Unknown · CVSS Not scored
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.
Published Sep 18, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.
Published Sep 1, 2004 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The rwho/rwhod service is running, which exposes machine status and user information.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A version of rusers is running that exposes valid user information to any entity on the network.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A version of finger is running that exposes valid user information to any entity on the network.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in "poll" in OpenBSD.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in WinGate proxy through a buffer overflow in POP3.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in OpenBSD ping.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
OpenBSD kernel crash through TSS handling, as caused by the crashme program.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Local users can gain privileges using the debug utility in the MPE/iX operating system.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can perform a denial of service using IRIX fcagent.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris ff.core allows local users to modify files.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.
Published Sep 29, 1999 · Updated Aug 1, 2024