N/A
The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
2.4%
1999-12-08
N/A
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
4.6%
1999-12-08
N/A
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
0.1%
1999-12-07
N/A
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
7.3%
1999-12-07
N/A
Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.
6.4%
1999-12-06
N/A
Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.
7.0%
1999-12-06
N/A
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
0.1%
1999-12-05
N/A
The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.
0.1%
1999-12-05
N/A
UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
0.4%
1999-12-04
N/A
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
0.7%
1999-12-03
N/A
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
0.4%
1999-12-03
N/A
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
0.2%
1999-12-03
N/A
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
0.6%
1999-12-03
N/A
Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.
0.6%
1999-12-03
N/A
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
0.5%
1999-12-03
N/A
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
0.3%
1999-12-03
N/A
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
0.1%
1999-12-02
N/A
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.
0.1%
1999-12-02
N/A
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.
11.9%
1999-12-02
N/A
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
0.0%
1999-12-02
N/A
The default permissions for Endymion MailMan allow local users to read email or modify files.
0.1%
1999-12-02
N/A
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
0.4%
1999-12-02
N/A
Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.
0.6%
1999-12-01
N/A
ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.
0.6%
1999-12-01
N/A
FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.
0.1%
1999-12-01
N/A
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
0.3%
1999-12-01
N/A
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
0.3%
1999-12-01
N/A
FreeBSD gdc program allows local users to modify files via a symlink attack.
0.4%
1999-12-01
N/A
login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.
0.2%
1999-12-01
N/A
Buffer overflow in FreeBSD gdc program.
1.1%
1999-12-01
N/A
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.
0.9%
1999-12-01
N/A
Denial of service in MDaemon 2.7 via a large number of connection attempts.
0.5%
1999-12-01
N/A
Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.
6.4%
1999-12-01
N/A
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
3.2%
1999-12-01
N/A
Buffer overflow in FreeBSD angband allows local users to gain privileges.
0.4%
1999-12-01
N/A
Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.
0.4%
1999-12-01
N/A
FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.
0.9%
1999-12-01
N/A
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
56.5%
1999-12-01
N/A
Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.
0.3%
1999-11-30
N/A
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
0.2%
1999-11-30
N/A
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
0.3%
1999-11-30
N/A
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
7.2%
1999-11-30
N/A
Buffer overflow in free internet chess server (FICS) program, xboard.
0.5%
1999-11-29
N/A
Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.
3.8%
1999-11-29
N/A
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
0.8%
1999-11-29
N/A
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.
19.4%
1999-11-29
N/A
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.
0.6%
1999-11-25
N/A
Buffer overflow in SCO su program allows local users to gain root access via a long username.
0.2%
1999-11-25
N/A
Buffer overflow in Linux su command gives root access to local users.
0.2%
1999-11-25
N/A
Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.
0.5%
1999-11-24