Unknown · CVSS Not scored
Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
wwwboard allows a remote attacker to delete message board articles via a malformed argument.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Cisco Cache Engine allows an attacker to replace content in the cache.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in AIX ftpd in the libc library.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Solaris dtprintinfo program.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.
Published Mar 9, 2002 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Dosemu Slang library in Linux.
Published Mar 22, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Published Mar 22, 2000 · Updated Aug 1, 2024