1:server + cpe:/o:microsoft:windows_nt:4.0::workstation + cpe:/o:microsoft:windows_xp:::pro + + CVE-2002-2401 + 2002-12-31T00:00:00.000-05:00 + 2008-09-10T15:17:16.057-04:00 + + + 3.6 + LOCAL + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T10:15:00.000-05:00 + + + + + BID + 5740 + + + XF + win-execute-permissions-16bit(10132) + + + MSKB + 319458 + + + BUGTRAQ + 20020918 Execution Rights Not Checked Correctly For 16-bit Applications + + NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs. + + + + + + + + + cpe:/h:surecom:ep-4501 + + CVE-2002-2402 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:07.990-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T10:18:00.000-05:00 + + + + BID + 6176 + + + XF + surecom-default-snmp-string(10621) + + + BUGTRAQ + 20021113 Default SNMP community in Surecom Broadband Router + + SURECOM broadband router EP-4501 uses a default SNMP read community string of "public" and a default SNMP read/write community string of "secret," which allows remote attackers to read and modify router configuration information. + + + + + + + + + cpe:/a:key_focus:kf_web_server:1.0.8 + + CVE-2002-2403 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.130-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T10:31:00.000-05:00 + + + + + BID + 6180 + + + BUGTRAQ + 20021113 KeyFocus KF Web Server File Disclosure Vulnerability + + + CONFIRM + http://www.keyfocus.net/kfws/support/ + + + XF + keyfocus-get-directory-traversal(10622) + + + SREASON + 3331 + + + VULNWATCH + 20021113 KeyFocus KF Web Server File Disclosure Vulnerability + + Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences. + + + + + + + + + + cpe:/a:curtis_specialty_consulting:iispop:1.181 + cpe:/a:curtis_specialty_consulting:iispop:1.161 + + CVE-2002-2404 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.287-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2008-01-02T10:35:00.000-05:00 + + + + + BID + 6183 + + + XF + iispop-email-server-bo(10632) + + + BUGTRAQ + 20021114 IISPop remote DOS + + Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110). + + + + + + + + + + cpe:/a:checkpoint:firewall-1:ng + cpe:/a:checkpoint:firewall-1:4.1 + + CVE-2002-2405 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.427-04:00 + + + 4.9 + NETWORK + MEDIUM + SINGLE_INSTANCE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T10:41:00.000-05:00 + + + + + BID + 5744 + + + XF + fw1-http-proxy-bypass(10139) + + + BUGTRAQ + 20020918 Firewall-1 ?HTTP Security Server - Proxy vulnerability + + Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through the firewall. + + + + + + + + + + + cpe:/a:perception:liteserve:2.0 + cpe:/a:perception:liteserve:2.0.2 + cpe:/a:perception:liteserve:2.0.1 + + CVE-2002-2406 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.600-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2008-01-02T10:47:00.000-05:00 + + + + + BID + 6192 + + + XF + liteserve-percent-character-dos(10644) + + + VULNWATCH + 20021117 LiteServe URL Decoding DoS + + Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request. + + + + + + + + + + cpe:/a:qnx:rtos:6.2a + cpe:/a:qnx:rtos:6.2 + + CVE-2002-2407 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.757-04:00 + + + 6.9 + LOCAL + MEDIUM + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T10:46:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + BID + 6206 + + + XF + qnx-rtos-improper-permissions(10656) + + + BUGTRAQ + 20021119 Multiple incorrect permissions in QNX. + + Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed. + + + + + + + + + cpe:/a:gordano:ntmail:8.0 + + CVE-2002-2408 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:08.913-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2008-01-02T11:04:00.000-05:00 + + + + BID + 6209 + + + CONFIRM + http://www.gordano.com/kb.htm?q=1709 + + + XF + gmsmail-juce-filter-bypass(10657) + + + SECTRACK + 1005650 + + Gordano Messaging Server (GMS) Mail 8 (a.k.a. NTMail) only filters email messages for the first recipient, which allows remote attackers to bypass JUCE filters by sending a message to more than one user on the GMS server. + + + + + + + + + + + cpe:/a:qnx:neutrino_rtos:6.2.0 + cpe:/a:qnx:neutrino_rtos:6.1.0 + cpe:/a:qnx:photon_microgui + + CVE-2002-2409 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.053-04:00 + + + 3.5 + NETWORK + MEDIUM + SINGLE_INSTANCE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2008-01-02T10:52:00.000-05:00 + + + + + BID + 6207 + + + XF + qnx-photon-view-clipboard(10658) + + + BUGTRAQ + 20021119 Clipboard in QNX Photon + + Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID. + + + + + + + + + + cpe:/a:open_webmail:open_webmail:1.71 + cpe:/a:open_webmail:open_webmail:1.7 + + CVE-2002-2410 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.210-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2008-01-02T10:57:00.000-05:00 + + + + + BID + 6232 + + + XF + open-webmail-information-disclosure(10684) + + + BUGTRAQ + 20021119 Open WebMail 1.71 "background" magic info + + openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information. + + + + + + + + + cpe:/a:bannerwheel:bannerwheel:1.0 + + CVE-2002-2411 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.367-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T11:06:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + bannerwheel-badmin-cgi-bo(9115) + + + BID + 4782 + + + BUGTRAQ + 20020520 CAPZLOCK SECURITY ADVISORY NO. 1 + + Buffer overflow in badmin.c in BannerWheel 1.0 allows remote attackers to execute arbitrary code via a long rcmd command. + + + + + + + + + cpe:/a:nullsoft:winamp:2.80 + + CVE-2002-2412 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.507-04:00 + + + 2.1 + LOCAL + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2008-01-02T11:10:00.000-05:00 + + + + + BID + 4781 + + + XF + winamp-plaintext-password(9114) + + + BUGTRAQ + 20020519 Plain Text Password Vulnerability in Winamp 2.80 + + Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts. + + + + + + + + + + + + + + + cpe:/a:deerfield:website_pro:3.1.11.0 + + CVE-2002-2413 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.663-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T11:16:00.000-05:00 + + + + BID + 4783 + + + XF + website-pro-source-disclosure(9147) + + + BUGTRAQ + 20020519 Multiple vendors web server source code disclosure (8.3 name format vulnerability - take II) + + WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. + + + + + + + + + + cpe:/a:squid:squid:2.4 + cpe:/a:opera_software:opera:6.0.3 + + CVE-2002-2414 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.820-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2008-01-02T11:18:00.000-05:00 + + + + BID + 6218 + + + XF + opera-squid-https-dos(10673) + + + FULLDISC + 20021120 Opera 6.03/Linux crashes on HTTPS over Squid Proxy on a site + + Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash). + + + + + + + + + + cpe:/h:alliedtelesyn:rapier_24 + cpe:/h:alliedtelesyn:at-8024:1.3.1 + + CVE-2002-2415 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:09.977-04:00 + + + 6.8 + NETWORK + LOW + SINGLE_INSTANCE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2008-01-02T12:45:00.000-05:00 + + + + + BID + 6233 + + + XF + telesyn-zero-stream-dos(10680) + + + BUGTRAQ + 20021120 Allied Telesyn switches & routers vulnerability + + Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service. + + + + + + + + + cpe:/a:zeroo:http_server:1.5 + + CVE-2002-2416 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.117-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T12:47:00.000-05:00 + + + + + BID + 6308 + + + XF + zeroo-dotdot-directory-traversal(10672) + + + BUGTRAQ + 20021122 Zeroo Folder Traversal Vulnerability + + + VULNWATCH + 20021121 Zeroo Folder Traversal Vulnerability + + Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. + + + + + + + + + cpe:/a:acftp:acftp:1.4 + + CVE-2002-2417 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.273-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T12:52:00.000-05:00 + + + + + BID + 6235 + + + BUGTRAQ + 20021124 acFTP Authentication Issue + + + XF + acftp-authentication-bypass(10681) + + + SREASON + 3334 + + + VULNWATCH + 20021123 acFTP Authentication Issue + + acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges. + + + + + + + + + cpe:/a:acfp_project:acfreeproxy:1.33beta7 + + CVE-2002-2418 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.413-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T12:52:00.000-05:00 + + + + + BID + 6236 + + + XF + acfp-error-page-xss(10682) + + + SREASON + 3327 + + + BUGTRAQ + 20021124 acFreeProxy Cross-Site Scripting Vulnerability/Possible DoS + + + VULNWATCH + 20021123 acFreeProxy Cross-Site Scripting Vulnerability/Possible DoS + + Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page. + + + + + + + + + cpe:/a:dctc_project:dctc:0.83.3 + + CVE-2002-2419 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.570-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2008-01-02T13:01:00.000-05:00 + + + + + BID + 5781 + + + XF + dctc-null-byte-dos(10181) + + Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character. + + + + + + + + + + cpe:/a:independent_solution:simple_site_searcher + cpe:/a:independent_solution:super_site_searcher + + CVE-2002-2420 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.710-04:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2008-01-02T13:07:00.000-05:00 + + + + + BID + 5605 + + + SECTRACK + 1005190 + + site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. + + + + + + + + + cpe:/a:andrey_cherezov:acweb:1.14 + + CVE-2002-2421 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:10.867-04:00 + + + 7.8 + NETWORK + LOW + NONE + NONE + NONE + COMPLETE + http://nvd.nist.gov + 2008-01-02T13:07:00.000-05:00 + + + + + XF + acweb-device-name-dos(10190) + + + BUGTRAQ + 20020925 IIL Advisory: Vulnerabilities in acWEB HTTP server + + acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2. + + + + + + + + + + + + + + cpe:/a:compaq:insight_management_agent:2.1 + cpe:/a:compaq:insight_management_agent:2.0 + cpe:/a:compaq:insight_management_agent:4.37 + cpe:/a:compaq:insight_management_agent:4.2 + cpe:/a:compaq:insight_management_agent:2.1_b + cpe:/a:compaq:insight_management_agent:3.6.0 + + CVE-2002-2422 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:11.023-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T13:14:00.000-05:00 + + + + + BID + 5780 + + + MISC + http://www.securiteam.com/windowsntfocus/6G00K0A5SM.html + + Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message. + + + + + + + + + + + + + + + cpe:/a:sendmail:sendmail:8.12.5 + cpe:/a:sendmail:sendmail:8.12.6 + cpe:/a:sendmail:sendmail:8.12.1 + cpe:/a:sendmail:sendmail:8.12.2 + cpe:/a:sendmail:sendmail:8.12.3 + cpe:/a:sendmail:sendmail:8.12.4 + cpe:/a:sendmail:sendmail:8.12.0 + + CVE-2002-2423 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:11.177-04:00 + + + 6.4 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T13:13:00.000-05:00 + + + + + BID + 5770 + + + XF + sendmail-ident-logging-bypass(10153) + + + BUGTRAQ + 20020921 Sendmail logging and short string precision allows anonymous commands/relay + + Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response. + + + + + + + + + cpe:/a:ekilat_llc:php%28reactor%29:1.27pl1 + + CVE-2002-2424 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:11.333-04:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T13:19:00.000-05:00 + + + + + BID + 5569 + + + XF + phpreactor-style-xss(9958) + + + BUGTRAQ + 20020824 phpReactor - Cross-Site Scripting via STYLE + + Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag. + + + + + + + + + + + + + cpe:/a:sun:solaris_answerbook2:1.4 + cpe:/a:sun:solaris_answerbook2:1.3 + cpe:/a:sun:solaris_answerbook2:1.2 + cpe:/a:sun:solaris_answerbook2:1.4.2 + cpe:/a:sun:solaris_answerbook2:1.4.1 + + CVE-2002-2425 + 2002-12-31T00:00:00.000-05:00 + 2008-09-05T16:33:11.477-04:00 + + + 10.0 + NETWORK + LOW + NONE + COMPLETE + COMPLETE + COMPLETE + http://nvd.nist.gov + 2008-01-02T13:22:00.000-05:00 + + + ALLOWS_ADMIN_ACCESS + + + XF + answerbook2-admin-scripts-access(9756) + + + BID + 5383 + + + BUGTRAQ + 20020801 Sun AnswerBook2 format string and other vulnerabilities + + Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request. + + + + + + + + + + + + + + cpe:/a:citrix:presentation_server:4.0 + cpe:/a:citrix:metaframe_presentation_server:3.0 + cpe:/a:citrix:access_essentials:1.5 + cpe:/a:citrix:presentation_server:4.5 + cpe:/a:citrix:access_essentials:2.0 + cpe:/a:citrix:access_essentials:1.0 + + CVE-2002-2426 + 2002-12-31T00:00:00.000-05:00 + 2011-03-07T21:11:55.063-05:00 + + + 4.3 + NETWORK + MEDIUM + NONE + NONE + PARTIAL + NONE + http://nvd.nist.gov + 2008-01-02T13:37:00.000-05:00 + + + + + VUPEN + ADV-2007-3870 + + + SECTRACK + 1018962 + + + BID + 26451 + + + CONFIRM + http://support.citrix.com/article/CTX115245 + + + MISC + http://packetstormsecurity.org/0210-exploits/hackingcitrix.txt + + Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information. + + + + + + + + + + cpe:/a:goahead:goahead_webserver:2.1 + cpe:/a:goahead:goahead_webserver:2.0 + + CVE-2002-2427 + 2009-02-06T14:30:00.280-05:00 + 2009-07-23T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2009-02-06T15:51:00.000-05:00 + + + + + CERT-VN + VU#124059 + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#security-features-can-be-bypassed-by-adding-an-extra-slash-in-the-url-bug01518 + + The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603. + + + + + + + + + + + + + cpe:/a:goahead:goahead_webserver:2.1.1 + cpe:/a:goahead:goahead_webserver:2.1.2 + cpe:/a:goahead:goahead_webserver:2.1.3 + cpe:/a:goahead:goahead_webserver:2.1 + cpe:/a:goahead:goahead_webserver:2.0 + + CVE-2002-2428 + 2009-02-06T14:30:00.313-05:00 + 2009-07-23T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2009-02-06T16:08:00.000-05:00 + + + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#fixed-vulnerability-to-malicious-code-in-webs-c + + webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data. + + + + + + + + + + + + + cpe:/a:goahead:goahead_webserver:2.1.1 + cpe:/a:goahead:goahead_webserver:2.1.2 + cpe:/a:goahead:goahead_webserver:2.1.3 + cpe:/a:goahead:goahead_webserver:2.1 + cpe:/a:goahead:goahead_webserver:2.0 + + CVE-2002-2429 + 2009-02-06T14:30:00.327-05:00 + 2009-02-06T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2009-02-06T16:14:00.000-05:00 + + + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#fixed-vulnerability-to-malicious-code-in-webs-c + + webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header. + + + + + + + + + + cpe:/a:goahead:goahead_webserver:2.1 + cpe:/a:goahead:goahead_webserver:2.0 + + CVE-2002-2430 + 2009-02-06T14:30:00.343-05:00 + 2009-02-06T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2009-02-06T16:16:00.000-05:00 + + + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#cpu-utilization-hangs-at-100-on-a-socket-disconnect-bug01865 + + GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server. + + + + + + + + + + + + + cpe:/a:goahead:goahead_webserver:2.1.1 + cpe:/a:goahead:goahead_webserver:2.1.2 + cpe:/a:goahead:goahead_webserver:2.1.3 + cpe:/a:goahead:goahead_webserver:2.1 + cpe:/a:goahead:goahead_webserver:2.0 + + CVE-2002-2431 + 2009-02-06T14:30:00.377-05:00 + 2009-02-09T00:00:00.000-05:00 + + + 7.5 + NETWORK + LOW + NONE + PARTIAL + PARTIAL + PARTIAL + http://nvd.nist.gov + 2009-02-09T09:03:00.000-05:00 + + + + CONFIRM + http://data.goahead.com/Software/Webserver/2.1.8/release.htm#fixed-vulnerability-to-malicious-code-in-sockgen-c + + Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c. + + + + + + + + + + + + + + + + + + + + + cpe:/a:novell:netware_ftp_server:5.01w + cpe:/o:novell:netware + cpe:/a:novell:netware_ftp_server:5.02b + cpe:/a:novell:netware_ftp_server:5.01y + cpe:/a:novell:netware_ftp_server:5.02r + cpe:/a:novell:netware_ftp_server:5.01i + cpe:/a:novell:netware_ftp_server:5.02y + cpe:/a:novell:netware_ftp_server:5.01o + cpe:/a:novell:netware_ftp_server:5.02i + + CVE-2002-2432 + 2010-04-05T11:30:00.563-04:00 + 2010-04-05T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2010-04-05T14:44:00.000-04:00 + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username. + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:novell:netware_ftp_server:5.01w + cpe:/a:novell:netware_ftp_server:5.02b + cpe:/a:novell:netware_ftp_server:5.01y + cpe:/a:novell:netware_ftp_server:5.02r + cpe:/a:novell:netware_ftp_server:5.01i + cpe:/o:novell:netware:6.5 + cpe:/a:novell:netware_ftp_server:5.02y + cpe:/a:novell:netware_ftp_server:5.01o + cpe:/a:novell:netware_ftp_server:5.02i + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-2433 + 2010-04-05T11:30:00.593-04:00 + 2010-06-08T00:00:00.000-04:00 + + + 4.0 + NETWORK + LOW + SINGLE_INSTANCE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2010-04-05T16:11:00.000-04:00 + + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command. + + + + + + + + + + + + + + + + + + + + cpe:/a:novell:netware_ftp_server:5.01w + cpe:/a:novell:netware_ftp_server:5.02b + cpe:/a:novell:netware_ftp_server:5.01y + cpe:/a:novell:netware_ftp_server:5.01i + cpe:/o:novell:netware:6.5 + cpe:/a:novell:netware_ftp_server:5.01o + cpe:/o:novell:netware:6.0 + cpe:/o:novell:netware:5.1 + + CVE-2002-2434 + 2010-04-05T11:30:00.627-04:00 + 2010-06-08T00:00:00.000-04:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2010-04-05T16:15:00.000-04:00 + + + + CONFIRM + http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1 + + NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:microsoft:ie:5.5:sp1 + cpe:/a:microsoft:ie:5.5:sp2 + cpe:/a:microsoft:ie:6.0.2900.2180 + cpe:/a:microsoft:ie:5.00.2314.1003 + cpe:/a:microsoft:ie:5.00.3314.2101 + cpe:/a:microsoft:ie:7.00.6000.16441 + cpe:/a:microsoft:ie:6.00.2900.2180 + cpe:/a:microsoft:ie:5.00.3700.1000 + cpe:/a:microsoft:ie:4.71.544 + cpe:/a:microsoft:ie:8.0.6001:beta + cpe:/a:microsoft:ie:5.5:preview + cpe:/a:microsoft:ie:5.00.2920.0000 + cpe:/a:microsoft:ie:5.50.4522.1800 + cpe:/a:microsoft:ie:5.0.1 + cpe:/a:microsoft:ie:5.00.2014.0216 + cpe:/a:microsoft:ie:8.0.6001 + cpe:/a:microsoft:ie:5.00.2614.3500 + cpe:/a:microsoft:ie:6.00.2800.1106 + cpe:/a:microsoft:ie:5.50.4030.2400 + cpe:/a:microsoft:ie:4.72.2106.8 + cpe:/a:microsoft:ie:5.00.3502.1000 + cpe:/a:microsoft:ie:4.1 + cpe:/a:microsoft:ie:4.0 + cpe:/a:microsoft:ie:3.0.2 + cpe:/a:microsoft:ie:5.50.4308.2900 + cpe:/a:microsoft:ie:3.0.1 + cpe:/a:microsoft:ie:4.5 + cpe:/a:microsoft:ie:4.70.1155 + cpe:/a:microsoft:ie:7.00.5730.1100 + cpe:/a:microsoft:ie:6.0.2800.1106 + cpe:/a:microsoft:ie:6.00.3790.0000 + cpe:/a:microsoft:ie:4.70.1158 + cpe:/a:microsoft:ie:7.00.6000.16386 + cpe:/a:microsoft:ie:6.0.2900 + cpe:/a:microsoft:ie:5 + cpe:/a:microsoft:ie:6.00.3790.1830 + cpe:/a:microsoft:ie:6.0.2800 + cpe:/a:microsoft:ie:5.0.1:sp4 + cpe:/a:microsoft:ie:5.01:sp3 + cpe:/a:microsoft:ie:5.00.2919.6307 + cpe:/a:microsoft:ie:7.0:beta2 + cpe:/a:microsoft:ie:5.0.1:sp3 + cpe:/a:microsoft:ie:5.01:sp4 + cpe:/a:microsoft:ie:7.0:beta1 + cpe:/a:microsoft:ie:6 + cpe:/a:microsoft:ie:7 + cpe:/a:microsoft:ie:7.0:beta3 + cpe:/a:microsoft:ie:8 + cpe:/a:microsoft:ie:5.00.2516.1900 + cpe:/a:microsoft:ie:4.70.1215 + cpe:/a:microsoft:ie:5.00.3103.1000 + cpe:/a:microsoft:ie:5.0.1:sp2 + cpe:/a:microsoft:ie:5.01:sp1 + cpe:/a:microsoft:ie:5.0.1:sp1 + cpe:/a:microsoft:ie:5.01 + cpe:/a:microsoft:ie:5.01:sp2 + cpe:/a:microsoft:ie:8.0b + cpe:/a:microsoft:ie:6:sp1 + cpe:/a:microsoft:ie:5.00.2919.800 + cpe:/a:microsoft:ie:4.0.1 + cpe:/a:microsoft:ie:8.0.7600.16385 + cpe:/a:microsoft:ie:4.71.1712.6 + cpe:/a:microsoft:ie:5.50.3825.1300 + cpe:/a:microsoft:ie:7.0.5730.11 + cpe:/a:microsoft:ie:4.72.3110.8 + cpe:/a:microsoft:ie:6.00.3790.3959 + cpe:/a:microsoft:ie:4.72.3612.1713 + cpe:/a:microsoft:ie:4.71.1008.3 + cpe:/a:microsoft:ie:5.00.3105.0106 + cpe:/a:microsoft:ie:5.5 + cpe:/a:microsoft:ie:5.00.3315.1000 + cpe:/a:microsoft:ie:5.50.4807.2300 + cpe:/a:microsoft:ie:5.0 + cpe:/a:microsoft:ie:5.1 + cpe:/a:microsoft:ie:5.2.3 + cpe:/a:microsoft:ie:4.40.520 + cpe:/a:microsoft:ie:7.0:beta + cpe:/a:microsoft:ie:6.00.2600.0000 + cpe:/a:microsoft:ie:4.40.308 + cpe:/a:microsoft:ie:6.00.3718.0000 + cpe:/a:microsoft:ie:3.1 + cpe:/a:microsoft:ie:6.0.2600 + cpe:/a:microsoft:ie:3.2 + cpe:/a:microsoft:ie:7.0 + cpe:/a:microsoft:ie:3.0 + cpe:/a:microsoft:ie:4.01:sp1 + cpe:/a:microsoft:ie:4.70.1300 + cpe:/a:microsoft:ie:7.0.6000.16711 + cpe:/a:microsoft:ie:6.0 + cpe:/a:microsoft:ie:4.0.1:sp2 + cpe:/a:microsoft:ie:4.0.1:sp1 + cpe:/a:microsoft:ie:5.50.4134.0100 + cpe:/a:microsoft:ie:5.50.4134.0600 + cpe:/a:microsoft:ie:5.00.0910.1309 + cpe:/a:microsoft:ie:7.0.5730:unknown:gold + cpe:/a:microsoft:ie:5.00.2919.3800 + cpe:/a:microsoft:ie:6.00.3663.0000 + cpe:/a:microsoft:ie:6.00.2479.0006 + cpe:/a:microsoft:ie:4.01 + cpe:/a:microsoft:ie:6.00.2462.0000 + cpe:/a:microsoft:ie:5.00.0518.10 + + CVE-2002-2435 + 2011-12-07T14:55:00.987-05:00 + 2012-02-14T21:18:15.337-05:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2011-12-08T06:47:00.000-05:00 + + + + + XF + ms-ie-css-info-disc(71817) + + + MISC + http://w2spconf.com/2010/papers/p26.pdf + + + MISC + http://bugzilla.mozilla.org/show_bug.cgi?id=147777 + + The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:seamonkey:1.0 + cpe:/a:mozilla:seamonkey:1.1 + cpe:/a:mozilla:seamonkey:2.0.1 + cpe:/a:mozilla:thunderbird:3.0.8 + cpe:/a:mozilla:seamonkey:2.0.2 + cpe:/a:mozilla:seamonkey:2.0.3 + cpe:/a:mozilla:thunderbird:3.0.9 + cpe:/a:mozilla:seamonkey:2.0.4 + cpe:/a:mozilla:thunderbird:3.0.6 + cpe:/a:mozilla:thunderbird:3.0.7 + cpe:/a:mozilla:seamonkey:2.0.5 + cpe:/a:mozilla:thunderbird:3.0.4 + cpe:/a:mozilla:seamonkey:2.0.6 + cpe:/a:mozilla:seamonkey:2.0.7 + cpe:/a:mozilla:thunderbird:3.0.5 + cpe:/a:mozilla:thunderbird:3.0.3 + cpe:/a:mozilla:thunderbird:3.0.2 + cpe:/a:mozilla:thunderbird:3.0.1 + cpe:/a:mozilla:seamonkey:2.0 + cpe:/a:mozilla:thunderbird:3.0.11 + cpe:/a:mozilla:thunderbird:3.0.10 + cpe:/a:mozilla:seamonkey:2.0:beta_2 + cpe:/a:mozilla:seamonkey:2.0:beta_1 + cpe:/a:mozilla:seamonkey:1.1:alpha + cpe:/a:mozilla:seamonkey:1.0:alpha + cpe:/a:mozilla:firefox:3.0.8 + cpe:/a:mozilla:firefox:3.0.9 + cpe:/a:mozilla:firefox:3.0.6 + cpe:/a:mozilla:firefox:3.0.7 + cpe:/a:mozilla:seamonkey:1.5.0.9 + cpe:/a:mozilla:firefox:3.0.4 + cpe:/a:mozilla:seamonkey:1.5.0.8 + cpe:/a:mozilla:firefox:3.0.5 + cpe:/a:mozilla:firefox:3.0.2 + cpe:/a:mozilla:firefox:3.0.3 + cpe:/a:mozilla:firefox:3.0.1 + cpe:/a:mozilla:firefox:3.6.15 + cpe:/a:mozilla:firefox:3.6.16 + cpe:/a:mozilla:firefox:3.5 + cpe:/a:mozilla:firefox:3.6.17 + cpe:/a:mozilla:firefox:3.6.18 + cpe:/a:mozilla:firefox:3.6.19 + cpe:/a:mozilla:firefox:3.6 + cpe:/a:mozilla:seamonkey:2.0a1::pre + cpe:/a:mozilla:seamonkey:2.0:alpha_3 + cpe:/a:mozilla:seamonkey:2.0:alpha_1 + cpe:/a:mozilla:seamonkey:2.0:alpha_2 + cpe:/a:mozilla:firefox:3.5.8 + cpe:/a:mozilla:firefox:3.5.7 + cpe:/a:mozilla:firefox:3.6.1 + cpe:/a:mozilla:firefox:3.5.9 + cpe:/a:mozilla:firefox:3.5.4 + cpe:/a:mozilla:firefox:3.5.3 + cpe:/a:mozilla:seamonkey:2.0.9 + cpe:/a:mozilla:firefox:3.5.6 + cpe:/a:mozilla:seamonkey:2.0.8 + cpe:/a:mozilla:firefox:3.5.5 + cpe:/a:mozilla:firefox:3.6.7 + cpe:/a:mozilla:firefox:3.6.6 + cpe:/a:mozilla:firefox:3.5.2 + cpe:/a:mozilla:firefox:3.6.10 + cpe:/a:mozilla:firefox:3.6.9 + cpe:/a:mozilla:firefox:3.6.8 + cpe:/a:mozilla:firefox:3.5.1 + cpe:/a:mozilla:firefox:3.6.12 + cpe:/a:mozilla:firefox:3.6.3 + cpe:/a:mozilla:firefox:3.6.11 + cpe:/a:mozilla:firefox:3.6.2 + cpe:/a:mozilla:firefox:3.0 + cpe:/a:mozilla:firefox:3.6.14 + cpe:/a:mozilla:firefox:3.6.4 + cpe:/a:mozilla:firefox:3.6.13 + cpe:/a:mozilla:seamonkey:1.5.0.10 + cpe:/a:mozilla:seamonkey:1.1.16 + cpe:/a:mozilla:thunderbird:3.1.6 + cpe:/a:mozilla:seamonkey:1.1.15 + cpe:/a:mozilla:thunderbird:3.1.5 + cpe:/a:mozilla:seamonkey:1.1.18 + cpe:/a:mozilla:thunderbird:3.1.4 + cpe:/a:mozilla:seamonkey:1.1.17 + cpe:/a:mozilla:thunderbird:3.1.3 + cpe:/a:mozilla:seamonkey:1.1.19 + cpe:/a:mozilla:thunderbird:3.1.9 + cpe:/a:mozilla:thunderbird:3.1.8 + cpe:/a:mozilla:thunderbird:3.1.7 + cpe:/a:mozilla:seamonkey:2.0:rc2 + cpe:/a:mozilla:firefox:3.6.24 + cpe:/a:mozilla:seamonkey:2.0:rc1 + cpe:/a:mozilla:firefox:3.6.22 + cpe:/a:mozilla:firefox:3.6.23 + cpe:/a:mozilla:firefox:3.6.20 + cpe:/a:mozilla:thunderbird:3.1.1 + cpe:/a:mozilla:firefox:3.6.21 + cpe:/a:mozilla:thunderbird:3.1.2 + cpe:/a:mozilla:thunderbird:3.0 + cpe:/a:mozilla:thunderbird:3.1 + cpe:/a:mozilla:seamonkey:1.1:beta + cpe:/a:mozilla:seamonkey:1.0:beta + cpe:/a:mozilla:seamonkey:1.0.3 + cpe:/a:mozilla:seamonkey:1.0.4 + cpe:/a:mozilla:seamonkey:1.1.10 + cpe:/a:mozilla:seamonkey:1.0.1 + cpe:/a:mozilla:seamonkey:1.0.2 + cpe:/a:mozilla:seamonkey:1.1.13 + cpe:/a:mozilla:seamonkey:1.0.7 + cpe:/a:mozilla:seamonkey:1.0.8 + cpe:/a:mozilla:seamonkey:1.1.14 + cpe:/a:mozilla:seamonkey:1.0.5 + cpe:/a:mozilla:seamonkey:1.1.11 + cpe:/a:mozilla:seamonkey:1.0.6 + cpe:/a:mozilla:seamonkey:1.1.12 + cpe:/a:mozilla:seamonkey:1.1.9 + cpe:/a:mozilla:seamonkey:1.1.8 + cpe:/a:mozilla:firefox:3.5.10 + cpe:/a:mozilla:firefox:3.5.11 + cpe:/a:mozilla:firefox:3.5.12 + cpe:/a:mozilla:firefox:3.5.13 + cpe:/a:mozilla:seamonkey:1.0.9 + cpe:/a:mozilla:seamonkey:2.1:alpha1 + cpe:/a:mozilla:firefox:3.5.15 + cpe:/a:mozilla:firefox:3.0.17 + cpe:/a:mozilla:firefox:3.5.14 + cpe:/a:mozilla:seamonkey:1.1.1 + cpe:/a:mozilla:firefox:3.0.13 + cpe:/a:mozilla:firefox:3.0.14 + cpe:/a:mozilla:seamonkey:1.1.3 + cpe:/a:mozilla:firefox:3.0.15 + cpe:/a:mozilla:seamonkey:1.1.2 + cpe:/a:mozilla:seamonkey:2.0.10 + cpe:/a:mozilla:firefox:3.0.16 + cpe:/a:mozilla:seamonkey:1.1.5 + cpe:/a:mozilla:seamonkey:2.0.11 + cpe:/a:mozilla:seamonkey:1.1.4 + cpe:/a:mozilla:seamonkey:2.1:alpha2 + cpe:/a:mozilla:firefox:3.0.10 + cpe:/a:mozilla:seamonkey:2.0.12 + cpe:/a:mozilla:seamonkey:1.1.7 + cpe:/a:mozilla:firefox:3.0.11 + cpe:/a:mozilla:seamonkey:2.1:alpha3 + cpe:/a:mozilla:seamonkey:2.0.13 + cpe:/a:mozilla:seamonkey:1.1.6 + cpe:/a:mozilla:firefox:3.0.12 + cpe:/a:mozilla:seamonkey:2.0.14 + cpe:/a:mozilla:thunderbird:3.1.16 + cpe:/a:mozilla:thunderbird:3.1.14 + cpe:/a:mozilla:thunderbird:3.1.15 + cpe:/a:mozilla:thunderbird:3.1.13 + cpe:/a:mozilla:thunderbird:3.1.12 + cpe:/a:mozilla:thunderbird:3.1.11 + cpe:/a:mozilla:thunderbird:3.1.10 + + CVE-2002-2436 + 2011-12-07T14:55:01.237-05:00 + 2012-02-14T21:18:15.683-05:00 + + + 4.3 + NETWORK + MEDIUM + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2011-12-08T06:57:00.000-05:00 + + + + + CONFIRM + https://developer.mozilla.org/en/CSS/Privacy_and_the_:visited_selector + + + XF + firefox-css-info-disclosure(71816) + + + MISC + http://w2spconf.com/2010/papers/p26.pdf + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=147777 + + + CONFIRM + http://blog.mozilla.com/security/2010/03/31/plugging-the-css-history-leak/ + + The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + cpe:/a:mozilla:seamonkey:1.0 + cpe:/a:mozilla:seamonkey:1.1 + cpe:/a:mozilla:seamonkey:2.0.1 + cpe:/a:mozilla:thunderbird:3.0.8 + cpe:/a:mozilla:seamonkey:2.0.2 + cpe:/a:mozilla:seamonkey:2.0.3 + cpe:/a:mozilla:thunderbird:3.0.9 + cpe:/a:mozilla:seamonkey:2.0.4 + cpe:/a:mozilla:thunderbird:3.0.6 + cpe:/a:mozilla:thunderbird:3.0.7 + cpe:/a:mozilla:seamonkey:2.0.5 + cpe:/a:mozilla:thunderbird:3.0.4 + cpe:/a:mozilla:seamonkey:2.0.6 + cpe:/a:mozilla:seamonkey:2.0.7 + cpe:/a:mozilla:thunderbird:3.0.5 + cpe:/a:mozilla:thunderbird:3.0.3 + cpe:/a:mozilla:thunderbird:3.0.2 + cpe:/a:mozilla:thunderbird:3.0.1 + cpe:/a:mozilla:seamonkey:2.0 + cpe:/a:mozilla:thunderbird:3.0.11 + cpe:/a:mozilla:thunderbird:3.0.10 + cpe:/a:mozilla:seamonkey:2.0:beta_2 + cpe:/a:mozilla:seamonkey:2.0:beta_1 + cpe:/a:mozilla:seamonkey:1.1:alpha + cpe:/a:mozilla:seamonkey:1.0:alpha + cpe:/a:mozilla:firefox:3.0.8 + cpe:/a:mozilla:firefox:3.0.9 + cpe:/a:mozilla:firefox:3.0.6 + cpe:/a:mozilla:firefox:3.0.7 + cpe:/a:mozilla:seamonkey:1.5.0.9 + cpe:/a:mozilla:firefox:3.0.4 + cpe:/a:mozilla:seamonkey:1.5.0.8 + cpe:/a:mozilla:firefox:3.0.5 + cpe:/a:mozilla:firefox:3.0.2 + cpe:/a:mozilla:firefox:3.0.3 + cpe:/a:mozilla:firefox:3.0.1 + cpe:/a:mozilla:firefox:3.6.15 + cpe:/a:mozilla:firefox:3.6.16 + cpe:/a:mozilla:firefox:3.5 + cpe:/a:mozilla:firefox:3.6.17 + cpe:/a:mozilla:firefox:3.6.18 + cpe:/a:mozilla:firefox:3.6.19 + cpe:/a:mozilla:firefox:3.6 + cpe:/a:mozilla:seamonkey:2.0a1::pre + cpe:/a:mozilla:seamonkey:2.0:alpha_3 + cpe:/a:mozilla:seamonkey:2.0:alpha_1 + cpe:/a:mozilla:seamonkey:2.0:alpha_2 + cpe:/a:mozilla:firefox:3.5.8 + cpe:/a:mozilla:firefox:3.5.7 + cpe:/a:mozilla:firefox:3.6.1 + cpe:/a:mozilla:firefox:3.5.9 + cpe:/a:mozilla:firefox:3.5.4 + cpe:/a:mozilla:firefox:3.5.3 + cpe:/a:mozilla:seamonkey:2.0.9 + cpe:/a:mozilla:firefox:3.5.6 + cpe:/a:mozilla:seamonkey:2.0.8 + cpe:/a:mozilla:firefox:3.5.5 + cpe:/a:mozilla:firefox:3.6.7 + cpe:/a:mozilla:firefox:3.6.6 + cpe:/a:mozilla:firefox:3.5.2 + cpe:/a:mozilla:firefox:3.6.10 + cpe:/a:mozilla:firefox:3.6.9 + cpe:/a:mozilla:firefox:3.6.8 + cpe:/a:mozilla:firefox:3.5.1 + cpe:/a:mozilla:firefox:3.6.12 + cpe:/a:mozilla:firefox:3.6.3 + cpe:/a:mozilla:firefox:3.6.11 + cpe:/a:mozilla:firefox:3.6.2 + cpe:/a:mozilla:firefox:3.0 + cpe:/a:mozilla:firefox:3.6.14 + cpe:/a:mozilla:firefox:3.6.4 + cpe:/a:mozilla:firefox:3.6.13 + cpe:/a:mozilla:seamonkey:1.5.0.10 + cpe:/a:mozilla:seamonkey:1.1.16 + cpe:/a:mozilla:thunderbird:3.1.6 + cpe:/a:mozilla:seamonkey:1.1.15 + cpe:/a:mozilla:thunderbird:3.1.5 + cpe:/a:mozilla:seamonkey:1.1.18 + cpe:/a:mozilla:thunderbird:3.1.4 + cpe:/a:mozilla:seamonkey:1.1.17 + cpe:/a:mozilla:thunderbird:3.1.3 + cpe:/a:mozilla:seamonkey:1.1.19 + cpe:/a:mozilla:thunderbird:3.1.9 + cpe:/a:mozilla:thunderbird:3.1.8 + cpe:/a:mozilla:thunderbird:3.1.7 + cpe:/a:mozilla:seamonkey:2.0:rc2 + cpe:/a:mozilla:firefox:3.6.24 + cpe:/a:mozilla:seamonkey:2.0:rc1 + cpe:/a:mozilla:firefox:3.6.22 + cpe:/a:mozilla:firefox:3.6.23 + cpe:/a:mozilla:firefox:3.6.20 + cpe:/a:mozilla:thunderbird:3.1.1 + cpe:/a:mozilla:firefox:3.6.21 + cpe:/a:mozilla:thunderbird:3.1.2 + cpe:/a:mozilla:thunderbird:3.0 + cpe:/a:mozilla:thunderbird:3.1 + cpe:/a:mozilla:seamonkey:1.1:beta + cpe:/a:mozilla:seamonkey:1.0:beta + cpe:/a:mozilla:seamonkey:1.0.3 + cpe:/a:mozilla:seamonkey:1.0.4 + cpe:/a:mozilla:seamonkey:1.1.10 + cpe:/a:mozilla:seamonkey:1.0.1 + cpe:/a:mozilla:seamonkey:1.0.2 + cpe:/a:mozilla:seamonkey:1.1.13 + cpe:/a:mozilla:seamonkey:1.0.7 + cpe:/a:mozilla:seamonkey:1.0.8 + cpe:/a:mozilla:seamonkey:1.1.14 + cpe:/a:mozilla:seamonkey:1.0.5 + cpe:/a:mozilla:seamonkey:1.1.11 + cpe:/a:mozilla:seamonkey:1.0.6 + cpe:/a:mozilla:seamonkey:1.1.12 + cpe:/a:mozilla:seamonkey:1.1.9 + cpe:/a:mozilla:seamonkey:1.1.8 + cpe:/a:mozilla:firefox:3.5.10 + cpe:/a:mozilla:firefox:3.5.11 + cpe:/a:mozilla:firefox:3.5.12 + cpe:/a:mozilla:firefox:3.5.13 + cpe:/a:mozilla:seamonkey:1.0.9 + cpe:/a:mozilla:seamonkey:2.1:alpha1 + cpe:/a:mozilla:firefox:3.5.15 + cpe:/a:mozilla:firefox:3.0.17 + cpe:/a:mozilla:firefox:3.5.14 + cpe:/a:mozilla:seamonkey:1.1.1 + cpe:/a:mozilla:firefox:3.0.13 + cpe:/a:mozilla:firefox:3.0.14 + cpe:/a:mozilla:seamonkey:1.1.3 + cpe:/a:mozilla:firefox:3.0.15 + cpe:/a:mozilla:seamonkey:1.1.2 + cpe:/a:mozilla:seamonkey:2.0.10 + cpe:/a:mozilla:firefox:3.0.16 + cpe:/a:mozilla:seamonkey:1.1.5 + cpe:/a:mozilla:seamonkey:2.0.11 + cpe:/a:mozilla:seamonkey:1.1.4 + cpe:/a:mozilla:seamonkey:2.1:alpha2 + cpe:/a:mozilla:firefox:3.0.10 + cpe:/a:mozilla:seamonkey:2.0.12 + cpe:/a:mozilla:seamonkey:1.1.7 + cpe:/a:mozilla:firefox:3.0.11 + cpe:/a:mozilla:seamonkey:2.1:alpha3 + cpe:/a:mozilla:seamonkey:2.0.13 + cpe:/a:mozilla:seamonkey:1.1.6 + cpe:/a:mozilla:firefox:3.0.12 + cpe:/a:mozilla:seamonkey:2.0.14 + cpe:/a:mozilla:thunderbird:3.1.16 + cpe:/a:mozilla:thunderbird:3.1.14 + cpe:/a:mozilla:thunderbird:3.1.15 + cpe:/a:mozilla:thunderbird:3.1.13 + cpe:/a:mozilla:thunderbird:3.1.12 + cpe:/a:mozilla:thunderbird:3.1.11 + cpe:/a:mozilla:thunderbird:3.1.10 + + CVE-2002-2437 + 2011-12-07T14:55:01.283-05:00 + 2012-03-08T00:00:00.000-05:00 + + + 5.0 + NETWORK + LOW + NONE + PARTIAL + NONE + NONE + http://nvd.nist.gov + 2011-12-08T07:08:00.000-05:00 + + + + + CONFIRM + https://developer.mozilla.org/en/CSS/Privacy_and_the_:visited_selector + + + MISC + http://w2spconf.com/2010/papers/p26.pdf + + + CONFIRM + http://bugzilla.mozilla.org/show_bug.cgi?id=147777 + + + CONFIRM + http://blog.mozilla.com/security/2010/03/31/plugging-the-css-history-leak/ + + The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. + + + + + + + + + cpe:/a:mit:kerberos:5-1.11.2 + + CVE-2002-2443 + 2013-05-29T10:29:06.287-04:00 + 2013-12-12T21:28:39.137-05:00 + + + 5.0 + NETWORK + LOW + NONE + NONE + NONE + PARTIAL + http://nvd.nist.gov + 2013-05-29T13:05:00.000-04:00 + + + + + CONFIRM + https://github.com/krb5/krb5/commit/cf1a0c411b2668c57c41e9c4efd15ba17b6b322c + + + CONFIRM + https://bugzilla.redhat.com/show_bug.cgi?id=962531 + + + MANDRIVA + MDVSA-2013:166 + + + DEBIAN + DSA-2701 + + + REDHAT + RHSA-2013:0942 + + + SUSE + openSUSE-SU-2013:1122 + + + SUSE + openSUSE-SU-2013:1119 + + + FEDORA + FEDORA-2013-8113 + + + FEDORA + FEDORA-2013-8219 + + + FEDORA + FEDORA-2013-8212 + + + CONFIRM + http://krbdev.mit.edu/rt/Ticket/Display.html?id=7637 + + schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103. + + \ No newline at end of file