<?xml version="1.0"?>
<cve xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
     xmlns="http://cve.mitre.org/cve/downloads"
     xsi:noNamespaceSchemaLocation="http://cve.mitre.org/schema/cve/cve_1.0.xsd">
<item type="CVE" name="CVE-1999-0002" seq="1999-0002">
<status>Entry</status>
<desc>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
<ref source="CERT">CA-98.12.mountd</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/121">121</ref>
<ref source="XF">linux-mountd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0003" seq="1999-0003">
<status>Entry</status>
<desc>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</desc>
<refs>
<ref source="NAI">NAI-29</ref>
<ref source="CERT">CA-98.11.tooltalk</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
<ref source="XF">aix-ttdbserver</ref>
<ref source="XF">tooltalk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0005" seq="1999-0005">
<status>Entry</status>
<desc>Arbitrary command execution via IMAP buffer overflow in authenticate command.</desc>
<refs>
<ref source="CERT">CA-98.09.imapd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
<ref source="XF">imap-authenticate-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0006" seq="1999-0006">
<status>Entry</status>
<desc>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</desc>
<refs>
<ref source="CERT">CA-98.08.qpopper_vul</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
<ref source="AUSCERT">AA-98.01</ref>
<ref source="XF">qpopper-pass-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0007" seq="1999-0007">
<status>Entry</status>
<desc>Information from SSL-encrypted sessions via PKCS #1.</desc>
<refs>
<ref source="CERT">CA-98.07.PKCS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref>
<ref source="XF">nt-ssl-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0008" seq="1999-0008">
<status>Entry</status>
<desc>Buffer overflow in NIS+, in Sun's rpc.nisd program.</desc>
<refs>
<ref source="CERT">CA-98.06.nisd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
<ref source="ISS">June10,1998</ref>
<ref source="XF">nisd-bo-check</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0009" seq="1999-0009">
<status>Entry</status>
<desc>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="XF">bind-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0010" seq="1999-0010">
<status>Entry</status>
<desc>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="XF">bind-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0011" seq="1999-0011">
<status>Entry</status>
<desc>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="XF">bind-axfr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0012" seq="1999-0012">
<status>Entry</status>
<desc>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</desc>
<refs>
<ref source="CERT">CA-98.04.Win32.WebServers</ref>
<ref source="XF">nt-web8.3</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0013" seq="1999-0013">
<status>Entry</status>
<desc>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</desc>
<refs>
<ref source="CERT">CA-98.03.ssh-agent</ref>
<ref source="NAI">NAI-24</ref>
<ref source="XF">ssh-agent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0014" seq="1999-0014">
<status>Entry</status>
<desc>Unauthorized privileged access or denial of service via dtappgather program in CDE.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
<ref source="CERT">CA-98.02.CDE</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0016" seq="1999-0016">
<status>Entry</status>
<desc>Land IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="FREEBSD">FreeBSD-SA-98:01</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/land-pub.shtml</ref>
<ref source="XF">cisco-land</ref>
<ref source="XF">land</ref>
<ref source="XF">95-verv-tcp</ref>
<ref source="XF">land-patch</ref>
<ref source="XF">ver-tcpip-sys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0017" seq="1999-0017">
<status>Entry</status>
<desc>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</desc>
<refs>
<ref source="CERT">CA-97.27.FTP_bounce</ref>
<ref source="XF">ftp-bounce</ref>
<ref source="XF">ftp-privileged-port</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0018" seq="1999-0018">
<status>Entry</status>
<desc>Buffer overflow in statd allows root privileges.</desc>
<refs>
<ref source="CERT">CA-97.26.statd</ref>
<ref source="AUSCERT">AA-97.29</ref>
<ref source="XF">statd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/127">127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0019" seq="1999-0019">
<status>Entry</status>
<desc>Delete or create a file via rpc.statd, due to invalid information.</desc>
<refs>
<ref source="CERT">CA-96.09.rpc.statd</ref>
<ref source="XF">rpc-stat</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0021" seq="1999-0021">
<status>Entry</status>
<desc>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</desc>
<refs>
<ref source="BUGTRAQ">19971010 Security flaw in Count.cgi (wwwcount)</ref>
<ref source="CERT">CA-97.24.Count_cgi</ref>
<ref source="XF">http-cgi-count</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0022" seq="1999-0022">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</desc>
<refs>
<ref source="CERT">CA-97.23.rdist</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
<ref source="XF">rdist-bo3</ref>
<ref source="XF">rdist-sept97</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0023" seq="1999-0023">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</desc>
<refs>
<ref source="CERT">CA-96.14.rdist_vul</ref>
<ref source="XF">rdist-bo</ref>
<ref source="XF">rdist-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0024" seq="1999-0024">
<status>Entry</status>
<desc>DNS cache poisoning via BIND, by predictable query IDs.</desc>
<refs>
<ref source="CERT">CA-97.22.bind</ref>
<ref source="XF">bind</ref>
<ref source="NAI">NAI-11</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0025" seq="1999-0025">
<status>Entry</status>
<desc>root privileges via buffer overflow in df command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
<ref source="AUSCERT">AA-97.19.IRIX.df.buffer.overflow.vul</ref>
<ref source="SGI">SGI:19970505-01-A</ref>
<ref source="SGI">SGI:19970505-02-PX</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0026" seq="1999-0026">
<status>Entry</status>
<desc>root privileges via buffer overflow in pset command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.20.IRIX.pset.buffer.overflow.vul</ref>
<ref source="XF">pset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0027" seq="1999-0027">
<status>Entry</status>
<desc>root privileges via buffer overflow in eject command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.21.IRIX.eject.buffer.overflow.vul</ref>
<ref source="XF">eject-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0028" seq="1999-0028">
<status>Entry</status>
<desc>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.22.IRIX.login.scheme.buffer.overflow.vul</ref>
<ref source="XF">sgi-schemebo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0029" seq="1999-0029">
<status>Entry</status>
<desc>root privileges via buffer overflow in ordist command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.23-IRIX.ordist.buffer.overflow.vul</ref>
<ref source="XF">ordist-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0031" seq="1999-0031">
<status>Entry</status>
<desc>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</desc>
<refs>
<ref source="CERT">CA-97.20.javascript</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0032" seq="1999-0032">
<status>Entry</status>
<desc>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</desc>
<refs>
<ref source="BUGTRAQ">19960813 Possible bufferoverflow condition in lpr, xterm and xload</ref>
<ref source="BUGTRAQ">19961025 Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[freebsd-security] 19961025 Vadim Kolontsov: BoS: Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[linux-security] 19961122 LSF Update#14: Vulnerability of the lpr program.</ref>
<ref source="CERT">CA-97.19.bsdlp</ref>
<ref source="AUSCERT">AA-96.12</ref>
<ref source="CIAC">H-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
<ref source="XF">bsd-lprbo2</ref>
<ref source="XF">bsd-lprbo</ref>
<ref source="XF">lpr-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0034" seq="1999-0034">
<status>Entry</status>
<desc>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</desc>
<refs>
<ref source="CERT">CA-97.17.sperl</ref>
<ref source="XF">perl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0035" seq="1999-0035">
<status>Entry</status>
<desc>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</desc>
<refs>
<ref source="XF">ftp-ftpd</ref>
<ref source="CERT">CA-97.16.ftpd</ref>
<ref source="AUSCERT">AA-97.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0036" seq="1999-0036">
<status>Entry</status>
<desc>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</desc>
<refs>
<ref source="CERT">CA-97.15.sgi_login</ref>
<ref source="AUSCERT">AA-97.12</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0037" seq="1999-0037">
<status>Entry</status>
<desc>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</desc>
<refs>
<ref source="CERT">CA-97.14.metamail</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0038" seq="1999-0038">
<status>Entry</status>
<desc>Buffer overflow in xlock program allows local users to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-97.13.xlock</ref>
<ref source="XF">xlock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0039" seq="1999-0039">
<status>Entry</status>
<desc>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</desc>
<refs>
<ref source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in</ref>
<ref source="BUGTRAQ">19970507 Re: SGI Advisory: webdist.cgi</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
<ref source="AUSCERT">AA-97.14</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
<ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0040" seq="1999-0040">
<status>Entry</status>
<desc>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.11.libXt</ref>
<ref source="XF">libXt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0041" seq="1999-0041">
<status>Entry</status>
<desc>Buffer overflow in NLS (Natural Language Service).</desc>
<refs>
<ref source="CERT">CA-97.10.nls</ref>
<ref source="XF">nls-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0042" seq="1999-0042">
<status>Entry</status>
<desc>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</desc>
<refs>
<ref source="NAI">NAI-21</ref>
<ref source="CERT">CA-97.09.imap_pop</ref>
<ref source="XF">popimap-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0043" seq="1999-0043">
<status>Entry</status>
<desc>Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</desc>
<refs>
<ref source="CERT">CA-97.08.innd</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0044" seq="1999-0044">
<status>Entry</status>
<desc>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
<ref source="XF">sgi-fsdump</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0045" seq="1999-0045">
<status>Entry</status>
<desc>List of arbitrary files on Web host via nph-test-cgi script.</desc>
<refs>
<ref source="CERT">CA-97.07.nph-test-cgi_script</ref>
<ref source="XF">http-cgi-nph</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0046" seq="1999-0046">
<status>Entry</status>
<desc>Buffer overflow of rlogin program using TERM environmental variable.</desc>
<refs>
<ref source="CERT">CA-97.06.rlogin-term</ref>
<ref source="XF">rlogin-termbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0047" seq="1999-0047">
<status>Entry</status>
<desc>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</desc>
<refs>
<ref source="CERT">CA-97.05.sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
<ref source="XF">sendmail-mime-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0048" seq="1999-0048">
<status>Entry</status>
<desc>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.04.talkd</ref>
<ref source="FREEBSD">FreeBSD-SA-96:21</ref>
<ref source="AUSCERT">AA-97.01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
<ref source="XF">talkd-bo</ref>
<ref source="XF">netkit-talkd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0049" seq="1999-0049">
<status>Entry</status>
<desc>Csetup under IRIX allows arbitrary file creation or overwriting.</desc>
<refs>
<ref source="XF">sgi-csetup</ref>
<ref source="CERT">CA-97.03.csetup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0050" seq="1999-0050">
<status>Entry</status>
<desc>Buffer overflow in HP-UX newgrp program.</desc>
<refs>
<ref source="CERT">CA-97.02.hp_newgrp</ref>
<ref source="AUSCERT">AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability</ref>
<ref source="XF">hp-newgrpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0051" seq="1999-0051">
<status>Entry</status>
<desc>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</desc>
<refs>
<ref source="XF">sgi-licensemanager</ref>
<ref source="CERT">CA-97.01.flex_lm</ref>
<ref source="AUSCERT">AA-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0052" seq="1999-0052">
<status>Entry</status>
<desc>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:08</ref>
<ref source="OSVDB" url="http://www.osvdb.org/908">908</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0053" seq="1999-0053">
<status>Entry</status>
<desc>TCP RST denial of service in FreeBSD.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:07</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0054" seq="1999-0054">
<status>Entry</status>
<desc>Sun's ftpd daemon can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
<ref source="XF">sun-ftpd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0055" seq="1999-0055">
<status>Entry</status>
<desc>Buffer overflows in Sun libnsl allow root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
<ref source="RSI">RSI.0005.05-14-98.SUN.LIBNSL</ref>
<ref source="XF">sun-libnsl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0056" seq="1999-0056">
<status>Entry</status>
<desc>Buffer overflow in Sun's ping program can give root access to local users.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
<ref source="XF">sun-ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0057" seq="1999-0057">
<status>Entry</status>
<desc>Vacation program allows command execution by remote users through a sendmail command.</desc>
<refs>
<ref source="NAI">NAI-19</ref>
<ref source="XF">vacation</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0058" seq="1999-0058">
<status>Entry</status>
<desc>Buffer overflow in PHP cgi program, php.cgi allows shell access.</desc>
<refs>
<ref source="NAI">NAI-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
<ref source="XF">http-cgi-phpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0059" seq="1999-0059">
<status>Entry</status>
<desc>IRIX fam service allows an attacker to obtain a list of all files on the server.</desc>
<refs>
<ref source="NAI">NAI-16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
<ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0060" seq="1999-0060">
<status>Entry</status>
<desc>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</desc>
<refs>
<ref source="NAI">NAI-26</ref>
<ref source="XF">ascend-config-kill</ref>
<ref source="ASCEND">http://www.ascend.com/2695.html</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0062" seq="1999-0062">
<status>Entry</status>
<desc>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</desc>
<refs>
<ref source="XF">openbsd-chpass</ref>
<ref source="NAI">NAI-28</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0063" seq="1999-0063">
<status>Entry</status>
<desc>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</desc>
<refs>
<ref source="AUSCERT">ESB-98.197</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/iossyslog-pub.shtml</ref>
<ref source="XF">cisco-syslog-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0064" seq="1999-0064">
<status>Entry</status>
<desc>Buffer overflow in AIX lquerylv program gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">May28,1997</ref>
<ref source="XF">lquerylv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0065" seq="1999-0065">
<status>Entry</status>
<desc>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
<ref source="XF">hp-dtmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0066" seq="1999-0066">
<status>Entry</status>
<desc>AnyForm CGI remote execution.</desc>
<refs>
<ref source="BUGTRAQ">19950731 SECURITY HOLE: &quot;AnyForm&quot; CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
<ref source="XF">http-cgi-anyform</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0067" seq="1999-0067">
<status>Entry</status>
<desc>phf CGI program allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19960923 PHF Attacks - Fun and games for the whole family</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
<ref source="AUSCERT">AA-96.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
<ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
<ref source="XF">http-cgi-phf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0068" seq="1999-0068">
<status>Entry</status>
<desc>CGI PHP mylog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="XF">http-cgi-php-mylog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0069" seq="1999-0069">
<status>Entry</status>
<desc>Solaris ufsrestore buffer overflow.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
<ref source="XF">sun-ufsrestore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0070" seq="1999-0070">
<status>Entry</status>
<desc>test-cgi program allows an attacker to list files on the server.</desc>
<refs>
<ref source="XF">http-cgi-test</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0071" seq="1999-0071">
<status>Entry</status>
<desc>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</desc>
<refs>
<ref source="XF">http-apache-cookie</ref>
<ref source="NAI">NAI-2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0072" seq="1999-0072">
<status>Entry</status>
<desc>Buffer overflow in AIX xdat gives root access to local users.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:004.1</ref>
<ref source="XF">ibm-xdat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0073" seq="1999-0073">
<status>Entry</status>
<desc>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</desc>
<refs>
<ref source="CERT">CA-95:14.Telnetd_Environment_Vulnerability</ref>
<ref source="XF">linkerbug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0074" seq="1999-0074">
<status>Entry</status>
<desc>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</desc>
<refs>
<ref source="XF">seqport</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0075" seq="1999-0075">
<status>Entry</status>
<desc>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</desc>
<refs>
<ref source="BUGTRAQ">19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd</ref>
<ref source="XF">ftp-pasvcore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0077" seq="1999-0077">
<status>Entry</status>
<desc>Predictable TCP sequence numbers allow spoofing.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0079" seq="1999-0079">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</desc>
<refs>
<ref source="XF">ftp-pasv-dos</ref>
<ref source="XF">ftp-pasvdos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0080" seq="1999-0080">
<status>Entry</status>
<desc>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</desc>
<refs>
<ref source="BUGTRAQ">19950531 SECURITY: problem with some wu-ftpd-2.4 binaries (fwd)</ref>
<ref source="CERT">CA-95:16.wu-ftpd.vul</ref>
<ref source="XF">ftp-execdotdot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0081" seq="1999-0081">
<status>Entry</status>
<desc>wu-ftp allows files to be overwritten via the rnfr command.</desc>
<refs>
<ref source="XF">ftp-rnfr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0082" seq="1999-0082">
<status>Entry</status>
<desc>CWD ~root command in ftpd allows root access.</desc>
<refs>
<ref source="XF">ftp-cwd</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0083" seq="1999-0083">
<status>Entry</status>
<desc>getcwd() file descriptor leak in FTP.</desc>
<refs>
<ref source="XF">cwdleak</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0084" seq="1999-0084">
<status>Entry</status>
<desc>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0085" seq="1999-0085">
<status>Entry</status>
<desc>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</desc>
<refs>
<ref source="BUGTRAQ">19960821 rwhod buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0087" seq="1999-0087">
<status>Entry</status>
<desc>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</desc>
<refs>
<ref source="XF">ibm-telnetdos</ref>
<ref source="ERS">ERS-SVA-E01-1998:003.1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0090" seq="1999-0090">
<status>Entry</status>
<desc>Buffer overflow in AIX rcp command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-rcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0091" seq="1999-0091">
<status>Entry</status>
<desc>Buffer overflow in AIX writesrv command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-writesrv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0093" seq="1999-0093">
<status>Entry</status>
<desc>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:008.1</ref>
<ref source="XF">ibm-nslookup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0094" seq="1999-0094">
<status>Entry</status>
<desc>AIX piodmgrsu command allows local users to gain additional group privileges.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:007.1</ref>
<ref source="XF">ibm-piodmgrsu</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0095" seq="1999-0095">
<status>Entry</status>
<desc>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-88.01</ref>
<ref source="CERT">CA-93.14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
<ref source="XF">smtp-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0096" seq="1999-0096">
<status>Entry</status>
<desc>Sendmail decode alias can be used to overwrite sensitive files.</desc>
<refs>
<ref source="CERT">CA-93.16</ref>
<ref source="CERT">CA-95.05</ref>
<ref source="CIAC">A-13</ref>
<ref source="CIAC">A-14</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF">smtp-dcod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0097" seq="1999-0097">
<status>Entry</status>
<desc>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:009.1</ref>
<ref source="XF">ibm-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0099" seq="1999-0099">
<status>Entry</status>
<desc>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-95.13.syslog.vul</ref>
<ref source="XF">smtp-syslog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0100" seq="1999-0100">
<status>Entry</status>
<desc>Remote access in AIX innd 1.5.1, using control messages.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:002.1</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0101" seq="1999-0101">
<status>Entry</status>
<desc>Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:001.1</ref>
<ref source="ERS">ERS-SVA-E01-1996:007.1</ref>
<ref source="SUN">00137a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="NAI">NAI-1</ref>
<ref source="XF">ghbn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0102" seq="1999-0102">
<status>Entry</status>
<desc>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</desc>
<refs>
<ref source="XF">slmail-fromheader-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0103" seq="1999-0103">
<status>Entry</status>
<desc>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</desc>
<refs>
<ref source="CERT">CA-96.01.UDP_service_denial</ref>
<ref source="XF">echo</ref>
<ref source="XF">chargen</ref>
<ref source="XF">chargen-patch</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0108" seq="1999-0108">
<status>Entry</status>
<desc>The printers program in IRIX has a buffer overflow that gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">another day, another buffer overflow...</ref>
<ref source="XF">printers-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0109" seq="1999-0109">
<status>Entry</status>
<desc>Buffer overflow in ffbconfig in Solaris 2.5.1.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
<ref source="AUSCERT">AA-97.06</ref>
<ref source="XF">ffbconfig-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0111" seq="1999-0111">
<status>Entry</status>
<desc>RIP v1 is susceptible to spoofing.</desc>
<refs>
<ref source="XF">rip</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0112" seq="1999-0112">
<status>Entry</status>
<desc>Buffer overflow in AIX dtterm program for the CDE.</desc>
<refs>
<ref source="BUGTRAQ">19970520 AIX 4.2 dtterm exploit</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0113" seq="1999-0113">
<status>Entry</status>
<desc>Some implementations of rlogin allow root access if given a -froot parameter.</desc>
<refs>
<ref source="BUGTRAQ">19940729 -froot??? (AIX rlogin bug)</ref>
<ref source="CERT">CA-94.09.bin.login.vulnerability</ref>
<ref source="CIAC">E-26</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
<ref source="XF">rlogin-froot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0115" seq="1999-0115">
<status>Entry</status>
<desc>AIX bugfiler program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19970909 AIX bugfiler</ref>
<ref source="XF">ibm-bugfiler</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0116" seq="1999-0116">
<status>Entry</status>
<desc>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</desc>
<refs>
<ref source="CERT">CA-96.21.tcp_syn.flooding</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0117" seq="1999-0117">
<status>Entry</status>
<desc>AIX passwd allows local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-passwd</ref>
<ref source="CERT">CA-92:07.AIX.passwd.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0118" seq="1999-0118">
<status>Entry</status>
<desc>AIX infod allows local users to gain root access through an X display.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
<ref source="XF">aix-infod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0120" seq="1999-0120">
<status>Entry</status>
<desc>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
<ref source="CERT">CA-94.06.utmp.vulnerability</ref>
<ref source="XF">utmp-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0122" seq="1999-0122">
<status>Entry</status>
<desc>Buffer overflow in AIX lchangelv gives root access.</desc>
<refs>
<ref source="BUGTRAQ">Jul21,1999</ref>
<ref source="XF">lchangelv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0124" seq="1999-0124">
<status>Entry</status>
<desc>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</desc>
<refs>
<ref source="CERT">CA-93:11.UMN.UNIX.gopher.vulnerability</ref>
<ref source="XF">gopher-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0125" seq="1999-0125">
<status>Entry</status>
<desc>Buffer overflow in SGI IRIX mailx program.</desc>
<refs>
<ref source="XF">sgi-mailx-bo</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0126" seq="1999-0126">
<status>Entry</status>
<desc>SGI IRIX buffer overflow in xterm and Xaw allows root access.</desc>
<refs>
<ref source="CERT">VB-98.04.xterm.Xaw</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
<ref source="XF">xfree86-xterm-xaw</ref>
<ref source="XF">xfree86-xaw</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0128" seq="1999-0128">
<status>Entry</status>
<desc>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</desc>
<refs>
<ref source="XF">ping-death</ref>
<ref source="CERT">CA-96.26.ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0129" seq="1999-0129">
<status>Entry</status>
<desc>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</desc>
<refs>
<ref source="CERT">CA-96.25.sendmail_groups</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0130" seq="1999-0130">
<status>Entry</status>
<desc>Local users can start Sendmail in daemon mode and gain root privileges.</desc>
<refs>
<ref source="CERT">CA-96.24.sendmail.daemon.mode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
<ref source="XF">sendmail-daemon-mode</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0131" seq="1999-0131">
<status>Entry</status>
<desc>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</desc>
<refs>
<ref source="CERT">CA-96.20.sendmail_vul</ref>
<ref source="XF">smtp-875bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0132" seq="1999-0132">
<status>Entry</status>
<desc>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0133" seq="1999-0133">
<status>Entry</status>
<desc>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT">CA-96.18.fm_fls</ref>
<ref source="XF">fmaker-logfile</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0134" seq="1999-0134">
<status>Entry</status>
<desc>vold in Solaris 2.x allows local users to gain root access.</desc>
<refs>
<ref source="XF">sol-voldtmp</ref>
<ref source="CERT">CA-96.17.Solaris_vold_vul</ref>
<ref source="AUSCERT">AL-96.04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0135" seq="1999-0135">
<status>Entry</status>
<desc>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sun-admintool</ref>
<ref source="CERT">CA-96.16.Solaris_admintool_vul</ref>
<ref source="AUSCERT">AL-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0136" seq="1999-0136">
<status>Entry</status>
<desc>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sol-KCMSvuln</ref>
<ref source="AUSCERT">AL-96.02</ref>
<ref source="CERT">CA-96.15.Solaris_KCMS_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0137" seq="1999-0137">
<status>Entry</status>
<desc>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</desc>
<refs>
<ref source="XF">linux-dipbo</ref>
<ref source="CERT">CA-96.13.dip_vul</ref>
<ref source="XF">dip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0138" seq="1999-0138">
<status>Entry</status>
<desc>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</desc>
<refs>
<ref source="CERT">CA-96.12.suidperl_vul</ref>
<ref source="XF">sperl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0139" seq="1999-0139">
<status>Entry</status>
<desc>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</desc>
<refs>
<ref source="XF">sol-mkcookie</ref>
<ref source="RSI">RSI.0012.12-03-98.SOLARIS.MKCOOKIE</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0141" seq="1999-0141">
<status>Entry</status>
<desc>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</desc>
<refs>
<ref source="XF">http-java-applet</ref>
<ref source="CERT">CA-96.07.java_bytecode_verifier</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0142" seq="1999-0142">
<status>Entry</status>
<desc>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</desc>
<refs>
<ref source="CERT">CA-96.05.java_applet_security_mgr</ref>
<ref source="XF">http-java-appletsecmgr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0143" seq="1999-0143">
<status>Entry</status>
<desc>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</desc>
<refs>
<ref source="CERT">CA-96.03.kerberos_4_key_server</ref>
<ref source="XF">kerberos-bf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0145" seq="1999-0145">
<status>Entry</status>
<desc>Sendmail WIZ command enabled, allowing root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0146" seq="1999-0146">
<status>Entry</status>
<desc>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</desc>
<refs>
<ref source="BUGTRAQ">19970715 Bug CGI campas</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0147" seq="1999-0147">
<status>Entry</status>
<desc>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</desc>
<refs>
<ref source="XF">http-cgi-glimpse</ref>
<ref source="AUSCERT">AA-97.28</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0148" seq="1999-0148">
<status>Entry</status>
<desc>The handler CGI program in IRIX allows arbitrary command execution.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
<ref source="XF">http-sgi-handler</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0149" seq="1999-0149">
<status>Entry</status>
<desc>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970420 IRIX 6.x /cgi-bin/wrap bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
<ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0150" seq="1999-0150">
<status>Entry</status>
<desc>The Perl fingerd program allows arbitrary command execution from remote users.</desc>
<refs>
<ref source="XF">perl-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0151" seq="1999-0151">
<status>Entry</status>
<desc>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</desc>
<refs>
<ref source="CERT">CA-95.07a.REVISED.satan.vul</ref>
<ref source="CERT">CA-95.06.satan.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0152" seq="1999-0152">
<status>Entry</status>
<desc>The DG/UX finger daemon allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19970811 dgux in.fingerd vulnerability</ref>
<ref source="XF">dgux-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0153" seq="1999-0153">
<status>Entry</status>
<desc>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</desc>
<refs>
<ref source="XF">win-oob</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0155" seq="1999-0155">
<status>Entry</status>
<desc>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</desc>
<refs>
<ref source="XF">gscript-dsafer</ref>
<ref source="CERT">CA-95.10.ghostscript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0157" seq="1999-0157">
<status>Entry</status>
<desc>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/nifrag.shtml</ref>
<ref source="XF">cisco-fragmented-attacks</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0158" seq="1999-0158">
<status>Entry</status>
<desc>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml">20010913 Cisco PIX Firewall Manager File Exposure</ref>
<ref source="XF">cisco-pix-file-exposure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/685">685</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0159" seq="1999-0159">
<status>Entry</status>
<desc>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/ioslogin-pub.shtml</ref>
<ref source="XF">cisco-ios-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0160" seq="1999-0160">
<status>Entry</status>
<desc>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</desc>
<refs>
<ref source="CISCO">19971001 Vulnerabilities in Cisco CHAP Authentication</ref>
<ref source="CIAC">I-002A</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
<ref source="XF">cisco-chap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0161" seq="1999-0161">
<status>Entry</status>
<desc>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/707/1.html</ref>
<ref source="XF">cisco-acl-tacacs</ref>
<ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0162" seq="1999-0162">
<status>Entry</status>
<desc>The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</desc>
<refs>
<ref source="CISCO">19950601 &quot;Established&quot; Keyword May Allow Packets to Bypass Filter</ref>
<ref source="XF">cisco-acl-established</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0164" seq="1999-0164">
<status>Entry</status>
<desc>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</desc>
<refs>
<ref source="XF">sol-pstmprace</ref>
<ref source="AUSCERT">AA-95.07</ref>
<ref source="CERT">CA-95.09.Solaris.ps.vul</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0166" seq="1999-0166">
<status>Entry</status>
<desc>NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</desc>
<refs>
<ref source="XF">nfs-cd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0167" seq="1999-0167">
<status>Entry</status>
<desc>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</desc>
<refs>
<ref source="XF">nfs-guess</ref>
<ref source="CERT">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0168" seq="1999-0168">
<status>Entry</status>
<desc>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</desc>
<refs>
<ref source="XF">nfs-portmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0170" seq="1999-0170">
<status>Entry</status>
<desc>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</desc>
<refs>
<ref source="XF">nfs-ultrix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0172" seq="1999-0172">
<status>Entry</status>
<desc>FormMail CGI program allows remote execution of commands.</desc>
<refs>
<ref source="XF">http-cgi-formmail-exe</ref>
<ref source="BUGTRAQ">Aug02,1995</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0173" seq="1999-0173">
<status>Entry</status>
<desc>FormMail CGI program can be used by web servers other than the host server that the program resides on.</desc>
<refs>
<ref source="XF">http-cgi-formmail-use</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0174" seq="1999-0174">
<status>Entry</status>
<desc>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970208 view-source</ref>
<ref source="XF">http-cgi-viewsrc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0175" seq="1999-0175">
<status>Entry</status>
<desc>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</desc>
<refs>
<ref source="XF">http-nov-convert</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0176" seq="1999-0176">
<status>Entry</status>
<desc>The Webgais program allows a remote user to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">Jul10,1997</ref>
<ref source="XF">http-webgais-query</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0177" seq="1999-0177">
<status>Entry</status>
<desc>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</desc>
<refs>
<ref source="NTBUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="NTBUGTRAQ">19970905 Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="BUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="XF">http-website-uploader</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0178" seq="1999-0178">
<status>Entry</status>
<desc>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0179" seq="1999-0179">
<status>Entry</status>
<desc>Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
<ref source="XF">nt-samba-dotdot</ref>
<ref source="XF">nt-351</ref>
<ref source="XF">nt-35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0180" seq="1999-0180">
<status>Entry</status>
<desc>in.rshd allows users to login with a NULL username and execute commands.</desc>
<refs>
<ref source="XF">rsh-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0181" seq="1999-0181">
<status>Entry</status>
<desc>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</desc>
<refs>
<ref source="XF">walld</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0182" seq="1999-0182">
<status>Entry</status>
<desc>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
<ref source="CERT">VB-97.10.samba</ref>
<ref source="XF">nt-samba-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0183" seq="1999-0183">
<status>Entry</status>
<desc>Linux implementations of TFTP would allow access to files outside the restricted directory.</desc>
<refs>
<ref source="XF">linux-tftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0184" seq="1999-0184">
<status>Entry</status>
<desc>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</desc>
<refs>
<ref source="XF">dns-updates</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0185" seq="1999-0185">
<status>Entry</status>
<desc>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
<ref source="XF">sun-ftpd/logind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0188" seq="1999-0188">
<status>Entry</status>
<desc>The passwd command in Solaris can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
<ref source="XF">sun-passwd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0189" seq="1999-0189">
<status>Entry</status>
<desc>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</desc>
<refs>
<ref source="NAI">NAI-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
<ref source="XF">rpc-32771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0190" seq="1999-0190">
<status>Entry</status>
<desc>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
<ref source="XF">sun-rpcbind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0191" seq="1999-0191">
<status>Entry</status>
<desc>IIS newdsn.exe CGI script allows remote users to overwrite files.</desc>
<refs>
<ref source="XF">http-cgi-newdsn</ref>
<ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0192" seq="1999-0192">
<status>Entry</status>
<desc>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</desc>
<refs>
<ref source="SNI">SNI-20</ref>
<ref source="XF">bsd-tel-tgetent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0194" seq="1999-0194">
<status>Entry</status>
<desc>Denial of service in in.comsat allows attackers to generate messages.</desc>
<refs>
<ref source="XF">comsat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0196" seq="1999-0196">
<status>Entry</status>
<desc>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</desc>
<refs>
<ref source="BUGTRAQ">19970704 Vulnerability in websendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
<ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
<ref source="XF">http-webgais-smail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0201" seq="1999-0201">
<status>Entry</status>
<desc>A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</desc>
<refs>
<ref source="XF">ftp-home</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0202" seq="1999-0202">
<status>Entry</status>
<desc>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="XF">ftp-exectar</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0203" seq="1999-0203">
<status>Entry</status>
<desc>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</desc>
<refs>
<ref source="CERT">CA-95.08</ref>
<ref source="CIAC">E-03</ref>
<ref source="XF">smtp-sendmail-version5</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0204" seq="1999-0204">
<status>Entry</status>
<desc>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</desc>
<refs>
<ref source="XF">ident-bo</ref>
<ref source="CIAC">F-13</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0206" seq="1999-0206">
<status>Entry</status>
<desc>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</desc>
<refs>
<ref source="XF">sendmail-mime-bo</ref>
<ref source="AUSCERT">AA-96.06a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0207" seq="1999-0207">
<status>Entry</status>
<desc>Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</desc>
<refs>
<ref source="XF">majordomo-exe</ref>
<ref source="CERT">CA-94.11.majordomo.vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0208" seq="1999-0208">
<status>Entry</status>
<desc>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="XF">rpc-update</ref>
<ref source="CERT">CA-95.17.rpc.ypupdated.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0209" seq="1999-0209">
<status>Entry</status>
<desc>The SunView (SunTools) selection_svc facility allows remote users to read files.</desc>
<refs>
<ref source="CERT">CA-90.05.sunselection.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
<ref source="XF">selsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0210" seq="1999-0210">
<status>Entry</status>
<desc>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0211" seq="1999-0211">
<status>Entry</status>
<desc>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</desc>
<refs>
<ref source="CERT">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0212" seq="1999-0212">
<status>Entry</status>
<desc>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168">00168</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref>
<ref source="XF">sun-mountd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0214" seq="1999-0214">
<status>Entry</status>
<desc>Denial of service by sending forged ICMP unreachable packets.</desc>
<refs>
<ref source="XF">icmp-unreachable</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0215" seq="1999-0215">
<status>Entry</status>
<desc>Routed allows attackers to append data to files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
<ref source="XF">ripapp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0217" seq="1999-0217">
<status>Entry</status>
<desc>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</desc>
<refs>
<ref source="XF">udp-bomb</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0218" seq="1999-0218">
<status>Entry</status>
<desc>Livingston portmaster machines could be rebooted via a series of commands.</desc>
<refs>
<ref source="XF">portmaster-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0219" seq="1999-0219">
<status>Entry</status>
<desc>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="BUGTRAQ">19990909 Exploit: Serv-U Ver2.5 FTPd Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0221" seq="1999-0221">
<status>Entry</status>
<desc>Denial of service of Ascend routers through port 150 (remote administration).</desc>
<refs>
<ref source="XF">ascend-150-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0223" seq="1999-0223">
<status>Entry</status>
<desc>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</desc>
<refs>
<ref source="BUGTRAQ">19961109 Syslogd and Solaris 2.4</ref>
<ref source="SUNBUG">1249320</ref>
<ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
<ref source="XF">sol-syslogd-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0224" seq="1999-0224">
<status>Entry</status>
<desc>Denial of service in Windows NT messenger service through a long username.</desc>
<refs>
<ref source="XF">nt-messenger</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0225" seq="1999-0225">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp">19980214 Windows NT Logon Denial of Service</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
<ref source="XF">nt-logondos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0227" seq="1999-0227">
<status>Entry</status>
<desc>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
<ref source="XF">nt-lsass-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0228" seq="1999-0228">
<status>Entry</status>
<desc>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</desc>
<refs>
<ref source="XF">nt-rpc-ver</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0230" seq="1999-0230">
<status>Entry</status>
<desc>Buffer overflow in Cisco 7xx routers through the telnet service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/pwbuf-pub.shtml</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0233" seq="1999-0233">
<status>Entry</status>
<desc>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
<ref source="XF">http-iis-cmd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0234" seq="1999-0234">
<status>Entry</status>
<desc>Bash treats any character with a value of 255 as a command separator.</desc>
<refs>
<ref source="XF">bash-cmd</ref>
<ref source="CERT">CA-96.22.bash_vuls</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0236" seq="1999-0236">
<status>Entry</status>
<desc>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</desc>
<refs>
<ref source="XF">http-scriptalias</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0237" seq="1999-0237">
<status>Entry</status>
<desc>Remote execution of arbitrary commands through Guestbook CGI program.</desc>
<refs>
<ref source="XF">http-cgi-guestbook</ref>
<ref source="CERT">VB-97.02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0239" seq="1999-0239">
<status>Entry</status>
<desc>Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</desc>
<refs>
<ref source="XF">fastrack-get-directory-list</ref>
<ref source="OSVDB" url="http://www.osvdb.org/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0244" seq="1999-0244">
<status>Entry</status>
<desc>Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</desc>
<refs>
<ref source="NAI">NAI-23</ref>
<ref source="XF">radius-accounting-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0245" seq="1999-0245">
<status>Entry</status>
<desc>Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19950907 Linux NIS security problem hole and fix</ref>
<ref source="XF">linux-plus</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0247" seq="1999-0247">
<status>Entry</status>
<desc>Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1443">1443</ref>
<ref source="XF">inn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0248" seq="1999-0248">
<status>Entry</status>
<desc>A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
<ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0251" seq="1999-0251">
<status>Entry</status>
<desc>Denial of service in talk program allows remote attackers to disrupt a user's display.</desc>
<refs>
<ref source="XF">talkd-flash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0252" seq="1999-0252">
<status>Entry</status>
<desc>Buffer overflow in listserv allows arbitrary command execution.</desc>
<refs>
<ref source="XF">smtp-listserv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0256" seq="1999-0256">
<status>Entry</status>
<desc>Buffer overflow in War FTP allows remote execution of commands.</desc>
<refs>
<ref source="XF">war-ftpd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0259" seq="1999-0259">
<status>Entry</status>
<desc>cfingerd lists all users on a system via search.**@target.</desc>
<refs>
<ref source="BUGTRAQ">19970523 cfingerd vulnerability</ref>
<ref source="XF">cfinger-user-enumeration</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0260" seq="1999-0260">
<status>Entry</status>
<desc>The jj CGI program allows command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19961224 jj cgi</ref>
<ref source="XF">http-cgi-jj</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0262" seq="1999-0262">
<status>Entry</status>
<desc>Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</desc>
<refs>
<ref source="BUGTRAQ">19980804 remote exploit in faxsurvey cgi-script</ref>
<ref source="BUGTRAQ">19980804 PATCH: faxsurvey</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0263" seq="1999-0263">
<status>Entry</status>
<desc>Solaris SUNWadmap can be exploited to obtain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref>
<ref source="XF">sun-sunwadmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0264" seq="1999-0264">
<status>Entry</status>
<desc>htmlscript CGI program allows remote read access to files.</desc>
<refs>
<ref source="XF">http-htmlscript-file-access</ref>
<ref source="BUGTRAQ">Jan27,1998</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0265" seq="1999-0265">
<status>Entry</status>
<desc>ICMP redirect messages may crash or lock up a host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174">Q154174</ref>
<ref source="ISS">ICMP Redirects Against Embedded Controllers</ref>
<ref source="XF">icmp-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0266" seq="1999-0266">
<status>Entry</status>
<desc>The info2www CGI script allows remote file access or remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">19980303 Vulnerabilites in some versions of info2www CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref>
<ref source="XF">http-cgi-info2www</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0267" seq="1999-0267">
<status>Entry</status>
<desc>Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</desc>
<refs>
<ref source="XF">http-port</ref>
<ref source="CERT">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0268" seq="1999-0268">
<status>Entry</status>
<desc>MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</desc>
<refs>
<ref source="BUGTRAQ">19980630 Security vulnerabilities in MetaInfo products</ref>
<ref source="BUGTRAQ">19980703 Followup to MetaInfo vulnerabilities</ref>
<ref source="OSVDB" url="http://www.osvdb.org/110">110</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref>
<ref source="XF">metaweb-server-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0269" seq="1999-0269">
<status>Entry</status>
<desc>Netscape Enterprise servers may list files through the PageServices query.</desc>
<refs>
<ref source="XF">netscape-server-pageservices</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0270" seq="1999-0270">
<status>Entry</status>
<desc>Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19980317 IRIX performer_tools bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref>
<ref source="OSVDB" url="http://www.osvdb.org/134">134</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0272" seq="1999-0272">
<status>Entry</status>
<desc>Denial of service in Slmail v2.5 through the POP3 port.</desc>
<refs>
<ref source="XF">slmail-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0273" seq="1999-0273">
<status>Entry</status>
<desc>Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</desc>
<refs>
<ref source="XF">sun-telnet-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0274" seq="1999-0274">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</desc>
<refs>
<ref source="NAI">NAI-5</ref>
<ref source="XF">nt-dns-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0275" seq="1999-0275">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</desc>
<refs>
<ref source="XF">nt-dnscrash</ref>
<ref source="XF">nt-dnsver</ref>
<ref source="MS">Q169461</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0276" seq="1999-0276">
<status>Entry</status>
<desc>mSQL v2.0.1 and below allows remote execution through a buffer overflow.</desc>
<refs>
<ref source="XF">msql-debug-bo</ref>
<ref source="SEKURE">sekure.01-99.msql</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0277" seq="1999-0277">
<status>Entry</status>
<desc>The WorkMan program can be used to overwrite any file to get root access.</desc>
<refs>
<ref source="XF">workman</ref>
<ref source="CERT">CA-96.23.workman_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0278" seq="1999-0278">
<status>Entry</status>
<desc>In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref>
<ref source="XF">iis-asp-data-check</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0279" seq="1999-0279">
<status>Entry</status>
<desc>Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19971217 CGI security hole in EWS (Excite for Web Servers)</ref>
<ref source="BUGTRAQ">19980115 Excite announcement</ref>
<ref source="CERT">VB-98.01.excite</ref>
<ref source="XF">excite-cgi-search-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0280" seq="1999-0280">
<status>Entry</status>
<desc>Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</desc>
<refs>
<ref source="NTBUGTRAQ">19970317 Internet Explorer Bug #4</ref>
<ref source="CIAC">H-38</ref>
<ref source="XF">http-ie-lnkurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0281" seq="1999-0281">
<status>Entry</status>
<desc>Denial of service in IIS using long URLs.</desc>
<refs>
<ref source="XF">http-iis-longurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0288" seq="1999-0288">
<status>Entry</status>
<desc>The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</desc>
<refs>
<ref source="NTBUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970815 Re: WINS flooding</ref>
<ref source="MISC" url="http://safenetworks.com/Windows/wins.html">http://safenetworks.com/Windows/wins.html</ref>
<ref source="MSKB">155701</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0289" seq="1999-0289">
<status>Entry</status>
<desc>The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0290" seq="1999-0290">
<status>Entry</status>
<desc>The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</desc>
<refs>
<ref source="BUGTRAQ">19980221 WinGate DoS</ref>
<ref source="BUGTRAQ">19980326 WinGate Intermediary Fix/Update</ref>
<ref source="XF">wingate-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0291" seq="1999-0291">
<status>Entry</status>
<desc>The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</desc>
<refs>
<ref source="XF">wingate-unpassworded</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0292" seq="1999-0292">
<status>Entry</status>
<desc>Denial of service through Winpopup using large user names.</desc>
<refs>
<ref source="XF">nt-winpopup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0293" seq="1999-0293">
<status>Entry</status>
<desc>AAA authentication on Cisco systems allows attackers to execute commands without authorization.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/aaapair-pub.shtml</ref>
<ref source="XF">cisco-ios-aaa-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0294" seq="1999-0294">
<status>Entry</status>
<desc>All records in a WINS database can be deleted through SNMP for a denial of service.</desc>
<refs>
<ref source="XF">nt-wins-snmp2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0295" seq="1999-0295">
<status>Entry</status>
<desc>Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</desc>
<refs>
<ref source="XF">sun-sysdef</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0296" seq="1999-0296">
<status>Entry</status>
<desc>Solaris volrmmount program allows attackers to read any file.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref>
<ref source="XF">sun-volrmmount</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0297" seq="1999-0297">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</desc>
<refs>
<ref source="NAI">NAI-3</ref>
<ref source="AUSCERT">AA-96.21</ref>
<ref source="CIAC">H-17</ref>
<ref source="XF">vixie-cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0299" seq="1999-0299">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD lpd through long DNS hostnames.</desc>
<refs>
<ref source="NAI">NAI-9</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0300" seq="1999-0300">
<status>Entry</status>
<desc>nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
<ref source="XF">sun-niscache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0301" seq="1999-0301">
<status>Entry</status>
<desc>Buffer overflow in SunOS/Solaris ps command.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
<ref source="AUSCERT">AUSCERT-97.17</ref>
<ref source="XF">sun-ps2bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0302" seq="1999-0302">
<status>Entry</status>
<desc>SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref>
<ref source="XF">sun-ftp-server</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0303" seq="1999-0303">
<status>Entry</status>
<desc>Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</desc>
<refs>
<ref source="XF">bnu-uucpd-bo</ref>
<ref source="RSI">RSI.0002.05-18-98.BNU.UUCPD</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0304" seq="1999-0304">
<status>Entry</status>
<desc>mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</desc>
<refs>
<ref source="XF">bsd-mmap</ref>
<ref source="FREEBSD">FreeBSD-SA-98:02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0305" seq="1999-0305">
<status>Entry</status>
<desc>The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</desc>
<refs>
<ref source="OPENBSD">Feb15,1998 &quot;IP Source Routing Problem&quot;</ref>
<ref source="MISC" url="http://www.openbsd.org/advisories/sourceroute.txt">http://www.openbsd.org/advisories/sourceroute.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0308" seq="1999-0308">
<status>Entry</status>
<desc>HP-UX gwind program allows users to modify arbitrary files.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
<ref source="XF">hpux-gwind-overwrite</ref>
<ref source="CIAC">H-03: HP-UX suid Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0309" seq="1999-0309">
<status>Entry</status>
<desc>HP-UX vgdisplay program gives root access to local users.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
<ref source="XF">hpux-vgdisplay</ref>
<ref source="CIAC">H-27: HP-UX vgdisplay Buffer Overrun Vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0310" seq="1999-0310">
<status>Entry</status>
<desc>SSH 1.2.25 on HP-UX allows access to new user accounts.</desc>
<refs>
<ref source="XF">ssh-1225</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0311" seq="1999-0311">
<status>Entry</status>
<desc>fpkg2swpk in HP-UX allows local users to gain root access.</desc>
<refs>
<ref source="XF">hpux-fpkg2swpk</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0312" seq="1999-0312">
<status>Entry</status>
<desc>HP ypbind allows attackers with root privileges to modify NIS data.</desc>
<refs>
<ref source="XF">nis-ypbind</ref>
<ref source="CERT">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0313" seq="1999-0313">
<status>Entry</status>
<desc>disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref>
<ref source="OSVDB" url="http://www.osvdb.org/936">936</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0314" seq="1999-0314">
<status>Entry</status>
<desc>ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0315" seq="1999-0315">
<status>Entry</status>
<desc>Buffer overflow in Solaris fdformat command gives root access to local users.</desc>
<refs>
<ref source="XF">fdformat-bo</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0316" seq="1999-0316">
<status>Entry</status>
<desc>Buffer overflow in Linux splitvt command gives root access to local users.</desc>
<refs>
<ref source="XF">linux-splitvt</ref>
<ref source="CIAC">G-08</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0318" seq="1999-0318">
<status>Entry</status>
<desc>Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19961125 Security Problems in XMCD</ref>
<ref source="BUGTRAQ">19961125 XMCD v2.1 released (was: Security Problems in XMCD)</ref>
<ref source="XF">xmcd-envbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0320" seq="1999-0320">
<status>Entry</status>
<desc>SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/166">00166</ref>
<ref source="XF">sun-rpc.cmsd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0321" seq="1999-0321">
<status>Entry</status>
<desc>Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</desc>
<refs>
<ref source="XF">sun-kcms-configure-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0322" seq="1999-0322">
<status>Entry</status>
<desc>The open() function in FreeBSD allows local attackers to write to arbitrary files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:05</ref>
<ref source="XF">freebsd-open</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0323" seq="1999-0323">
<status>Entry</status>
<desc>FreeBSD mmap function allows users to modify append-only or immutable files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:04</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref>
<ref source="XF">bsd-mmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0324" seq="1999-0324">
<status>Entry</status>
<desc>ppl program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
<ref source="CIAC">H-31</ref>
<ref source="XF">hp-ppllog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0325" seq="1999-0325">
<status>Entry</status>
<desc>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="XF">hp-vhe</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0326" seq="1999-0326">
<status>Entry</status>
<desc>Vulnerability in HP-UX mediainit program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
<ref source="XF">hp-mediainit</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0327" seq="1999-0327">
<status>Entry</status>
<desc>SGI syserr program allows local users to corrupt files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-syserr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0328" seq="1999-0328">
<status>Entry</status>
<desc>SGI permissions program allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-permtool</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0329" seq="1999-0329">
<status>Entry</status>
<desc>SGI mediad program allows local users to gain root access.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref>
<ref source="XF">sgi-mediad</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0332" seq="1999-0332">
<status>Entry</status>
<desc>Buffer overflow in NetMeeting allows denial of service and remote command execution.</desc>
<refs>
<ref source="XF">nt-netmeeting</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346">Q184346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0334" seq="1999-0334">
<status>Entry</status>
<desc>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</desc>
<refs>
<ref source="XF">sol-startup</ref>
<ref source="CERT">CA-93.19.Solaris.Startup.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0335" seq="1999-0335">
<status>Entry</status>
<desc>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0337" seq="1999-0337">
<status>Entry</status>
<desc>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</desc>
<refs>
<ref source="CERT">CA-94.10.IBM.AIX.bsh.vulnerability.html</ref>
<ref source="XF">ibm-bsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0338" seq="1999-0338">
<status>Entry</status>
<desc>AIX Licensed Program Product performance tools allow local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-perf-tools</ref>
<ref source="CERT">CA-94.03.AIX.performance.tools </ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0339" seq="1999-0339">
<status>Entry</status>
<desc>Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</desc>
<refs>
<ref source="XF">sol-sun-libauth</ref>
<ref source="RSI">RSI.0007.05-26-98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0340" seq="1999-0340">
<status>Entry</status>
<desc>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">005</ref>
<ref source="XF">linux-crond</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0341" seq="1999-0341">
<status>Entry</status>
<desc>Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">006</ref>
<ref source="XF">linux-deliver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0342" seq="1999-0342">
<status>Entry</status>
<desc>Linux PAM modules allow local users to gain root access using temporary files.</desc>
<refs>
<ref source="REDHAT">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref>
<ref source="XF">linux-pam-passwd-tmprace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0343" seq="1999-0343">
<status>Entry</status>
<desc>A malicious Palace server can force a client to execute arbitrary programs.</desc>
<refs>
<ref source="BUGTRAQ">19981002 Announcements from The Palace (fwd)</ref>
<ref source="XF">palace-malicious-servers-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0344" seq="1999-0344">
<status>Entry</status>
<desc>NT users can gain debug-level access on a system process using the Sechole exploit.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288">Q190288</ref>
<ref source="XF">nt-priv-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0346" seq="1999-0346">
<status>Entry</status>
<desc>CGI PHP mlog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="XF">http-cgi-php-mlog</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0348" seq="1999-0348">
<status>Entry</status>
<desc>IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</desc>
<refs>
<ref source="NTBUGTRAQ">Jan27,1999</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003">Q197003</ref>
<ref source="OSVDB" url="http://www.osvdb.org/930">930</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0349" seq="1999-0349">
<status>Entry</status>
<desc>A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348">Q188348</ref>
<ref source="BUGTRAQ">Jan27,1999</ref>
<ref source="XF">iis-remote-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0350" seq="1999-0350">
<status>Entry</status>
<desc>Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</desc>
<refs>
<ref source="L0PHT">Feb8,1999</ref>
<ref source="XF">clearcase-temp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0351" seq="1999-0351">
<status>Entry</status>
<desc>FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</desc>
<refs>
<ref source="INFOWAR">01</ref>
<ref source="MISC" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">pasv-pizza-thief-dos(3389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0353" seq="1999-0353">
<status>Entry</status>
<desc>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref>
<ref source="XF">pcnfsd-world-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0355" seq="1999-0355">
<status>Entry</status>
<desc>Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0357" seq="1999-0357">
<status>Entry</status>
<desc>Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</desc>
<refs>
<ref source="BUGTRAQ">19990125 Win98 crash?</ref>
<ref source="XF">win98-oshare-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0358" seq="1999-0358">
<status>Entry</status>
<desc>Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
<ref source="COMPAQ">SSRT0583U</ref>
<ref source="XF">du-inc</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0362" seq="1999-0362">
<status>Entry</status>
<desc>WS_FTP server remote denial of service through cwd command.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref>
<ref source="XF">wsftp-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0363" seq="1999-0363">
<status>Entry</status>
<desc>SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</desc>
<refs>
<ref source="BUGTRAQ">Feb02,1999</ref>
<ref source="XF">plp-lpc-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0365" seq="1999-0365">
<status>Entry</status>
<desc>The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</desc>
<refs>
<ref source="BUGTRAQ">Feb04,1999</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0366" seq="1999-0366">
<status>Entry</status>
<desc>In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840">Q214840</ref>
<ref source="XF">nt-sp4-auth-error</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0367" seq="1999-0367">
<status>Entry</status>
<desc>NetBSD netstat command allows local users to access kernel memory.</desc>
<refs>
<ref source="NETBSD">1999-002</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0368" seq="1999-0368">
<status>Entry</status>
<desc>Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</desc>
<refs>
<ref source="NETECT">palmetto.ftpd</ref>
<ref source="CERT">CA-99.03</ref>
<ref source="XF">palmetto-ftpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0369" seq="1999-0369">
<status>Entry</status>
<desc>The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
<ref source="XF">sun-sdtcm-convert-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0371" seq="1999-0371">
<status>Entry</status>
<desc>Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990211 Lynx /tmp problem</ref>
<ref source="CERT">VB-97.05.lynx</ref>
<ref source="XF">lynx-temp-files-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0372" seq="1999-0372">
<status>Entry</status>
<desc>The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref>
<ref source="XF">nt-backoffice-setup</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004">Q217004</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0373" seq="1999-0373">
<status>Entry</status>
<desc>Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</desc>
<refs>
<ref source="ISS">Buffer Overflow in &quot;Super&quot; package in Debian Linux</ref>
<ref source="XF">linux-super-bo</ref>
<ref source="XF">linux-super-logging-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0374" seq="1999-0374">
<status>Entry</status>
<desc>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990215</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">linux-cfengine-symlinks</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0375" seq="1999-0375">
<status>Entry</status>
<desc>Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</desc>
<refs>
<ref source="NAI">February 16, 1999</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">nfr-webd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0376" seq="1999-0376">
<status>Entry</status>
<desc>Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref>
<ref source="BUGTRAQ">Feb20,1999</ref>
<ref source="L0PHT">Feb18,1999</ref>
<ref source="XF">nt-knowndlls-list</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0377" seq="1999-0377">
<status>Entry</status>
<desc>Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</desc>
<refs>
<ref source="BUGTRAQ">Feb22,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0378" seq="1999-0378">
<status>Entry</status>
<desc>InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</desc>
<refs>
<ref source="BUGTRAQ">19990222 BlackHats Advisory -- InterScan VirusWall</ref>
<ref source="BUGTRAQ">19990225 Patch for InterScan VirusWall for Unix now available</ref>
<ref source="XF">viruswall-http-request</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0379" seq="1999-0379">
<status>Entry</status>
<desc>Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref>
<ref source="BUGTRAQ">19990223 Microsoft Security Bulletin (MS99-007)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref>
<ref source="XF">win-resourcekit-taskpads</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0380" seq="1999-0380">
<status>Entry</status>
<desc>SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref>
<ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0382" seq="1999-0382">
<status>Entry</status>
<desc>The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref>
<ref source="XF">nt-screen-saver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0383" seq="1999-0383">
<status>Entry</status>
<desc>ACC Tigris allows public access without a login.</desc>
<refs>
<ref source="BUGTRAQ">19990103 Tigris vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref>
<ref source="OSVDB" url="http://www.osvdb.org/267">267</ref>
<ref source="XF">acc-tigris-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0384" seq="1999-0384">
<status>Entry</status>
<desc>The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</desc>
<refs>
<ref source="XF">forms-vuln-patch</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0385" seq="1999-0385">
<status>Entry</status>
<desc>The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref>
<ref source="ISS">LDAP Buffer overflow against Microsoft Directory Services</ref>
<ref source="XF">ldap-exchange-overflow</ref>
<ref source="XF">ldap-mds-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0386" seq="1999-0386">
<status>Entry</status>
<desc>Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref>
<ref source="XF">pws-file-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/111">111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0387" seq="1999-0387">
<status>Entry</status>
<desc>A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp">MS99-052</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115">Q168115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref>
<ref source="XF">9x-plaintext-pwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0388" seq="1999-0388">
<status>Entry</status>
<desc>DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</desc>
<refs>
<ref source="XF">datalynx-suguard-relative-paths</ref>
<ref source="L0PHT">Jan3,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0390" seq="1999-0390">
<status>Entry</status>
<desc>Buffer overflow in Dosemu Slang library in Linux.</desc>
<refs>
<ref source="BUGTRAQ">19990104 Dosemu/S-Lang Overflow + sploit</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0391" seq="1999-0391">
<status>Entry</status>
<desc>The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</desc>
<refs>
<ref source="L0PHT">Jan. 5, 1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0392" seq="1999-0392">
<status>Entry</status>
<desc>Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</desc>
<refs>
<ref source="BUGTRAQ">Jan10,1999</ref>
<ref source="XF">http-cgic-library-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0393" seq="1999-0393">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</desc>
<refs>
<ref source="BUGTRAQ">19981212 ** Sendmail 8.9.2 DoS - exploit ** get what you want!</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
<ref source="XF">sendmail-parsing-redirection</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0395" seq="1999-0395">
<status>Entry</status>
<desc>A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise17.php">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
<ref source="XF">backweb-polite-agent-protocol</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0396" seq="1999-0396">
<status>Entry</status>
<desc>A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="NETBSD">1999-001</ref>
<ref source="OPENBSD">Feb17,1999</ref>
<ref source="XF">netbsd-tcp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0402" seq="1999-0402">
<status>Entry</status>
<desc>wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</desc>
<refs>
<ref source="BUGTRAQ">Feb2,1999</ref>
<ref source="XF">wget-permissions</ref>
<ref source="DEBIAN">19990220</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0403" seq="1999-0403">
<status>Entry</status>
<desc>A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref>
<ref source="XF">cyrix-hang</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0404" seq="1999-0404">
<status>Entry</status>
<desc>Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">Feb14,1999</ref>
<ref source="XF">mailmax-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0405" seq="1999-0405">
<status>Entry</status>
<desc>A buffer overflow in lsof allows local users to obtain root privilege.</desc>
<refs>
<ref source="HERT">002</ref>
<ref source="BUGTRAQ">Feb18,1999</ref>
<ref source="DEBIAN">19990220a</ref>
<ref source="XF">lsof-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0407" seq="1999-0407">
<status>Entry</status>
<desc>By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="XF">iis-iisadmpwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0408" seq="1999-0408">
<status>Entry</status>
<desc>Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</desc>
<refs>
<ref source="BUGTRAQ">19990225 Cobalt root exploit</ref>
<ref source="XF">cobalt-raq-history-exposure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0409" seq="1999-0409">
<status>Entry</status>
<desc>Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">19990304 Linux /usr/bin/gnuplot overflow</ref>
<ref source="XF">gnuplot-home-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0410" seq="1999-0410">
<status>Entry</status>
<desc>The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">Mar5,1999</ref>
<ref source="XF">sol-cancel</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0412" seq="1999-0412">
<status>Entry</status>
<desc>In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">iis-isapi-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0413" seq="1999-0413">
<status>Entry</status>
<desc>A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref>
<ref source="XF">irix-font-path-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0414" seq="1999-0414">
<status>Entry</status>
<desc>In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</desc>
<refs>
<ref source="NAI">Linux Blind TCP Spoofing</ref>
<ref source="XF">linux-blind-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0415" seq="1999-0415">
<status>Entry</status>
<desc>The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-router-commands</ref>
<ref source="XF">cisco-web-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0416" seq="1999-0416">
<status>Entry</status>
<desc>Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-web-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0417" seq="1999-0417">
<status>Entry</status>
<desc>64 bit Solaris 7 procfs allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">Mar9,1999</ref>
<ref source="XF">solaris-psinfo-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0420" seq="1999-0420">
<status>Entry</status>
<desc>umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</desc>
<refs>
<ref source="NETBSD">1999-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0421" seq="1999-0421">
<status>Entry</status>
<desc>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</desc>
<refs>
<ref source="ISS">Short-Term High-Risk Vulnerability During Slackware 3.6 Network Installations</ref>
<ref source="XF">linux-slackware-install</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/338">338</ref>
<ref source="OSVDB" url="http://www.osvdb.org/981">981</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0422" seq="1999-0422">
<status>Entry</status>
<desc>In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</desc>
<refs>
<ref source="NETBSD">1999-007</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0423" seq="1999-0423">
<status>Entry</status>
<desc>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
<ref source="XF">hp-hpterm-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0424" seq="1999-0424">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0425" seq="1999-0425">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0428" seq="1999-0428">
<status>Entry</status>
<desc>OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</desc>
<refs>
<ref source="BUGTRAQ">19990322 OpenSSL/SSLeay Security Alert</ref>
<ref source="XF">ssl-session-reuse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0429" seq="1999-0429">
<status>Entry</status>
<desc>The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref>
<ref source="XF">lotus-client-encryption</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0430" seq="1999-0430">
<status>Entry</status>
<desc>Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</desc>
<refs>
<ref source="ISS">Remote Denial of Service Vulnerability in Cisco Catalyst Series Ethernet Switches</ref>
<ref source="CISCO">Cisco Catalyst Supervisor Remote Reload</ref>
<ref source="XF">cisco-catalyst-crash</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0432" seq="1999-0432">
<status>Entry</status>
<desc>ftp on HP-UX 11.00 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref>
<ref source="XF">hp-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0433" seq="1999-0433">
<status>Entry</status>
<desc>XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="SUSE">Mar28,1999</ref>
<ref source="BUGTRAQ">19990321 X11R6 NetBSD Security Problem</ref>
<ref source="XF">xfree86-temp-directories</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0436" seq="1999-0436">
<status>Entry</status>
<desc>Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref>
<ref source="XF">hp-desms-servers</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0437" seq="1999-0437">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-device-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0438" seq="1999-0438">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-ipchange</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0439" seq="1999-0439">
<status>Entry</status>
<desc>Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19990405 Re: [SECURITY] new version of procmail with security fixes</ref>
<ref source="DEBIAN">19990422</ref>
<ref source="CALDERA">CSSA-1999:007</ref>
<ref source="XF">procmail-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0440" seq="1999-0440">
<status>Entry</status>
<desc>The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
<ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref>
<ref source="XF">java-unverified-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0441" seq="1999-0441">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref>
<ref source="XF">wingate-redirector-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0442" seq="1999-0442">
<status>Entry</status>
<desc>Solaris ff.core allows local users to modify files.</desc>
<refs>
<ref source="BUGTRAQ">19990107 really silly ff.core exploit for Solaris</ref>
<ref source="BUGTRAQ">19990108 ff.core exploit on Solaris (2.)7</ref>
<ref source="BUGTRAQ">19990408 Solaris7 and ff.core</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0445" seq="1999-0445">
<status>Entry</status>
<desc>In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</desc>
<refs>
<ref source="CISCO">Cisco IOS(R) Software Input Access List Leakage with NAT</ref>
<ref source="XF">cisco-natacl-leakage</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0446" seq="1999-0446">
<status>Entry</status>
<desc>Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</desc>
<refs>
<ref source="NETBSD">1999-008</ref>
<ref source="XF">netbsd-vfslocking-panic</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0447" seq="1999-0447">
<status>Entry</status>
<desc>Local users can gain privileges using the debug utility in the MPE/iX operating system.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref>
<ref source="XF">mpeix-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0448" seq="1999-0448">
<status>Entry</status>
<desc>IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</desc>
<refs>
<ref source="BUGTRAQ">19990121 IIS 4 Request Logging Security Advisory</ref>
<ref source="XF">iis-http-request-logging</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0449" seq="1999-0449">
<status>Entry</status>
<desc>The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</desc>
<refs>
<ref source="BUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="NTBUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BUGTRAQ">19990125 Re: [NTSEC] IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2">2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3">3</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4">4</ref>
<ref source="XF">iis-exair-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0457" seq="1999-0457">
<status>Entry</status>
<desc>Linux ftpwatch program allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">Jan17,1999</ref>
<ref source="DEBIAN">19990117</ref>
<ref source="XF">ftpwatch-vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0458" seq="1999-0458">
<status>Entry</status>
<desc>L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</desc>
<refs>
<ref source="BUGTRAQ">Jan6,1999</ref>
<ref source="XF">l0phtcrack-temp-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/915">915</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0463" seq="1999-0463">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service using IRIX fcagent.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref>
<ref source="XF">sgi-fcagent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0464" seq="1999-0464">
<status>Entry</status>
<desc>Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref>
<ref source="CONFIRM" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6609">6609</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0466" seq="1999-0466">
<status>Entry</status>
<desc>The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</desc>
<refs>
<ref source="NETBSD">1999-009</ref>
<ref source="OSVDB" url="http://www.osvdb.org/905">905</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0468" seq="1999-0468">
<status>Entry</status>
<desc>Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref>
<ref source="XF">ie-scriplet-fileread</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0470" seq="1999-0470">
<status>Entry</status>
<desc>A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</desc>
<refs>
<ref source="BUGTRAQ">19990409 New Novell Remote.NLM Password Decryption Algorithm with Exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref>
<ref source="XF">netware-remotenlm-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0471" seq="1999-0471">
<status>Entry</status>
<desc>The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the &quot;cancel&quot; button.</desc>
<refs>
<ref source="XF">winroute-config</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0472" seq="1999-0472">
<status>Entry</status>
<desc>The SNMP default community name &quot;public&quot; is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</desc>
<refs>
<ref source="XF">netcache-snmp</ref>
<ref source="BUGTRAQ">Apr7,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0473" seq="1999-0473">
<status>Entry</status>
<desc>The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</desc>
<refs>
<ref source="BUGTRAQ">19990407 rsync 2.3.1 release - security fix</ref>
<ref source="CALDERA">CSSA-1999:010.0</ref>
<ref source="DEBIAN">19990823</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref>
<ref source="XF">rsync-permissions</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0474" seq="1999-0474">
<status>Entry</status>
<desc>The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</desc>
<refs>
<ref source="XF">icq-webserver-read</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0475" seq="1999-0475">
<status>Entry</status>
<desc>A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</desc>
<refs>
<ref source="XF">procmail-race</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0478" seq="1999-0478">
<status>Entry</status>
<desc>Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref>
<ref source="XF">sendmail-headers-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0479" seq="1999-0479">
<status>Entry</status>
<desc>Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref>
<ref source="XF">netscape-server-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0481" seq="1999-0481">
<status>Entry</status>
<desc>Denial of service in &quot;poll&quot; in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Mar22,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7556">7556</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0482" seq="1999-0482">
<status>Entry</status>
<desc>OpenBSD kernel crash through TSS handling, as caused by the crashme program.</desc>
<refs>
<ref source="OPENBSD">Mar21,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7557">7557</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0483" seq="1999-0483">
<status>Entry</status>
<desc>OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</desc>
<refs>
<ref source="OPENBSD">Feb25,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6129">6129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0484" seq="1999-0484">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD ping.</desc>
<refs>
<ref source="OPENBSD">Feb23,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6130">6130</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0485" seq="1999-0485">
<status>Entry</status>
<desc>Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Feb19,1999</ref>
<ref source="XF">openbsd-ipintr-race</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7558">7558</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0487" seq="1999-0487">
<status>Entry</status>
<desc>The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx">MS99-011</ref>
<ref source="XF">ie-dhtml-control</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0491" seq="1999-0491">
<status>Entry</status>
<desc>The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org">19990420 Bash Bug</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt">CSSA-1999-008.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0493" seq="1999-0493">
<status>Entry</status>
<desc>rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0494" seq="1999-0494">
<status>Entry</status>
<desc>Denial of service in WinGate proxy through a buffer overflow in POP3.</desc>
<refs>
<ref source="XF">wingate-pop3-user-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0496" seq="1999-0496">
<status>Entry</status>
<desc>A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q146965">Q146965</ref>
<ref source="XF">nt-getadmin</ref>
<ref source="XF">nt-getadmin-present</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0513" seq="1999-0513">
<status>Entry</status>
<desc>ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</desc>
<refs>
<ref source="CERT">CA-98.01.smurf</ref>
<ref source="FREEBSD">FreeBSD-SA-98:06</ref>
<ref source="XF">smurf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0514" seq="1999-0514">
<status>Entry</status>
<desc>UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</desc>
<refs>
<ref source="XF">fraggle</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0526" seq="1999-0526">
<status>Entry</status>
<desc>An X server's access control is disabled (e.g. through an &quot;xhost +&quot; command) and allows anyone to connect to the server.</desc>
<refs>
<ref source="XF">xcheck-keystroke</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0551" seq="1999-0551">
<status>Entry</status>
<desc>HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078">HPSBUX9804-078</ref>
<ref source="XF">hp-openmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0566" seq="1999-0566">
<status>Entry</status>
<desc>An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</desc>
<refs>
<ref source="XF">ibm-syslogd</ref>
<ref source="XF">syslog-flood</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0608" seq="1999-0608">
<status>Entry</status>
<desc>An incorrect configuration of the PDG Shopping Cart CGI program &quot;shopper.cgi&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
<ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security.html.">http://www.pdgsoft.com/Security/security.html.</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3857">pdgsoftcart-misconfig(3857)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0612" seq="1999-0612">
<status>Entry</status>
<desc>A version of finger is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">finger-out</ref>
<ref source="XF">finger-running</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0626" seq="1999-0626">
<status>Entry</status>
<desc>A version of rusers is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">rusersd</ref>
<ref source="XF">ruser</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0627" seq="1999-0627">
<status>Entry</status>
<desc>The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</desc>
<refs>
<ref source="XF">rexd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0628" seq="1999-0628">
<status>Entry</status>
<desc>The rwho/rwhod service is running, which exposes machine status and user information.</desc>
<refs>
<ref source="XF">rwhod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0668" seq="1999-0668">
<status>Entry</status>
<desc>The scriptlet.typelib ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</desc>
<refs>
<ref source="BUGTRAQ">19990821 IE 5.0 allows executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/598">598</ref>
<ref source="XF">ms-scriptlet-eyedog-unsafe</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240308">Q240308</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0671" seq="1999-0671">
<status>Entry</status>
<desc>Buffer overflow in ToxSoft NextFTP client through CWD command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/572">572</ref>
<ref source="XF">toxsoft-nextftp-cwd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0672" seq="1999-0672">
<status>Entry</status>
<desc>Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</desc>
<refs>
<ref source="XF">fujitsu-topic-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/573">573</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0674" seq="1999-0674">
<status>Entry</status>
<desc>The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</desc>
<refs>
<ref source="NETBSD">1999-011</ref>
<ref source="OPENBSD">Aug 9,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:02</ref>
<ref source="BUGTRAQ">19990809 profil(2) bug, a simple test program</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/570">570</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-067.shtml">J-067</ref>
<ref source="XF">netbsd-profil</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0675" seq="1999-0675">
<status>Entry</status>
<desc>Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/23615">19990809 FW1 UDP Port 0 DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/576">576</ref>
<ref source="XF">checkpoint-port</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1038">1038</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0676" seq="1999-0676">
<status>Entry</status>
<desc>sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org">19990808 sdtcm_convert</ref>
<ref source="XF">sun-sdtcm-convert</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/575">575</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0678" seq="1999-0678">
<status>Entry</status>
<desc>A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</desc>
<refs>
<ref source="XF">apache-debian-usrdoc</ref>
<ref source="BUGTRAQ">19990405 An issue with Apache on Debian</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/318">318</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0679" seq="1999-0679">
<status>Entry</status>
<desc>Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</desc>
<refs>
<ref source="BUGTRAQ">19990813 w00w00's efnet ircd advisory (exploit included)</ref>
<ref source="CONFIRM" url="http://www.efnet.org/archive/servers/hybrid/ChangeLog">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/581">581</ref>
<ref source="XF">hybrid-ircd-minvite-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0680" seq="1999-0680">
<status>Entry</status>
<desc>Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx">MS99-028</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238600">Q238600</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-057.shtml">J-057</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/571">571</ref>
<ref source="XF">nt-terminal-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0681" seq="1999-0681">
<status>Entry</status>
<desc>Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html">19990807 Crash FrontPage Remotely...</ref>
<ref source="XF" url="http://xforce.iss.net/static/3117.php">frontpage-pws-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/568">568</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0682" seq="1999-0682">
<status>Entry</status>
<desc>Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx">MS99-027</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237927">Q237927</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/567">567</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-056.shtml">J-056</ref>
<ref source="XF">exchange-relay</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0683" seq="1999-0683">
<status>Entry</status>
<desc>Denial of service in Gauntlet Firewall via a malformed ICMP packet.</desc>
<refs>
<ref source="XF">gauntlet-dos</ref>
<ref source="BUGTRAQ">19990729 Remotely Lock Up Gauntlet 5.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/556">556</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1029">1029</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0685" seq="1999-0685">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Netscape communicator 4.06J, 4.5J-4.6J, 4.61e Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/618">618</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0686" seq="1999-0686">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990514 TGAD DoS</ref>
<ref source="BUGTRAQ">19990610 Re: VVOS/Netscape Bug</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098">HPSBUX9906-098</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-046.shtml">J-046</ref>
<ref source="XF">hp-tgad-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0687" seq="1999-0687">
<status>Entry</status>
<desc>The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in ttsession</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRT0617U_TTSESSION</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-001.shtml">K-001</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/637">637</ref>
<ref source="XF">cde-ttsession-rpc-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0688" seq="1999-0688">
<status>Entry</status>
<desc>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101">HPSBUX9907-101</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/545">545</ref>
<ref source="XF">hp-sd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0689" seq="1999-0689">
<status>Entry</status>
<desc>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtspcd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880">oval:org.mitre.oval:def:1880</ref>
<ref source="XF">cde-dtspcd-file-auth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/636">636</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0690" seq="1999-0690">
<status>Entry</status>
<desc>HP CDE program includes the current directory in root's PATH variable.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100">HPSBUX9907-100</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-053.shtml">J-053</ref>
<ref source="XF">hp-cde-directory</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0691" seq="1999-0691">
<status>Entry</status>
<desc>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtaction</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRTO615U_DTACTION</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/635">635</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078">oval:org.mitre.oval:def:3078</ref>
<ref source="XF">cde-dtaction-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0692" seq="1999-0692">
<status>Entry</status>
<desc>The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-09</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-052.shtml">J-052</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P">19990701-01-P</ref>
<ref source="XF">sgi-arrayd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0693" seq="1999-0693">
<status>Entry</status>
<desc>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/641">641</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374">oval:org.mitre.oval:def:4374</ref>
<ref source="XF">cde-dtsession-env-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0694" seq="1999-0694">
<status>Entry</status>
<desc>Denial of service in AIX ptrace system call allows local users to crash the system.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-055.shtml">J-055</ref>
<ref source="IBM">ERS-SVA-E01-1999:002.1</ref>
<ref source="XF">aix-ptrace-halt</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0695" seq="1999-0695">
<status>Entry</status>
<desc>The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990904 [Sybase] software vendors do not think about old bugs</ref>
<ref source="XF">http-powerdynamo-dotdotslash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/620">620</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1064">1064</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0696" seq="1999-0696">
<status>Entry</status>
<desc>Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</desc>
<refs>
<ref source="BUGTRAQ">19990709 Exploit of rpc.cmsd</ref>
<ref source="SCO">SB-99.12</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188">00188</ref>
<ref source="SUNBUG">4230754</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102">HPSBUX9908-102</ref>
<ref source="COMPAQ">SSRT0614U_RPC_CMSD</ref>
<ref source="CERT">CA-99-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-051.shtml">J-051</ref>
<ref source="XF">sun-cmsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0697" seq="1999-0697">
<status>Entry</status>
<desc>SCO Doctor allows local users to gain root privileges through a Tools option.</desc>
<refs>
<ref source="BUGTRAQ">19990908 SCO 5.0.5 /bin/doctor nightmare</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/621">621</ref>
<ref source="XF">sco-doctor-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0699" seq="1999-0699">
<status>Entry</status>
<desc>The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</desc>
<refs>
<ref source="BUGTRAQ">19990908 [Security] Spoofed Id in Bluestone Sapphire/Web</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/623">623</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0700" seq="1999-0700">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237185">Q237185</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx">MS99-026</ref>
<ref source="XF">nt-malformed-dialer</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0701" seq="1999-0701">
<status>Entry</status>
<desc>After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx">MS99-036</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q173039">Q173039</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/626">626</ref>
<ref source="XF">nt-install-unattend-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0702" seq="1999-0702">
<status>Entry</status>
<desc>Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the &quot;ImportExportFavorites&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ">19990909 IE 5.0 security vulnerabilities - ImportExportFavorites - at least creating and overwriting files, probably executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx">MS99-037</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241361">Q241361</ref>
<ref source="XF">ie5-import-export-favorites</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/627">627</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0703" seq="1999-0703">
<status>Entry</status>
<desc>OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</desc>
<refs>
<ref source="BUGTRAQ">19990805 4.4 BSD issue -- chflags</ref>
<ref source="OPENBSD">Jul30,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:01</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-066.shtml">J-066</ref>
<ref source="XF">openbsd-chflags-fchflags-permitted</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0704" seq="1999-0704">
<status>Entry</status>
<desc>Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:032-01</ref>
<ref source="CALDERA">CSSA-1999:024.0</ref>
<ref source="FREEBSD">SA-99:06</ref>
<ref source="DEBIAN">19991018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/614">614</ref>
<ref source="CERT">CA-99-12</ref>
<ref source="XF">amd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0705" seq="1999-0705">
<status>Entry</status>
<desc>Buffer overflow in INN inews program.</desc>
<refs>
<ref source="XF">inn-inews-bo</ref>
<ref source="REDHAT">RHSA1999033_01</ref>
<ref source="CALDERA">CSSA-1999-026</ref>
<ref source="SUSE">19990831 Security hole in INN</ref>
<ref source="DEBIAN">19990907</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/616">616</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0706" seq="1999-0706">
<status>Entry</status>
<desc>Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</desc>
<refs>
<ref source="DEBIAN">19990807</ref>
<ref source="SUSE">19990817 Security hole in i4l (xmonisdn)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/583">583</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0707" seq="1999-0707">
<status>Entry</status>
<desc>The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099">HPSBUX9906-099</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-050.shtml">J-050</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/493">493</ref>
<ref source="XF">hp-visualize-conference-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0708" seq="1999-0708">
<status>Entry</status>
<desc>Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ">19990921 BP9909-00: cfingerd local buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/651">651</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0710" seq="1999-0710">
<status>Entry</status>
<desc>The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</desc>
<refs>
<ref source="BUGTRAQ">19990725 Redhat 6.0 cachemgr.cgi lameness</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid">http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-576">DSA-576</ref>
<ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
<ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-025.html">RHSA-1999:025</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2059">2059</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2385">http-cgi-cachemgr(2385)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0711" seq="1999-0711">
<status>Entry</status>
<desc>The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=92550157100002&amp;w=2&amp;r=1">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92609807906778&amp;w=2">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref>
<ref source="XF">oracle-oratclsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0713" seq="1999-0713">
<status>Entry</status>
<desc>The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990404 Digital Unix 4.0E /var permission</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-044.shtml">J-044</ref>
<ref source="XF">cde-dtlogin</ref>
<ref source="COMPAQ">SSRT0600U</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0714" seq="1999-0714">
<status>Entry</status>
<desc>Vulnerability in Compaq Tru64 UNIX edauth command.</desc>
<refs>
<ref source="COMPAQ">SSRT0588U</ref>
<ref source="XF">du-edauth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0715" seq="1999-0715">
<status>Entry</status>
<desc>Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</desc>
<refs>
<ref source="BUGTRAQ">19990519 Buffer Overruns in RAS allows execution of arbitary code as system</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx">MS99-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230677">Q230677</ref>
<ref source="XF">nt-ras-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0716" seq="1999-0716">
<status>Entry</status>
<desc>Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</desc>
<refs>
<ref source="XF">nt-helpfile-bo</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231605">Q231605</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS99-015</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0717" seq="1999-0717">
<status>Entry</status>
<desc>A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx">MS99-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231304">Q231304</ref>
<ref source="XF">excel-virus-warning</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0718" seq="1999-0718">
<status>Entry</status>
<desc>IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534">19990823 IBM Gina security warning</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/608">608</ref>
<ref source="XF" url="http://xforce.iss.net/static/3166.php">ibm-gina-group-add</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0719" seq="1999-0719">
<status>Entry</status>
<desc>The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</desc>
<refs>
<ref source="BUGTRAQ">19990802 Gnumeric potential security hole.</ref>
<ref source="REDHAT">RHSA-1999:023-01</ref>
<ref source="XF">gnu-guile-plugin-export</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/563">563</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0720" seq="1999-0720">
<status>Entry</status>
<desc>The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/597">597</ref>
<ref source="XF">linux-pt-chown</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0721" seq="1999-0721">
<status>Entry</status>
<desc>Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</desc>
<refs>
<ref source="BINDVIEW">Phantom Technical Advisory</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231457">Q231457</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx">MS99-020</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="XF">msrpc-lsa-lookupnames-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0722" seq="1999-0722">
<status>Entry</status>
<desc>The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</desc>
<refs>
<ref source="CERT">CA-99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/558">558</ref>
<ref source="XF">cobalt-raq2-default-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0723" seq="1999-0723">
<status>Entry</status>
<desc>The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</desc>
<refs>
<ref source="NTBUGTRAQ">19990411 Death by MessageBox</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx">MS99-021</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233323">Q233323</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/478">478</ref>
<ref source="XF">nt-csrss-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0724" seq="1999-0724">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</desc>
<refs>
<ref source="OPENBSD">Aug12,1999</ref>
<ref source="XF">openbsd-uio_offset-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6128">6128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0725" seq="1999-0725">
<status>Entry</status>
<desc>When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. &quot;Double Byte Code Page&quot;.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233335">Q233335</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx">MS99-022</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/477">477</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2302">iis-double-byte-code-page(2302)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0726" seq="1999-0726">
<status>Entry</status>
<desc>An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx">MS99-023</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234557">Q234557</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/499">499</ref>
<ref source="XF">nt-malformed-image-header</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0727" seq="1999-0727">
<status>Entry</status>
<desc>A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</desc>
<refs>
<ref source="OPENBSD">19990608 Packets that should have been handled by IPsec may be transmitted as cleartext</ref>
<ref source="XF">openbsd-ipsec-cleartext</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6127">6127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0728" seq="1999-0728">
<status>Entry</status>
<desc>A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx">MS99-024</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q236359">Q236359</ref>
<ref source="XF">nt-ioctl-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0729" seq="1999-0729">
<status>Entry</status>
<desc>Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise34.php">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-061.shtml">J-061</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/601">601</ref>
<ref source="XF">lotus-ldap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1057">1057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0730" seq="1999-0730">
<status>Entry</status>
<desc>The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990612</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0731" seq="1999-0731">
<status>Entry</status>
<desc>The KDE klock program allows local users to unlock a session using malformed input.</desc>
<refs>
<ref source="BUGTRAQ">19990623 Security flaw in klock</ref>
<ref source="CALDERA">CSSA-1999:017</ref>
<ref source="SUSE">19990629 Security hole in Klock</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/489">489</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0732" seq="1999-0732">
<status>Entry</status>
<desc>The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</desc>
<refs>
<ref source="DEBIAN">19990823b</ref>
<ref source="XF">smtp-refuser-tmp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0733" seq="1999-0733">
<status>Entry</status>
<desc>Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990626 VMWare Advisory - buffer overflows</ref>
<ref source="BUGTRAQ">19990626 VMware Security Alert</ref>
<ref source="BUGTRAQ">19990705 Re: VMWare Advisory.. - exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/490">490</ref>
<ref source="XF">vmware-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0734" seq="1999-0734">
<status>Entry</status>
<desc>A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</desc>
<refs>
<ref source="CISCO"> CiscoSecure Access Control Server for UNIX Remote Administration Vulnerability</ref>
<ref source="XF">ciscosecure-read-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0735" seq="1999-0735">
<status>Entry</status>
<desc>KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</desc>
<refs>
<ref source="ISS">KDE K-Mail File Creation Vulnerability</ref>
<ref source="CALDERA">CSSA-1999:016</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/300">300</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0740" seq="1999-0740">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/594">594</ref>
<ref source="XF">linux-telnetd-term</ref>
<ref source="CALDERA">CSSA-1999:022</ref>
<ref source="REDHAT">RHSA1999029_01</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0742" seq="1999-0742">
<status>Entry</status>
<desc>The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</desc>
<refs>
<ref source="DEBIAN">19990623</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/480">480</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0743" seq="1999-0743">
<status>Entry</status>
<desc>Trn allows local users to overwrite other users' files via symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990819 Insecure use of file in /tmp by trn</ref>
<ref source="DEBIAN">19990823c</ref>
<ref source="SUSE">19990824 Security hole in trn</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3144">trn-symlinks(3144)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0744" seq="1999-0744">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</desc>
<refs>
<ref source="ISS">Buffer Overflow in Netscape Enterprise and FastTrack Web Servers</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/603">603</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0745" seq="1999-0745">
<status>Entry</status>
<desc>Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</desc>
<refs>
<ref source="IBM">ERS-SVA-E01-1999:003.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-059.shtml">J-059</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/590">590</ref>
<ref source="XF">aix-pdnsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0746" seq="1999-0746">
<status>Entry</status>
<desc>A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990814 DOS against SuSE's identd</ref>
<ref source="SUSE">19990824 Security hole in netcfg</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/587">587</ref>
<ref source="XF">suse-identd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0747" seq="1999-0747">
<status>Entry</status>
<desc>Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/589">589</ref>
<ref source="XF">bsdi-smp-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0749" seq="1999-0749">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</desc>
<refs>
<ref source="BUGTRAQ">19990815 telnet.exe heap overflow - remotely exploitable</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx">MS99-033</ref>
<ref source="XF">win-ie5-telnet-heap-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/586">586</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0751" seq="1999-0751">
<status>Entry</status>
<desc>Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Accept overflow on Netscape Enterprise Server 3.6 SP2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/631">631</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3256">netscape-accept-bo(3256)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0752" seq="1999-0752">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</desc>
<refs>
<ref source="BUGTRAQ">19990706 Netscape Enterprise Server SSL Handshake Bug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0753" seq="1999-0753">
<status>Entry</status>
<desc>The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Stupid bug in W3-msql</ref>
<ref source="XF">mini-sql-w3-msql-cgi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/591">591</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0754" seq="1999-0754">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt">CSSA-1999-011.0</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="MISC" url="http://www.redhat.com/corp/support/errata/inn99_05_22.html">http://www.redhat.com/corp/support/errata/inn99_05_22.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/255">255</ref>
<ref source="XF">inn-innconf-env</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0755" seq="1999-0755">
<status>Entry</status>
<desc>Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the &quot;Save password&quot; option.</desc>
<refs>
<ref source="XF">nt-ras-pwcache</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230681">Q230681</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx">MS99-017</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0756" seq="1999-0756">
<status>Entry</status>
<desc>ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full">ASB99-07</ref>
<ref source="XF" url="http://xforce.iss.net/static/2207.php">coldfusion-admin-dos(2207)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0758" seq="1999-0758">
<status>Entry</status>
<desc>Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.</desc>
<refs>
<ref source="ALLAIRE">ASB99-06</ref>
<ref source="XF">netscape-space-view</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0759" seq="1999-0759">
<status>Entry</status>
<desc>Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
<ref source="CONFIRM" url="http://www.crosswinds.net/~fuseware/faq.html#8">http://www.crosswinds.net/~fuseware/faq.html#8</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/634">634</ref>
<ref source="XF">fuseware-popmail-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0760" seq="1999-0760">
<status>Entry</status>
<desc>Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full">ASB99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/550">550</ref>
<ref source="XF" url="http://xforce.iss.net/static/3288.php">coldfusion-server-cfml-tags</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0761" seq="1999-0761">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-99:05</ref>
<ref source="XF">freebsd-fts-lib-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/644">644</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1074">1074</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0762" seq="1999-0762">
<status>Entry</status>
<desc>When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the &quot;about&quot; protocol to gain access to browser information.</desc>
<refs>
<ref source="XF">netscape-title</ref>
<ref source="BUGTRAQ">19990524 Netscape Communicator JavaScript in &lt;TITLE&gt; security vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0763" seq="1999-0763">
<status>Entry</status>
<desc>NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6540">6540</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0764" seq="1999-0764">
<status>Entry</status>
<desc>NetBSD allows ARP packets to overwrite static ARP entries.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6539">6539</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0765" seq="1999-0765">
<status>Entry</status>
<desc>SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</desc>
<refs>
<ref source="BUGTRAQ">19990619 IRIX midikeys root exploit.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A">19990501-01-A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/262">262</ref>
<ref source="XF">irix-midikeys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0766" seq="1999-0766">
<status>Entry</status>
<desc>The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx">MS99-031</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240346">Q240346</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/600">600</ref>
<ref source="XF">msvm-verifier-java</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0768" seq="1999-0768">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/602">602</ref>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0769" seq="1999-0769">
<status>Entry</status>
<desc>Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="CALDERA">CSSA-1999:023.0</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
<ref source="DEBIAN">19990830 cron</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0770" seq="1999-0770">
<status>Entry</status>
<desc>Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</desc>
<refs>
<ref source="BUGTRAQ">19990729 Simple DOS attack on FW-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/549">549</ref>
<ref source="CHECKPOINT">ACK DOS ATTACK</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1027">1027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0771" seq="1999-0771">
<status>Entry</status>
<desc>The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Infosec.19990526.compaq-im.a</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-file-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0772" seq="1999-0772">
<status>Entry</status>
<desc>Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</desc>
<refs>
<ref source="BUGTRAQ">19990527 Re: Infosec.19990526.compaq-im.a (New DoS and correction to my previous post)</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0773" seq="1999-0773">
<status>Entry</status>
<desc>Buffer overflow in Solaris lpset program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017">19990511 Solaris2.6 and 2.7 lpset overflow</ref>
<ref source="XF">sol-lpset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0774" seq="1999-0774">
<status>Entry</status>
<desc>Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</desc>
<refs>
<ref source="BUGTRAQ">19990830 Babcia Padlina Ltd. security advisory: mars_nwe buffer overf</ref>
<ref source="REDHAT">RHSA1999037_01</ref>
<ref source="SUSE">19990916 Security hole in mars nwe</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/617">617</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0775" seq="1999-0775">
<status>Entry</status>
<desc>Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the &quot;established&quot; keyword in an access list.</desc>
<refs>
<ref source="CISCO">19990610 Cisco IOS Software established Access List Keyword Error</ref>
<ref source="XF">cisco-gigaswitch</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0777" seq="1999-0777">
<status>Entry</status>
<desc>IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have &quot;No Access&quot; permissions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241407">Q241407</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242559">Q242559</ref>
<ref source="XF">iis-ftp-no-access-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/658">658</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0778" seq="1999-0778">
<status>Entry</status>
<desc>Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</desc>
<refs>
<ref source="BUGTRAQ">19990626 KSR[T] #011: Accelerated-X</ref>
<ref source="KSRT">011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/488">488</ref>
<ref source="XF">accelx-display-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0779" seq="1999-0779">
<status>Entry</status>
<desc>Denial of service in HP-UX SharedX recserv program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086">HPSBUX9810-086</ref>
<ref source="XF">hp-sharedx</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0780" seq="1999-0780">
<status>Entry</status>
<desc>KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-process-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0781" seq="1999-0781">
<status>Entry</status>
<desc>KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-bindir-trojans</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0782" seq="1999-0782">
<status>Entry</status>
<desc>KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-kppp-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0783" seq="1999-0783">
<status>Entry</status>
<desc>FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:05</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-057.shtml">I-057</ref>
<ref source="XF">freebsd-nfs-link-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6090">6090</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0785" seq="1999-0785">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain root privileges via the &quot;pathrun&quot; parameter in the inn.conf file.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="XF">inn-pathrun</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/254">254</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0786" seq="1999-0786">
<status>Entry</status>
<desc>The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990922 LD_PROFILE local root exploit for solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/659">659</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0787" seq="1999-0787">
<status>Entry</status>
<desc>The SSH authentication agent follows symlinks via a UNIX domain socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93832856804415&amp;w=2">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref>
<ref source="XF">ssh-socket-auth-symlink-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/660">660</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0788" seq="1999-0788">
<status>Entry</status>
<desc>Arkiea nlservd allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/662">662</ref>
<ref source="XF">arkiea-backup-nlserverd-remote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0789" seq="1999-0789">
<status>Entry</status>
<desc>Buffer overflow in AIX ftpd in the libc library.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Remote bufferoverflow exploit for ftpd from AIX 4.3.2 running on an RS6000</ref>
<ref source="IBM">ERS-SVA-E01-1999:004.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-072.shtml">J-072</ref>
<ref source="XF">aix-ftpd-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/679">679</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0790" seq="1999-0790">
<status>Entry</status>
<desc>A remote attacker can read information from a Netscape user's cache via JavaScript.</desc>
<refs>
<ref source="MISC" url="http://home.netscape.com/security/notes/jscachebrowsing.html">http://home.netscape.com/security/notes/jscachebrowsing.html</ref>
<ref source="XF">netscape-javascript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0791" seq="1999-0791">
<status>Entry</status>
<desc>Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</desc>
<refs>
<ref source="BUGTRAQ">19991006 KSR[T] Advisories #012: Hybrid Network's Cable Modems</ref>
<ref source="KSRT">012</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/695">695</ref>
<ref source="XF">hybrid-anon-cable-modem-reconfig</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0793" seq="1999-0793">
<status>Entry</status>
<desc>Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx">MS99-043</ref>
<ref source="XF">ie-java-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0794" seq="1999-0794">
<status>Entry</status>
<desc>Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx">MS99-044</ref>
<ref source="XF">excel-sylk</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241900">Q241900</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241901">Q241901</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241902">Q241902</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0796" seq="1999-0796">
<status>Entry</status>
<desc>FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</desc>
<refs>
<ref source="FREEBSD">SA-98.03</ref>
<ref source="XF">freebsd-ttcp-spoof</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6089">6089</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0797" seq="1999-0797">
<status>Entry</status>
<desc>NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</desc>
<refs>
<ref source="ISS">19980629 Distributed DoS attack against NIS/NIS+ based networks.</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-070.shtml">I-070</ref>
<ref source="XF">sun-nis-nisplus</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0799" seq="1999-0799">
<status>Entry</status>
<desc>Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</desc>
<refs>
<ref source="BUGTRAQ">19970725 Exploitable buffer overflow in bootpd (most unices)</ref>
<ref source="XF">bootpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0800" seq="1999-0800">
<status>Entry</status>
<desc>The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full">ASB99-05</ref>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html">19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1748">allaire-forums-file-read(1748)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/944">944</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0801" seq="1999-0801">
<status>Entry</status>
<desc>BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2075.php">bmc-patrol-frames(2075)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0802" seq="1999-0802">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</desc>
<refs>
<ref source="BUGTRAQ">19990503 MSIE 5 FAVICON BUG</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231450">Q231450</ref>
<ref source="XF">ie-favicon</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0803" seq="1999-0803">
<status>Entry</status>
<desc>The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92765973207648&amp;w=2">19990525 IBM eNetwork Firewall for AIX</ref>
<ref source="XF">ibm-enfirewall-tmpfiles</ref>
<ref source="OSVDB" url="http://www.osvdb.org/962">962</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0804" seq="1999-0804">
<status>Entry</status>
<desc>Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</desc>
<refs>
<ref source="BUGTRAQ">19990601 Linux kernel 2.2.x vulnerability/exploit</ref>
<ref source="DEBIAN">19990607</ref>
<ref source="CALDERA">CSSA-1999:013</ref>
<ref source="SUSE">19990602 Denial of Service on the 2.2 kernel</ref>
<ref source="REDHAT">19990603 Kernel Update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/302">302</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0806" seq="1999-0806">
<status>Entry</status>
<desc>Buffer overflow in Solaris dtprintinfo program.</desc>
<refs>
<ref source="BUGTRAQ">19990510 Solaris2.6,2.7 dtprintinfo exploits</ref>
<ref source="XF">cde-dtprintinfo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6552">6552</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0807" seq="1999-0807">
<status>Entry</status>
<desc>The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</desc>
<refs>
<ref source="XF">netscape-dirsvc-password</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0809" seq="1999-0809">
<status>Entry</status>
<desc>Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to &quot;Only accept cookies originating from the same server as the page being viewed&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19990709 Communicator 4.[56]x, JavaScript used to bypass cookie settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0810" seq="1999-0810">
<status>Entry</status>
<desc>Denial of service in Samba NETBIOS name service daemon (nmbd).</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0811" seq="1999-0811">
<status>Entry</status>
<desc>Buffer overflow in Samba smbd program via a malformed message command.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
<ref source="DEBIAN">19990731 Samba</ref>
<ref source="XF">samba-message-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/536">536</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0812" seq="1999-0812">
<status>Entry</status>
<desc>Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0813" seq="1999-0813">
<status>Entry</status>
<desc>Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Severe bug in cfingerd before 1.4.0</ref>
<ref source="BUGTRAQ">19980724 CFINGERD root security hole</ref>
<ref source="DEBIAN">19990814</ref>
<ref source="XF">cfingerd-privileges</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0814" seq="1999-0814">
<status>Entry</status>
<desc>Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-027.html">RHSA-1999:027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0815" seq="1999-0815">
<status>Entry</status>
<desc>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp">Q196270</ref>
<ref source="XF" url="http://xforce.iss.net/static/1974.php">nt-snmpagent-leak(1974)</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952">oval:org.mitre.oval:def:952</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0817" seq="1999-0817">
<status>Entry</status>
<desc>Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</desc>
<refs>
<ref source="SUSE">19990915 Security hole in lynx</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0819" seq="1999-0819">
<status>Entry</status>
<desc>NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 NTmail and VRFY</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94398141118586&amp;w=2">19991130 NTmail and VRFY</ref>
<ref source="XF">nt-mail-vrfy</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0820" seq="1999-0820">
<status>Entry</status>
<desc>FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
<ref source="XF">freebsd-seyon-dir-add</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5996">5996</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0823" seq="1999-0823">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/839">839</ref>
<ref source="XF">freebsd-xmindpath</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1150">1150</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0824" seq="1999-0824">
<status>Entry</status>
<desc>A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/833">833</ref>
<ref source="NTBUGTRAQ">19991130 SUBST problem</ref>
<ref source="BUGTRAQ">19991130 Subst.exe carelessness (fwd)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0826" seq="1999-0826">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD angband allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/840">840</ref>
<ref source="XF">angband-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1151">1151</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0831" seq="1999-0831">
<status>Entry</status>
<desc>Denial of service in Linux syslogd via a large number of connections.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt">CSSA-1999-035.0</ref>
<ref source="REDHAT">RHSA1999055-01</ref>
<ref source="SUSE">19991118 syslogd-1.3.33 (a1)</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/809">809</ref>
<ref source="XF">slackware-syslogd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0832" seq="1999-0832">
<status>Entry</status>
<desc>Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl">19991109 undocumented bugs - nfsd</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19991111">19991111 buffer overflow in nfs server</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt">CSSA-1999-033.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS">RHSA-1999:053-01</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="XF">linux-nfs-maxpath-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/782">782</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0833" seq="1999-0833">
<status>Entry</status>
<desc>Buffer overflow in BIND 8.2 via NXT records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-nxt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0834" seq="1999-0834">
<status>Entry</status>
<desc>Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</desc>
<refs>
<ref source="BUGTRAQ">19991201 Security Advisory: Buffer overflow in RSAREF2</ref>
<ref source="BUGTRAQ">19991202 OpenBSD sslUSA26 advisory (Re: CORE-SDI: Buffer overflow in RSAREF2)</ref>
<ref source="CERT">CA-99-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/843">843</ref>
<ref source="XF">rsaref-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0835" seq="1999-0835">
<status>Entry</status>
<desc>Denial of service in BIND named via malformed SIG records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-sigrecord-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0836" seq="1999-0836">
<status>Entry</status>
<desc>UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net">19991202 UnixWare 7 uidadmin exploit + discussion</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a">SB-99.22a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/842">842</ref>
<ref source="XF">unixware-uid-admin</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0837" seq="1999-0837">
<status>Entry</status>
<desc>Denial of service in BIND by improperly closing TCP sessions via so_linger.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-solinger-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0838" seq="1999-0838">
<status>Entry</status>
<desc>Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Remote DoS Attack in Serv-U FTP-Server v2.5a Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/859">859</ref>
<ref source="XF">servu-ftp-site-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0839" seq="1999-0839">
<status>Entry</status>
<desc>Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 Windows NT Task Scheduler vulnerability allows user to administrator elevation</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx">MS99-051</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246972">Q246972</ref>
<ref source="XF">ie-task-scheduler-privs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/828">828</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0842" seq="1999-0842">
<status>Entry</status>
<desc>Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/827">827</ref>
<ref source="XF">symantec-mail-dir-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1144">1144</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0847" seq="1999-0847">
<status>Entry</status>
<desc>Buffer overflow in free internet chess server (FICS) program, xboard.</desc>
<refs>
<ref source="BUGTRAQ">19991129 FICS buffer overflow</ref>
<ref source="XF">fics-board-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0848" seq="1999-0848">
<status>Entry</status>
<desc>Denial of service in BIND named via consuming more than &quot;fdmax&quot; file descriptors.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-fdmax-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0849" seq="1999-0849">
<status>Entry</status>
<desc>Denial of service in BIND named via maxdname.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-maxdname-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0851" seq="1999-0851">
<status>Entry</status>
<desc>Denial of service in BIND named via naptr.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-naptr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0853" seq="1999-0853">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/847">847</ref>
<ref source="ISS">19991201 Buffer Overflow in Netscape Enterprise and FastTrack Authentication Procedure</ref>
<ref source="XF">netscape-fasttrack-auth-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0854" seq="1999-0854">
<status>Entry</status>
<desc>Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Ultimate Bulletin Board v5.3x? Bug</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
<ref source="CONFIRM" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
<ref source="XF">http-ultimate-bbs</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0856" seq="1999-0856">
<status>Entry</status>
<desc>login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Slackware 7.0 - login bug</ref>
<ref source="XF">slackware-remote-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0858" seq="1999-0858">
<status>Entry</status>
<desc>Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx">MS99-054</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247333">Q247333</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/846">846</ref>
<ref source="XF">ie-wpad-proxy-settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0859" seq="1999-0859">
<status>Entry</status>
<desc>Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Solaris 2.x chkperm/arp vulnerabilities</ref>
<ref source="SUNBUG">4296166</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
<ref source="XF">sol-arp-parse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6994">6994</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0861" seq="1999-0861">
<status>Entry</status>
<desc>Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx">MS99-053</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q244613">Q244613</ref>
<ref source="XF">iis-ssl-isapi-filter</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0864" seq="1999-0864">
<status>Entry</status>
<desc>UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net">19991202 UnixWare coredumps follow symlinks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="XF">sco-coredump-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/851">851</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0865" seq="1999-0865">
<status>Entry</status>
<desc>Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94426440413027&amp;w=2">19991203 CommuniGatePro 3.1 for NT DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94454565726775&amp;w=2">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/860">860</ref>
<ref source="XF">communigate-pro-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0866" seq="1999-0866">
<status>Entry</status>
<desc>Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</desc>
<refs>
<ref source="BUGTRAQ">19991203 UnixWare gain root with non-su/gid binaries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a">SB-99.24a</ref>
<ref source="XF">sco-xauto-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/848">848</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0867" seq="1999-0867">
<status>Entry</status>
<desc>Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx">MS99-029</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238349">Q238349</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-058.shtml">J-058</ref>
<ref source="XF">http-iis-malformed-header</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/579">579</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0868" seq="1999-0868">
<status>Entry</status>
<desc>ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</desc>
<refs>
<ref source="CERT">CA-97.08</ref>
<ref source="XF">inn-ucbmail-shell-meta</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0869" seq="1999-0869">
<status>Entry</status>
<desc>Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx">MS98-020</ref>
<ref source="MSKB">167614</ref>
<ref source="XF">http-frame-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0870" seq="1999-0870">
<status>Entry</status>
<desc>Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx">MS98-015</ref>
<ref source="MSKB">169245</ref>
<ref source="XF">ie-usp-cuartango</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0871" seq="1999-0871">
<status>Entry</status>
<desc>Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the &quot;Cross Frame Navigate&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx">MS98-013</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7837">7837</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3668">ie-crossframe-file-read(3668)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0873" seq="1999-0873">
<status>Entry</status>
<desc>Buffer overflow in Skyfull mail server via MAIL FROM command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
<ref source="XF">skyfull-mail-from-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0874" seq="1999-0874">
<status>Entry</status>
<desc>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-019.asp">MS99-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234905">Q234905</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD06081999.html">AD06081999</ref>
<ref source="CERT">CA-99-07</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-048.shtml">J-048</ref>
<ref source="XF">iis-htr-overflow</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915">oval:org.mitre.oval:def:915</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0875" seq="1999-0875">
<status>Entry</status>
<desc>DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</desc>
<refs>
<ref source="L0PHT">19990811</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q216141">Q216141</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/578">578</ref>
<ref source="XF">irdp-gateway-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0876" seq="1999-0876">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.0 via EMBED tag.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q185959">Q185959</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0877" seq="1999-0877">
<status>Entry</status>
<desc>Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243638">Q243638</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx">MS99-042</ref>
<ref source="XF">ie-iframe-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0878" seq="1999-0878">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</desc>
<refs>
<ref source="COMPAQ">SSRT0622</ref>
<ref source="REDHAT">RHSA1999031_01</ref>
<ref source="AUSCERT">AA-1999.01</ref>
<ref source="CERT">CA-99-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/599">599</ref>
<ref source="XF">wu-ftpd-dir-name</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0879" seq="1999-0879">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-message-file-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0880" seq="1999-0880">
<status>Entry</status>
<desc>Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-site-newer-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0881" seq="1999-0881">
<status>Entry</status>
<desc>Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991025 Falcon Web Server</ref>
<ref source="BINDVIEW">Falcon Web Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/743">743</ref>
<ref source="XF">falcon-path-parsing</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1127">1127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0883" seq="1999-0883">
<status>Entry</status>
<desc>Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1126">1126</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3380">zeus-remote-root(3380)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0884" seq="1999-0884">
<status>Entry</status>
<desc>The Zeus web server administrative interface uses weak encryption for its passwords.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8186">8186</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3833">zeus-weak-password(3833)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0886" seq="1999-0886">
<status>Entry</status>
<desc>The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242294">Q242294</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx">MS99-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/645">645</ref>
<ref source="XF">nt-rasman-pathname</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0887" seq="1999-0887">
<status>Entry</status>
<desc>FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991104 FTGate Version 2.1 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1137">1137</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0888" seq="1999-0888">
<status>Entry</status>
<desc>dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Security Bug in Oracle</ref>
<ref source="XF">oracle-dbsnmp</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/585">585</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0889" seq="1999-0889">
<status>Entry</status>
<desc>Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Cisco 675 password nonsense</ref>
<ref source="XF">cisco-cbos-telnet</ref>
<ref source="OSVDB" url="http://www.osvdb.org/39">39</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0890" seq="1999-0890">
<status>Entry</status>
<desc>iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Team Asylum: iHTML Merchant Vulnerabilities</ref>
<ref source="CONFIRM" url="http://www.ihtmlmerchant.com/support_patches_feedback.htm">http://www.ihtmlmerchant.com/support_patches_feedback.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/694">694</ref>
<ref source="XF">ihtml-merchant-file-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0891" seq="1999-0891">
<status>Entry</status>
<desc>The &quot;download behavior&quot; in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx">MS99-040</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242542">Q242542</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37828">VU#37828</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-002.shtml">K-002</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/674">674</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11274">11274</ref>
<ref source="XF">ie-download-behavior</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0892" seq="1999-0892">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</desc>
<refs>
<ref source="BUGTRAQ">19991018 Netscape 4.x buffer overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0893" seq="1999-0893">
<status>Entry</status>
<desc>userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991011 SCO OpenServer 5.0.5 overwrite /etc/shadow</ref>
<ref source="XF">sco-openserver-userosa-script</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0894" seq="1999-0894">
<status>Entry</status>
<desc>Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</desc>
<refs>
<ref source="REDHAT">RHSA1999042-01</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0895" seq="1999-0895">
<status>Entry</status>
<desc>Firewall-1 does not properly restrict access to LDAP attributes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/725">725</ref>
<ref source="XF">checkpoint-ldap-auth</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1117">1117</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0896" seq="1999-0896">
<status>Entry</status>
<desc>Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</desc>
<refs>
<ref source="BUGTRAQ">19991109 RealNetworks RealServer G2 buffer overflow.</ref>
<ref source="MISC" url="http://service.real.com/help/faq/servg260.html">http://service.real.com/help/faq/servg260.html</ref>
<ref source="XF">realserver-g2-pw-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/767">767</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0897" seq="1999-0897">
<status>Entry</status>
<desc>iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90538488231977&amp;w=2">19980908 bug in iChat 3.0 (maybe others)</ref>
<ref source="XF">ichat-file-read-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0898" seq="1999-0898">
<status>Entry</status>
<desc>Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/768">768</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0899" seq="1999-0899">
<status>Entry</status>
<desc>The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/769">769</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0900" seq="1999-0900">
<status>Entry</status>
<desc>Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0901" seq="1999-0901">
<status>Entry</status>
<desc>ypserv allows a local user to modify the GECOS and login shells of other users.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0902" seq="1999-0902">
<status>Entry</status>
<desc>ypserv allows local administrators to modify password tables.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0903" seq="1999-0903">
<status>Entry</status>
<desc>genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</desc>
<refs>
<ref source="BUGTRAQ">19991025 IBM AIX Packet Filter module</ref>
<ref source="BUGTRAQ">19991027 Re: IBM AIX Packet Filter module (followup)</ref>
<ref source="XF">aix-genfilt-filtering</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0904" seq="1999-0904">
<status>Entry</status>
<desc>Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</desc>
<refs>
<ref source="BUGTRAQ">19991103 Remote DoS Attack in BFTelnet Server v1.1 for Windows NT</ref>
<ref source="XF">bftelnet-username-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/771">771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0905" seq="1999-0905">
<status>Entry</status>
<desc>Denial of service in Axent Raptor firewall via malformed zero-length IP options.</desc>
<refs>
<ref source="BUGTRAQ">19991020 Remote DoS in Axent's Raptor 6.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/736">736</ref>
<ref source="XF">raptor-ipoptions-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1121">1121</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0906" seq="1999-0906">
<status>Entry</status>
<desc>Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990923 SuSE 6.2 sccw overflow exploit</ref>
<ref source="SUSE">19990926 Security hole in sccw (Part II)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/656">656</ref>
<ref source="XF">linux-sccw-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0907" seq="1999-0907">
<status>Entry</status>
<desc>sccw allows local users to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19990916 SuSE 6.2 /usr/bin/sccw read any file</ref>
<ref source="SUSE">19990921 Security Hole in sccw-1.1 and earlier</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0908" seq="1999-0908">
<status>Entry</status>
<desc>Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</desc>
<refs>
<ref source="BUGTRAQ">19990921 solaris DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/655">655</ref>
<ref source="XF">sun-tcp-mutex-enter-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0909" seq="1999-0909">
<status>Entry</status>
<desc>Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the &quot;Spoofed Route Pointer&quot; vulnerability.</desc>
<refs>
<ref source="NAI">Windows IP Source Routing Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx">MS99-038</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238453">Q238453</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/646">646</ref>
<ref source="XF">nt-ip-source-route</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0912" seq="1999-0912">
<status>Entry</status>
<desc>FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</desc>
<refs>
<ref source="BUGTRAQ">19990921 FreeBSD-specific denial of service</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/653">653</ref>
<ref source="XF">freebsd-vfscache-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1079">1079</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0914" seq="1999-0914">
<status>Entry</status>
<desc>Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</desc>
<refs>
<ref source="DEBIAN">19990104</ref>
<ref source="BUGTRAQ">19990103 [SECURITY] New versions of netstd fixes buffer overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0915" seq="1999-0915">
<status>Entry</status>
<desc>URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991028 URL Live! 1.0 WebServer</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/746">746</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1129">1129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0916" seq="1999-0916">
<status>Entry</status>
<desc>WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</desc>
<refs>
<ref source="ISS">19990629 Bad Permissions on Passwords Stored by WebTrends Software</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0917" seq="1999-0917">
<status>Entry</status>
<desc>The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231452">Q231452</ref>
<ref source="XF">legacy-activex-local-drive</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0918" seq="1999-0918">
<status>Entry</status>
<desc>Denial of service in various Windows systems via malformed, fragmented IGMP packets.</desc>
<refs>
<ref source="BUGTRAQ">19990703 IGMP fragmentation bug in Windows 98/2000</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238329">Q238329</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx">MS99-034</ref>
<ref source="XF">igmp-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/514">514</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0920" seq="1999-0920">
<status>Entry</status>
<desc>Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Remote vulnerability in pop2d</ref>
<ref source="DEBIAN">19990607a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/283">283</ref>
<ref source="XF">pop2-fold-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0921" seq="1999-0921">
<status>Entry</status>
<desc>BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4291.php">bmc-patrol-udp-dos(4291)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1879">1879</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0922" seq="1999-0922">
<status>Entry</status>
<desc>An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF">coldfusion-sourcewindow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0924" seq="1999-0924">
<status>Entry</status>
<desc>The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1742">coldfusion-syntax-checker(1742)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3236">3236</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0927" seq="1999-0927">
<status>Entry</status>
<desc>NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/279">279</ref>
<ref source="XF">ntmail-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0928" seq="1999-0928">
<status>Entry</status>
<desc>Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990525 Buffer overflow in SmartDesk WebSuite v2.1</ref>
<ref source="XF">websuite-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/278">278</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0930" seq="1999-0930">
<status>Entry</status>
<desc>wwwboard allows a remote attacker to delete message board articles via a malformed argument.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="CONFIRM" url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref>
<ref source="XF" url="http://xforce.iss.net/static/2344.php">http-cgi-wwwboard(2344)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1795">1795</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0931" seq="1999-0931">
<status>Entry</status>
<desc>Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/734">734</ref>
<ref source="XF">mediahouse-stats-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0932" seq="1999-0932">
<status>Entry</status>
<desc>Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/735">735</ref>
<ref source="XF">mediahouse-stats-adminpw-cleartext</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0933" seq="1999-0933">
<status>Entry</status>
<desc>TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991001 RFP9904: TeamTrack webserver vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/689">689</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1096">1096</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0934" seq="1999-0934">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2020">2020</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3102">http-cgi-classifieds-read(3102)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0935" seq="1999-0935">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0936" seq="1999-0936">
<status>Entry</status>
<desc>BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="EL8">19981203 BNBSurvey (survey.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0937" seq="1999-0937">
<status>Entry</status>
<desc>BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</desc>
<refs>
<ref source="EL8">19981203 BNBForm (bnbform.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0938" seq="1999-0938">
<status>Entry</status>
<desc>MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages.</desc>
<refs>
<ref source="CERT">VN-99-03</ref>
<ref source="XF">sdr-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0939" seq="1999-0939">
<status>Entry</status>
<desc>Denial of service in Debian IRC Epic/epic4 client via a long string.</desc>
<refs>
<ref source="BUGTRAQ">19990826 [SECURITY] New versions of epic4 fixes possible DoS vulnerability</ref>
<ref source="DEBIAN">19990826</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/605">605</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0940" seq="1999-0940">
<status>Entry</status>
<desc>Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</desc>
<refs>
<ref source="CALDERA">CSSA-1999-031</ref>
<ref source="SUSE">19990927 Security hole in mutt</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0942" seq="1999-0942">
<status>Entry</status>
<desc>UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</desc>
<refs>
<ref source="BUGTRAQ">19991005 SCO UnixWare 7.1 local root exploit</ref>
<ref source="XF">sco-unixware-dos7utils-root-privs</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0943" seq="1999-0943">
<status>Entry</status>
<desc>Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</desc>
<refs>
<ref source="BUGTRAQ">19991015 OpenLink 3.2 Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/720">720</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0945" seq="1999-0945">
<status>Entry</status>
<desc>Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise4.php">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-080.shtml">I-080</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q169174">Q169174</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1223">exchange-dos(1223)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0946" seq="1999-0946">
<status>Entry</status>
<desc>Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="XF">yamaha-midiplug-embed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/760">760</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0947" seq="1999-0947">
<status>Entry</status>
<desc>AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/762">762</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0950" seq="1999-0950">
<status>Entry</status>
<desc>Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</desc>
<refs>
<ref source="BUGTRAQ">19991027 WFTPD v2.40 FTPServer remotely exploitable buffer overflow vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/747">747</ref>
<ref source="XF">wftpd-mkd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0951" seq="1999-0951">
<status>Entry</status>
<desc>Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19991022 Imagemap CGI overflow exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/739">739</ref>
<ref source="XF">http-cgi-imagemap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3380">3380</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0953" seq="1999-0953">
<status>Entry</status>
<desc>WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0954" seq="1999-0954">
<status>Entry</status>
<desc>WWWBoard has a default username and default password.</desc>
<refs>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/649">649</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0955" seq="1999-0955">
<status>Entry</status>
<desc>Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</desc>
<refs>
<ref source="CERT">CA-94.08</ref>
<ref source="CIAC">E-17</ref>
<ref source="XF">ftp-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0956" seq="1999-0956">
<status>Entry</status>
<desc>The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</desc>
<refs>
<ref source="CERT">CA-93.02a</ref>
<ref source="XF">next-netinfo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0957" seq="1999-0957">
<status>Entry</status>
<desc>MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970618 Security hole in MajorCool 1.0.3</ref>
<ref source="XF">majorcool-file-overwrite-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0958" seq="1999-0958">
<status>Entry</status>
<desc>sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88465708614896&amp;w=2">19980112 Re: hole in sudo for MP-RAS.</ref>
<ref source="XF">sudo-dot-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0959" seq="1999-0959">
<status>Entry</status>
<desc>IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970209 IRIX: Bug in startmidi</ref>
<ref source="AUSCERT">AA-97-05</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8447">8447</ref>
<ref source="XF">irix-startmidi-file-creation((1634)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0960" seq="1999-0960">
<status>Entry</status>
<desc>IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.11</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="XF">irix-cdplayer-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0961" seq="1999-0961">
<status>Entry</status>
<desc>HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref>
<ref source="CIAC">H-03</ref>
<ref source="XF">hp-sysdiag-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0962" seq="1999-0962">
<status>Entry</status>
<desc>Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.13</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref>
<ref source="XF">hp-password-cmd-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6415">6415</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0963" seq="1999-0963">
<status>Entry</status>
<desc>FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19960517 BoS: SECURITY BUG in FreeBSD</ref>
<ref source="CERT">VB-96.06</ref>
<ref source="XF">freebsd-mount-union-root</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6088">6088</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0964" seq="1999-0964">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:01</ref>
<ref source="XF">freebsd-setlocale-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6086">6086</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0965" seq="1999-0965">
<status>Entry</status>
<desc>Race condition in xterm allows local users to modify arbitrary files via the logging option.</desc>
<refs>
<ref source="CERT">CA-93.17</ref>
<ref source="XF">xterm</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0966" seq="1999-0966">
<status>Entry</status>
<desc>Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</desc>
<refs>
<ref source="L0PHT">19970127 Solaris libc - getopt(3)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0967" seq="1999-0967">
<status>Entry</status>
<desc>Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</desc>
<refs>
<ref source="L0PHT">19971101 Microsoft Internet Explorer 4.0 Suite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0968" seq="1999-0968">
<status>Entry</status>
<desc>Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11711">19981226 bnc exploit</ref>
<ref source="XF" url="http://xforce.iss.net/static/1546.php">bnc-proxy-bo(1546)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1927">1927</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0969" seq="1999-0969">
<status>Entry</status>
<desc>The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</desc>
<refs>
<ref source="ISS">19980929 &quot;Snork&quot; Denial of Service Attack Against Windows NT RPC Service</ref>
<ref source="NTBUGTRAQ">19980929 ISS Security Advisory: Snork</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx">MS98-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q193233">Q193233</ref>
<ref source="XF">snork-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0971" seq="1999-0971">
<status>Entry</status>
<desc>Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref>
<ref source="XF">exim-include-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0972" seq="1999-0972">
<status>Entry</status>
<desc>Buffer overflow in Xshipwars xsw program.</desc>
<refs>
<ref source="BUGTRAQ">19991209 xsw 1.24 remote buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/863">863</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0973" seq="1999-0973">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</desc>
<refs>
<ref source="BUGTRAQ">19991206 [w00giving #8] Solaris 2.7's snoop</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/858">858</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0974" seq="1999-0974">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</desc>
<refs>
<ref source="ISS">19991209 Buffer Overflow in Solaris Snoop</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190">00190</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/864">864</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0975" seq="1999-0975">
<status>Entry</status>
<desc>The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</desc>
<refs>
<ref source="BUGTRAQ">19991207 Local user can fool another to run executable. .CNT/.GID/.HLP M$WINNT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/868">868</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0976" seq="1999-0976">
<status>Entry</status>
<desc>Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</desc>
<refs>
<ref source="OPENBSD">19991204</ref>
<ref source="BUGTRAQ">19991207 [Debian] New version of sendmail released</ref>
<ref source="XF">sendmail-bi-alias</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/857">857</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0977" seq="1999-0977">
<status>Entry</status>
<desc>Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</desc>
<refs>
<ref source="SF-INCIDENTS">19991209 sadmind</ref>
<ref source="BUGTRAQ">19991210 Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="BUGTRAQ">19991210 Re: Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="CERT">CA-99-16</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191">00191</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/866">866</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2354">2354</ref>
<ref source="XF">sol-sadmind-amslverify-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2558">2558</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0978" seq="1999-0978">
<status>Entry</status>
<desc>htdig allows remote attackers to execute commands via filenames with shell metacharacters.</desc>
<refs>
<ref source="DEBIAN">19991209</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/867">867</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0979" seq="1999-0979">
<status>Entry</status>
<desc>The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Fundamental flaw in UnixWare 7 security</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/869">869</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0980" seq="1999-0980">
<status>Entry</status>
<desc>Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx">MS99-055</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246045">Q246045</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0981" seq="1999-0981">
<status>Entry</status>
<desc>Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka &quot;Server-side Page Reference Redirect.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx">MS99-050</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246094">Q246094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0982" seq="1999-0982">
<status>Entry</status>
<desc>The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</desc>
<refs>
<ref source="BUGTRAQ">19991206 Solaris WBEM 1.0: plaintext password stored in world readable file</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0986" seq="1999-0986">
<status>Entry</status>
<desc>The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Big problem on 2.0.x?</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/870">870</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0987" seq="1999-0987">
<status>Entry</status>
<desc>Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991118 NT System Policy for Win95 Not downloaded when adding a space after domain name</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237923">Q237923</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0989" seq="1999-0989">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</desc>
<refs>
<ref source="NTBUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/861">861</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0991" seq="1999-0991">
<status>Entry</status>
<desc>Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/862">862</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0992" seq="1999-0992">
<status>Entry</status>
<desc>HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107">HPSBUX9912-107</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0994" seq="1999-0994">
<status>Entry</status>
<desc>Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</desc>
<refs>
<ref source="BINDVIEW">19991216 Windows NT's SYSKEY feature</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx">MS99-056</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248183">Q248183</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/873">873</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0995" seq="1999-0995">
<status>Entry</status>
<desc>Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka &quot;Malformed Security Identifier Request.&quot;</desc>
<refs>
<ref source="NAI">19991216 Windows NT LSA Remote Denial of Service</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx">MS99-057</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248185">Q248185</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0996" seq="1999-0996">
<status>Entry</status>
<desc>Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD19991215.html">AD19991215</ref>
<ref source="BUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="NTBUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="XF">infoseek-ultraseek-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6490">6490</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0997" seq="1999-0997">
<status>Entry</status>
<desc>wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</desc>
<refs>
<ref source="BUGTRAQ">19991220 Security vulnerability in certain wu-ftpd (and derivitives) configurations (fwd)</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-377">DSA-377</ref>
<ref source="XF">wuftp-ftp-conversion</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0998" seq="1999-0998">
<status>Entry</status>
<desc>Cisco Cache Engine allows an attacker to replace content in the cache.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-replace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0999" seq="1999-0999">
<status>Entry</status>
<desc>Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx">MS99-059</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248749">Q248749</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/817">817</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1000" seq="1999-1000">
<status>Entry</status>
<desc>The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-performance</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1001" seq="1999-1001">
<status>Entry</status>
<desc>Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1004" seq="1999-1004">
<status>Entry</status>
<desc>Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/38970">19991217 NAV2000 Email Protection DoS</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39194">19991220 Norton Email Protection Remote Overflow (Addendum)</ref>
<ref source="CONFIRM" url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy">http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6267">6267</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1005" seq="1999-1005">
<status>Entry</status>
<desc>Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
<ref source="XF">groupwise-web-read-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/879">879</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3413">3413</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1007" seq="1999-1007">
<status>Entry</status>
<desc>Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94512259331599&amp;w=2">19991213 VDO Live Player 3.02 Buffer Overflow</ref>
<ref source="XF">vdolive-bo-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/872">872</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1008" seq="1999-1008">
<status>Entry</status>
<desc>xsoldier program allows local users to gain root access via a long argument.</desc>
<refs>
<ref source="BUGTRAQ">19991215 FreeBSD 3.3 xsoldier root exploit</ref>
<ref source="MISC" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2">http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/871">871</ref>
<ref source="XF">unix-xsoldier-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1010" seq="1999-1010">
<status>Entry</status>
<desc>An SSH 1.2.27 server allows a client to use the &quot;none&quot; cipher, even if it is not allowed by the server policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94519142415338&amp;w=2">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref>
<ref source="XF">ssh-policy-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1011" seq="1999-1011">
<status>Entry</status>
<desc>The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-004.asp">MS98-004</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-025.asp">MS99-025</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">J-054</ref>
<ref source="ISS">19990809 Vulnerabilities in Microsoft Remote Data Service</ref>
<ref source="BID" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">529</ref>
<ref source="XF">nt-iis-rds</ref>
<ref source="OSVDB" url="http://www.osvdb.org/272">272</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1014" seq="1999-1014">
<status>Entry</status>
<desc>Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93727925026476&amp;w=2">19990913 Solaris 2.7 /usr/bin/mail</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846422810162&amp;w=2">19990927 Working Solaris x86 /usr/bin/mail exploit</ref>
<ref source="SUNBUG">4276509</ref>
<ref source="XF" url="http://xforce.iss.net/static/3297.php">sun-usrbinmail-local-bo(3297)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/672">672</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1019" seq="1999-1019">
<status>Entry</status>
<desc>SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398713491&amp;w=2">19990623 Cabletron Spectrum security vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398513475&amp;w=2">19990624 Re: Cabletron Spectrum security vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/495">495</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1021" seq="1999-1021">
<status>Entry</status>
<desc>NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">00117</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/47">47</ref>
<ref source="XF" url="http://xforce.iss.net/static/82.php">nfs-uid(82)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1027" seq="1999-1027">
<status>Entry</status>
<desc>Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925880&amp;w=2">19980507 admintool mode 0777 in Solaris 2.6 HW3/98</ref>
<ref source="SUNBUG">4178998</ref>
<ref source="XF" url="http://xforce.iss.net/static/7296.php">solaris-admintool-world-writable(7296)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/290">290</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1028" seq="1999-1028">
<status>Entry</status>
<desc>Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92807524225090&amp;w=2">19990528 DoS against PC Anywhere</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/288">288</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2256.php">pcanywhere-dos(2256)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1032" seq="1999-1032">
<status>Entry</status>
<desc>Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-11.html">CA-1991-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/26">26</ref>
<ref source="XF" url="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1034" seq="1999-1034">
<status>Entry</status>
<desc>Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-08.html">CA-1991-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/23">23</ref>
<ref source="XF" url="http://xforce.iss.net/static/583.php">sysv-login(583)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1035" seq="1999-1035">
<status>Entry</status>
<desc>IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS &quot;GET&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-019.asp">MS98-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp">Q192296</ref>
<ref source="XF" url="http://xforce.iss.net/static/1823.php">iis-get-dos(1823)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1037" seq="1999-1037">
<status>Entry</status>
<desc>rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125986&amp;w=2">19980627 Re: vulnerability in satan, cops &amp; tiger</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7167.php">satan-rexsatan-symlink(7167)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3147">3147</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1044" seq="1999-1044">
<status>Entry</status>
<desc>Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</desc>
<refs>
<ref source="COMPAQ" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">SSRT0495U</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">I-050</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7431.php">dgux-advfs-softlinks(7431)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1045" seq="1999-1045">
<status>Entry</status>
<desc>pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492978527261&amp;w=2">19980115 pnserver exploit..</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88490880523890&amp;w=2">19980115 [rootshell] Security Bulletin #7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90338245305236&amp;w=2">19980817 Re: Real Audio Server Version 5 bug?</ref>
<ref source="MISC" url="http://service.real.com/help/faq/serv501.html">http://service.real.com/help/faq/serv501.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7297.php">realserver-pnserver-remote-dos(7297)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6979">6979</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1047" seq="1999-1047">
<status>Entry</status>
<desc>When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94026690521279&amp;w=2">19991018 Gauntlet 5.0 BSDI warning</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94036662326185&amp;w=2">19991019 Re: Gauntlet 5.0 BSDI warning</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3397.php">gauntlet-bsdi-bypass(3397)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1048" seq="1999-1048">
<status>Entry</status>
<desc>Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10542">19980905 BASH buffer overflow, LiNUX x86 exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719555&amp;w=2">19970821 Buffer overflow in /bin/bash</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19980909">19980909 problem with very long pathnames</ref>
<ref source="XF" url="http://xforce.iss.net/static/3414.php">linux-bash-bo(3414)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8345">8345</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1055" seq="1999-1055">
<status>Entry</status>
<desc>Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel &quot;CALL Vulnerability.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-018.asp">MS98-018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/179">179</ref>
<ref source="XF" url="http://xforce.iss.net/static/1737.php">excel-call(1737)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1057" seq="1999-1057">
<status>Entry</status>
<desc>VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-07.html">CA-1990-07</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml">B-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1059" seq="1999-1059">
<status>Entry</status>
<desc>Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-04.html">CA-1992-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1074" seq="1999-1074">
<status>Entry</status>
<desc>Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9138">19980501 Warning! Webmin Security Advisory</ref>
<ref source="CONFIRM" url="http://www.webmin.com/webmin/changes.html">http://www.webmin.com/webmin/changes.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/98">98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1080" seq="1999-1080">
<status>Entry</status>
<desc>rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2">19991011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref>
<ref source="SUNBUG">4205437</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1085" seq="1999-1085">
<status>Entry</status>
<desc>SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &quot;SSH insertion attack.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125884&amp;w=2">19980612 CORE-SDI-04: SSH insertion attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525878&amp;w=2">19980703 UPDATE: SSH insertion attack</ref>
<ref source="CISCO">20010627 Multiple SSH Vulnerabilities</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13877">VU#13877</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1126.php">ssh-insert(1126)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1087" seq="1999-1087">
<status>Entry</status>
<desc>Internet Explorer 4 treats a 32-bit number (&quot;dotless IP address&quot;) in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-016.asp">MS98-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp">Q168617</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/Ie/security/dotless.asp">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7828">7828</ref>
<ref source="XF" url="http://xforce.iss.net/static/2209.php">ie-dotless(2209)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1090" seq="1999-1090">
<status>Entry</status>
<desc>The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an &quot;ftp=yes&quot; line, which allows remote attackers to read and modify arbitrary files.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-15.html">CA-1991-15</ref>
<ref source="XF" url="http://xforce.iss.net/static/1844.php">ftp-ncsa(1844)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1093" seq="1999-1093">
<status>Entry</status>
<desc>Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-011.asp">MS98-011</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp">Q191200</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1276.php">java-script-patch(1276)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1094" seq="1999-1094">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the &quot;mk:&quot; protocol, aka the &quot;MK Overrun security issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88480839506155&amp;w=2">19980114 L0pht Advisory MSIE4.0(1)</ref>
<ref source="XF" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1098" seq="1999-1098">
<status>Entry</status>
<desc>Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1995-03.html">CA-1995-03</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/f-12.shtml">F-12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4881">4881</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1099" seq="1999-1099">
<status>Entry</status>
<desc>Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2">19961122 L0pht Kerberos Advisory</ref>
<ref source="XF" url="http://xforce.iss.net/static/65.php">kerberos-user-grab(65)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1100" seq="1999-1100">
<status>Entry</status>
<desc>Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml">19980616 PIX Private Link Key Processing and Cryptography Issues</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml">I-056</ref>
<ref source="XF" url="http://xforce.iss.net/static/1579.php">cisco-pix-parse-error(1579)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1102" seq="1999-1102">
<status>Entry</status>
<desc>lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</desc>
<refs>
<ref source="MISC" url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr">http://www.phreak.org/archives/security/8lgm/8lgm.lpr</ref>
<ref source="BUGTRAQ" url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm">19940307 8lgm Advisory Releases</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml">E-25a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1103" seq="1999-1103">
<status>Entry</status>
<desc>dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec">VB-96.05</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml">G-18</ref>
<ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1104" seq="1999-1104">
<status>Entry</status>
<desc>Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418931&amp;w=2">19951205 Cracked: WINDOWS.PWL</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88540877601866&amp;w=2">19980121 How to recover private keys for various Microsoft products</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88536273725787&amp;w=2">19980120 How to recover private keys for various Microsoft products</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp">Q140557</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/71.php">win95-nbsmbpwl(71)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1105" seq="1999-1105">
<status>Entry</status>
<desc>Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</desc>
<refs>
<ref source="CONFIRM" url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html">http://www.zdnet.com/eweek/reviews/1016/tr42bug.html</ref>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/netware1.html">http://www.net-security.sk/bugs/NT/netware1.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7231.php">win95-netware-hidden-share(7231)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1109" seq="1999-1109">
<status>Entry</status>
<desc>Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94632241202626&amp;w=2">19991222 Re: procmail / Sendmail - five bugs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780566911948&amp;w=2">20000113 Re: procmail / Sendmail - five bugs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/904">904</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7760.php">sendmail-etrn-dos(7760)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1111" seq="1999-1111">
<status>Entry</status>
<desc>Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94218618329838&amp;w=2">19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/786">786</ref>
<ref source="XF" url="http://xforce.iss.net/static/3524.php">immunix-stackguard-bo(3524)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1114" seq="1999-1114">
<status>Entry</status>
<desc>Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml">H-15A</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul">AA-96.17</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I">19980405-01-I</ref>
<ref source="XF" url="http://xforce.iss.net/static/2100.php">ksh-suid_exec(2100)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/467">467</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1115" seq="1999-1115">
<status>Entry</status>
<desc>Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-04.html">CA-1990-04</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1116" seq="1999-1116">
<status>Entry</status>
<desc>Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX">19970503-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/462">462</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1009">1009</ref>
<ref source="XF" url="http://xforce.iss.net/static/2108.php">sgi-runpriv(2108)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1117" seq="1999-1117">
<status>Entry</status>
<desc>lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b">19961124</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420195&amp;w=2">19961125 lquerypv fix</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420196&amp;w=2">19961125 AIX lquerypv</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/455">455</ref>
<ref source="XF" url="http://xforce.iss.net/static/1752.php">ibm-lquerypv(1752)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1118" seq="1999-1118">
<status>Entry</status>
<desc>ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba">00165</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/433">433</ref>
<ref source="XF" url="http://xforce.iss.net/static/817.php">sun-ndd(817)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1119" seq="1999-1119">
<status>Entry</status>
<desc>FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-09.html">CA-1992-09</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref>
<ref source="XF" url="http://xforce.iss.net/static/3154.php">aix-anon-ftp(3154)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1120" seq="1999-1120">
<status>Entry</status>
<desc>netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2">19970104 Irix: netprint story</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">19961203-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/395">395</ref>
<ref source="OSVDB" url="http://www.osvdb.org/993">993</ref>
<ref source="XF" url="http://xforce.iss.net/static/2107.php">sgi-netprint(2107)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1121" seq="1999-1121">
<status>Entry</status>
<desc>The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-06.html">CA-1992-06</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref>
<ref source="XF" url="http://xforce.iss.net/static/554.php">ibm-uucp(554)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/891">891</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1122" seq="1999-1122">
<status>Entry</status>
<desc>Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1989-02.html">CA-1989-02</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref>
<ref source="SUNBUG">1019265</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1127" seq="1999-1127">
<status>Entry</status>
<desc>Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the &quot;Named Pipes Over RPC&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-017.asp">MS98-017</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp">Q195733</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/523.php">nt-spoolss(523)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1131" seq="1999-1131">
<status>Entry</status>
<desc>Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup">VB-97.12</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml">I-060</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX">19980601-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/1123.php">sgi-osf-dce-dos(1123)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1132" seq="1999-1132">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90763508011966&amp;w=2">19981005 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90760603030452&amp;w=2">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp">Q179157</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1399.php">token-ring-dos(1399)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1136" seq="1999-1136">
<status>Entry</status>
<desc>Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html">HPSBUX9807-081</ref>
<ref source="HP" url="http://cert.ip-plus.net/bulletin-archive/msg00040.html">HPSBMP9807-005</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526177&amp;w=2">19980729 HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-081.shtml">I-081</ref>
<ref source="XF" url="http://xforce.iss.net/static/1413.php">mpeix-predictive(1413)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1137" seq="1999-1137">
<status>Entry</status>
<desc>The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/e-01.shtml">E-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF" url="http://xforce.iss.net/static/549.php">sun-audio(549)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6436">6436</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1138" seq="1999-1138">
<status>Entry</status>
<desc>SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref>
<ref source="XF" url="http://xforce.iss.net/static/546.php">sco-homedir(546)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1139" seq="1999-1139">
<status>Entry</status>
<desc>Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2">19970901 HP UX Bug :)</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html">HPSBUX9801-074</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1140" seq="1999-1140">
<status>Entry</status>
<desc>Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88209041500913&amp;w=2">19971214 buffer overflows in cracklib?!</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib">VB-97.16</ref>
<ref source="XF" url="http://xforce.iss.net/static/1539.php">cracklib-bo(1539)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1142" seq="1999-1142">
<status>Entry</status>
<desc>SunOS 4.1.2 and earlier allows local users to gain privileges via &quot;LD_*&quot; environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-11.html">CA-1992-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref>
<ref source="XF" url="http://xforce.iss.net/static/3152.php">sun-env(3152)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1143" seq="1999-1143">
<status>Entry</status>
<desc>Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml">H-065</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/2109.php">sgi-rld(2109)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1144" seq="1999-1144">
<status>Entry</status>
<desc>Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html">HPSBUX9701-051</ref>
<ref source="XF" url="http://xforce.iss.net/static/2056.php">hp-mpower(2056)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1145" seq="1999-1145">
<status>Entry</status>
<desc>Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
<ref source="XF" url="http://xforce.iss.net/static/2059.php">hp-glanceplus(2059)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1146" seq="1999-1146">
<status>Entry</status>
<desc>Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/advisories/1555">HPSBUX9405-011</ref>
<ref source="XF" url="http://xforce.iss.net/static/2060.php">hp-glanceplus-gpm(2060)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1147" seq="1999-1147">
<status>Entry</status>
<desc>Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91273739726314&amp;w=2">19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="BUGTRAQ">19981207 Re: [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/1430.php">pcm-dos-execute(1430)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3164">3164</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1148" seq="1999-1148">
<status>Entry</status>
<desc>FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-006.asp">MS98-006</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP">Q189262</ref>
<ref source="XF" url="http://xforce.iss.net/static/1215.php">iis-passive-ftp(1215)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1156" seq="1999-1156">
<status>Entry</status>
<desc>BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</desc>
<refs>
<ref source="NTBUGTRAQ">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
<ref source="XF" url="http://xforce.iss.net/static/2254.php">bisonware-port-crash(2254)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1157" seq="1999-1157">
<status>Entry</status>
<desc>Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP">Q192774</ref>
<ref source="XF" url="http://xforce.iss.net/static/3894.php">tcpipsys-icmp-dos(3894)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1159" seq="1999-1159">
<status>Entry</status>
<desc>SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495920911490&amp;w=2">19981229 ssh2 security problem (and patch) (fwd)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1471.php">ssh-privileged-port-forward(1471)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1160" seq="1999-1160">
<status>Entry</status>
<desc>Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2">HPSBUX9702-055</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml">H-33</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1161" seq="1999-1161">
<status>Entry</status>
<desc>Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2">19961104 ppl bugs</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html">HPSBUX9704-057</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml">H-32</ref>
<ref source="AUSCERT">AA-97.07</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1162" seq="1999-1162">
<status>Entry</status>
<desc>Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-08.html">CA-1993-08</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1163" seq="1999-1163">
<status>Entry</status>
<desc>Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94347039929958&amp;w=2">HPSBUX9911-105</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7439.php">hp-ssp(7439)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1167" seq="1999-1167">
<status>Entry</status>
<desc>Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</desc>
<refs>
<ref source="CONFIRM" url="http://www.wired.com/news/technology/0,1282,20677,00.html">http://www.wired.com/news/technology/0,1282,20677,00.html</ref>
<ref source="MISC" url="http://www.wired.com/news/technology/0,1282,20636,00.html">http://www.wired.com/news/technology/0,1282,20636,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7252.php">thirdvoice-cross-site-scripting(7252)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1175" seq="1999-1175">
<status>Entry</status>
<desc>Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml">19980513 Cisco Web Cache Control Protocol Router Vulnerability</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-054.shtml">I-054</ref>
<ref source="XF" url="http://xforce.iss.net/static/1577.php">cisco-wccp-vuln(1577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1177" seq="1999-1177">
<status>Entry</status>
<desc>Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</desc>
<refs>
<ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf4.html">http://www.w3.org/Security/Faq/wwwsf4.html</ref>
<ref source="CONFIRM" url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish">http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish</ref>
<ref source="XF" url="http://xforce.iss.net/static/2055.php">http-cgi-nphpublish(2055)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1181" seq="1999-1181">
<status>Entry</status>
<desc>Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX">19980901-01-PX</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml">J-003</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7441.php">irix-register(7441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1188" seq="1999-1188">
<status>Entry</status>
<desc>mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91479159617803&amp;w=2">19981227 mysql: mysqld creates world readable logs..</ref>
<ref source="XF" url="http://xforce.iss.net/static/1568.php">mysql-readable-log-files(1568)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1189" seq="1999-1189">
<status>Entry</status>
<desc>Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36306">19991124 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36608">19991127 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/822">822</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7884">netscape-long-argument-bo(7884)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1191" seq="1999-1191">
<status>Entry</status>
<desc>Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul">AA-97.18</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144">00144</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/207">207</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1192" seq="1999-1192">
<status>Entry</status>
<desc>Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143">00143</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/206">206</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1193" seq="1999-1193">
<status>Entry</status>
<desc>The &quot;me&quot; user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-06.html">CA-1991-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/581.php">next-me(581)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1194" seq="1999-1194">
<status>Entry</status>
<desc>chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-05.html">CA-1991-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref>
<ref source="XF" url="http://xforce.iss.net/static/577.php">dec-chroot(577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1197" seq="1999-1197">
<status>Entry</status>
<desc>TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-12.html">CA-1990-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1198" seq="1999-1198">
<status>Entry</status>
<desc>BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1199" seq="1999-1199">
<status>Entry</status>
<desc>Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the &quot;sioux&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90252779826784&amp;w=2">19980807 YA Apache DoS attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90276683825862&amp;w=2">19980808 Debian Apache Security Update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90286768232093&amp;w=2">19980810 Apache DoS Attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90280517007869&amp;w=2">19980811 Apache 'sioux' DOS fix for TurboLinux</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1201" seq="1999-1201">
<status>Entry</status>
<desc>Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91849617221319&amp;w=2">19990206 New Windows 9x Bug:  TCP Chorusing</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/225">225</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7542">win-multiple-ip-dos(7542)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1203" seq="1999-1203">
<status>Entry</status>
<desc>Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91868964203769&amp;w=2">19990210 Security problems in ISDN equipment authentication</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91888117502765&amp;w=2">19990212 PPP/ISDN multilink security issue - summary</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7498.php">ascend-ppp-isdn-dos(7498)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1204" seq="1999-1204">
<status>Entry</status>
<desc>Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default &quot;ANY&quot; address and result in access to more systems than intended by the administrator.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925912&amp;w=2">19980511 Firewall-1 Reserved Keywords Vulnerability</ref>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/config/keywords.html">http://www.checkpoint.com/techsupport/config/keywords.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/7293.php">fw1-user-defined-keywords-access(7293)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4416">4416</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1205" seq="1999-1205">
<status>Entry</status>
<desc>nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2">19960607 HP-UX B.10.01 vulnerability</ref>
<ref source="HP" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08">HPSBUX9607-035</ref>
<ref source="CIAC">G-34</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1208" seq="1999-1208">
<status>Entry</status>
<desc>Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2">19970721 AIX ping, lchangelv, xlock fixes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2">19970721 AIX ping (Exploit)</ref>
<ref source="XF" url="http://xforce.iss.net/static/803.php">ping-bo(803)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1209" seq="1999-1209">
<status>Entry</status>
<desc>Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88131151000069&amp;w=2">19971204 scoterm exploit</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm">VB-97.14</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/690">sco-scoterm(690)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1214" seq="1999-1214">
<status>Entry</status>
<desc>The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.com/advisories/signals.txt">19970915 Vulnerability in I/O Signal Handling</ref>
<ref source="MISC" url="http://www.openbsd.com/advisories/signals.txt">http://www.openbsd.com/advisories/signals.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11062">11062</ref>
<ref source="XF" url="http://xforce.iss.net/static/556.php">openbsd-iosig(556)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1215" seq="1999-1215">
<status>Entry</status>
<desc>LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-12.html">CA-1993-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/545.php">novell-login(545)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1217" seq="1999-1217">
<status>Entry</status>
<desc>The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2">19970725 Re: NT security - why bother?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2">19970723 NT security - why bother?</ref>
<ref source="XF" url="http://xforce.iss.net/static/526.php">nt-path(526)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1222" seq="1999-1222">
<status>Entry</status>
<desc>Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP">Q188571</ref>
<ref source="XF" url="http://xforce.iss.net/static/3893.php">dns-netbtsys-dos(3893)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1223" seq="1999-1223">
<status>Entry</status>
<desc>IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp">Q187503</ref>
<ref source="XF" url="http://xforce.iss.net/static/3892.php">url-asp-av(3892)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1226" seq="1999-1226">
<status>Entry</status>
<desc>Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</desc>
<refs>
<ref source="MISC" url="http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html">http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3436.php">netscape-huge-key-dos(3436)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1233" seq="1999-1233">
<status>Entry</status>
<desc>IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the &quot;Domain Resolution&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp">241562</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/657">657</ref>
<ref source="XF" url="http://xforce.iss.net/static/3306.php">iis-unresolved-domain-access(3306)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1243" seq="1999-1243">
<status>Entry</status>
<desc>SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml">F-16</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373">19950301-01-P373</ref>
<ref source="XF" url="http://xforce.iss.net/static/2113.php">sgi-permissions(2113)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1246" seq="1999-1246">
<status>Entry</status>
<desc>Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp">Q229972</ref>
<ref source="XF" url="http://xforce.iss.net/static/2068.php">siteserver-directmail-passwords(2068)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1249" seq="1999-1249">
<status>Entry</status>
<desc>movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html">HPSBUX9701-047</ref>
<ref source="XF" url="http://xforce.iss.net/static/2057.php">hp-movemail(2057)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8099">8099</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1258" seq="1999-1258">
<status>Entry</status>
<desc>rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102">00102</ref>
<ref source="XF" url="http://xforce.iss.net/static/1782.php">sun-pwdauthd(1782)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1259" seq="1999-1259">
<status>Entry</status>
<desc>Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp">Q189529</ref>
<ref source="XF" url="http://xforce.iss.net/static/1780.php">office-extraneous-data(1780)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1262" seq="1999-1262">
<status>Entry</status>
<desc>Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref>
<ref source="XF" url="http://xforce.iss.net/static/1727.php">java-socket-open(1727)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1263" seq="1999-1263">
<status>Entry</status>
<desc>Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2">19971024 Vulnerability in metamail</ref>
<ref source="XF" url="http://xforce.iss.net/static/1677.php">metamail-file-creation(1677)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1276" seq="1999-1276">
<status>Entry</status>
<desc>fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19981207">19981207 fte-console: does not drop its root priviliges</ref>
<ref source="XF" url="http://xforce.iss.net/static/1609.php">fte-console-privileges(1609)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1279" seq="1999-1279">
<status>Entry</status>
<desc>An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp">Q138001</ref>
<ref source="XF" url="http://xforce.iss.net/static/1548.php">snaserver-shared-folders(1548)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1284" seq="1999-1284">
<status>Entry</status>
<desc>NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11131">19981105 various *lame* DoS attacks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91063407332594&amp;w=2">19981107 Re: various *lame* DoS attacks</ref>
<ref source="MISC" url="http://www.dynamsol.com/puppet/text/new.txt">http://www.dynamsol.com/puppet/text/new.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/1540.php">nukenabber-timeout-dos(1540)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1288" seq="1999-1288">
<status>Entry</status>
<desc>Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11397">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref>
<ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt">SA-1998.35</ref>
<ref source="XF" url="http://xforce.iss.net/static/1406.php">samba-wsmbconf(1406)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1290" seq="1999-1290">
<status>Entry</status>
<desc>Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91127951426494&amp;w=2">19981117 nftp vulnerability (fwd)</ref>
<ref source="CONFIRM" url="http://www.ayukov.com/nftp/history.html">http://www.ayukov.com/nftp/history.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/1397.php">nftp-bo(1397)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1294" seq="1999-1294">
<status>Entry</status>
<desc>Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp">Q146604</ref>
<ref source="XF" url="http://xforce.iss.net/static/562.php">nt-filemgr(562)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1297" seq="1999-1297">
<status>Entry</status>
<desc>cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20">1077164</ref>
<ref source="XF" url="http://xforce.iss.net/static/7482.php">sun-cmdtool-echo(7482)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1298" seq="1999-1298">
<status>Entry</status>
<desc>Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc">FreeBSD-SA-97:03</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6087">6087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1301" seq="1999-1301">
<status>Entry</status>
<desc>A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml">G-31</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc">FreeBSD-SA-96:17</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1309" seq="1999-1309">
<status>Entry</status>
<desc>Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0040.html">19940314 sendmail -d problem (OLD yet still here)</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0042.html">19940315 anyone know details?</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0048.html">19940315 Security problem in sendmail versions 8.x.x</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities">CA-1994-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1316" seq="1999-1316">
<status>Entry</status>
<desc>Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp">Q247975</ref>
<ref source="XF" url="http://xforce.iss.net/static/7391.php">passfilt-fullname(7391)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1317" seq="1999-1317">
<status>Entry</status>
<desc>Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92127046701349&amp;w=2">19990312 [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92162979530341&amp;w=2">19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp">Q222159</ref>
<ref source="XF" url="http://xforce.iss.net/static/7398.php">nt-symlink-case(7398)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1318" seq="1999-1318">
<status>Entry</status>
<desc>/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20">1121935</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1320" seq="1999-1320">
<status>Entry</status>
<desc>Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml">D-01</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7213.php">netware-packet-spoofing-privileges(7213)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1321" seq="1999-1321">
<status>Entry</status>
<desc>Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</desc>
<refs>
<ref source="BUGTRAQ" url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814">19981105 security patch for ssh-1.2.26 kerberos code</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4883">4883</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1324" seq="1999-1324">
<status>Entry</status>
<desc>VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml">D-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/7225.php">openvms-sysgen-enabled(7225)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1325" seq="1999-1325">
<status>Entry</status>
<desc>SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml">C-19</ref>
<ref source="XF" url="http://xforce.iss.net/static/7261.php">vaxvms-sas-gain-privileges(7261)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1326" seq="1999-1326">
<status>Entry</status>
<desc>wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2">19970104 serious security bug in wu-ftpd v2.4</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
<ref source="XF" url="http://xforce.iss.net/static/7169.php">wuftpd-abor-gain-privileges(7169)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1327" seq="1999-1327">
<status>Entry</status>
<desc>Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125826&amp;w=2">19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7239.php">linuxconf-lang-bo(7239)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6065">6065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1328" seq="1999-1328">
<status>Entry</status>
<desc>linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19980826 [djb@redhat.com: Unidentified subject!]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90383955231511&amp;w=2">19980823 Security concerns in linuxconf shipped w/RedHat 5.1</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7232.php">linuxconf-symlink-gain-privileges(7232)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6068">6068</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1329" seq="1999-1329">
<status>Entry</status>
<desc>Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7250.php">sysvinit-root-bo(7250)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1330" seq="1999-1330">
<status>Entry</status>
<desc>The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419259&amp;w=2">19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd)</ref>
<ref source="CONFIRM" url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html">http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#db">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7244.php">linux-libdb-snprintf-bo(7244)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1331" seq="1999-1331">
<status>Entry</status>
<desc>netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7245.php">netcfg-ethernet-dos(7245)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1332" seq="1999-1332">
<status>Entry</status>
<desc>gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88603844115233&amp;w=2">19980128 GZEXE - the big problem</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308">DSA-308</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7845">7845</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3812">3812</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7241.php">gzip-gzexe-tmp-symlink(7241)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1333" seq="1999-1333">
<status>Entry</status>
<desc>automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89042322924057&amp;w=2">19980319 ncftp 2.4.2 MkDirs bug</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7240.php">ncftp-autodownload-command-execution(7240)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6111">6111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1335" seq="1999-1335">
<status>Entry</status>
<desc>snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref>
<ref source="XF" url="http://xforce.iss.net/static/7251.php">cmusnmp-read-write(7251)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1336" seq="1999-1336">
<status>Entry</status>
<desc>3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93458364903256&amp;w=2">19990812 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93492615408725&amp;w=2">19990816 Re: 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6057">6057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1337" seq="1999-1337">
<status>Entry</status>
<desc>FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93370073207984&amp;w=2">19990801 midnight commander vulnerability(?) (fwd)</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/9873.php">midnight-commander-data-disclosure(9873)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5921">5921</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1339" seq="1999-1339">
<status>Entry</status>
<desc>Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277766505061&amp;w=2">19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277426802802&amp;w=2">19990722 Linux +ipchains+ ping -R</ref>
<ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz">http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7257.php">ipchains-ping-route-dos(7257)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6105">6105</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1341" seq="1999-1341">
<status>Entry</status>
<desc>Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94061108411308&amp;w=2">19991022 Local user can send forged packets</ref>
<ref source="XF" url="http://xforce.iss.net/static/7858.php">linux-tiocsetd-forge-packets(7858)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1351" seq="1999-1351">
<status>Entry</status>
<desc>Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the &quot;Listen to !nick &lt;soundname&gt; requests&quot; option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93845560631314&amp;w=2">19990924 Kvirc bug</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7761.php">kvirc-dot-directory-traversal(7761)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1356" seq="1999-1356">
<status>Entry</status>
<desc>Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93646669500991&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637792706047&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822830815&amp;w=2">19990917 Re: Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7763.php">compaq-smartstart-legal-notice(7763)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1358" seq="1999-1358">
<status>Entry</status>
<desc>When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp">Q157673</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7400.php">nt-user-policy-update(7400)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1359" seq="1999-1359">
<status>Entry</status>
<desc>When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp">Q163875</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7401.php">nt-group-policy-longname(7401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1360" seq="1999-1360">
<status>Entry</status>
<desc>Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp">Q160650</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7402.php">nt-kernel-handle-dos(7402)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1362" seq="1999-1362">
<status>Entry</status>
<desc>Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp">Q160601</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7403.php">nt-win32k-dos(7403)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1363" seq="1999-1363">
<status>Entry</status>
<desc>Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp">Q163143</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7405.php">nt-nonpagedpool-dos(7405)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1365" seq="1999-1365">
<status>Entry</status>
<desc>Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93069418400856&amp;w=2">19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93127894731200&amp;w=2">19990630 Update: NT runs explorer.exe, etc...</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2336">nt-login-default-folder(2336)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/0515">0515</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1379" seq="1999-1379">
<status>Entry</status>
<desc>DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93348057829957&amp;w=2">19990730 Possible Denial Of Service using DNS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93433758607623&amp;w=2">19990810 Possible Denial Of Service using DNS</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos">AL-1999.004</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml">J-063</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7238.php">dns-udp-query-dos(7238)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1380" seq="1999-1380">
<status>Entry</status>
<desc>Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</desc>
<refs>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref>
<ref source="MISC" url="http://mlarchive.ima.com/win95/1997/May/0342.html">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
<ref source="MISC" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1382" seq="1999-1382">
<status>Entry</status>
<desc>NetWare NFS mode 1 and 2 implements the &quot;Read Only&quot; flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to &quot;Read Only,&quot; which NetWare-NFS changes to a setuid root program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88427711321769&amp;w=2">19980108 NetWare NFS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90295697702474&amp;w=2">19980812 Re: Netware NFS (fwd)</ref>
<ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551">http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7246.php">netware-nfs-file-ownership(7246)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1384" seq="1999-1384">
<status>Entry</status>
<desc>Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2">19961030 (Another) vulnerability in new SGIs</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul">AA-96.08</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I">19961101-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/470">470</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1385" seq="1999-1385">
<status>Entry</status>
<desc>Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc">FreeBSD-SA-96:20</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6085">6085</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1386" seq="1999-1386">
<status>Entry</status>
<desc>Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88932165406213&amp;w=2">19980308 another /tmp race: `perl -e' opens temp file not safely</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7243.php">perl-e-tmp-symlink(7243)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1397" seq="1999-1397">
<status>Entry</status>
<desc>Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92242671024118&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92223293409756&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/476">476</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7559.php">iis-indexserver-reveal-path(7559)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1402" seq="1999-1402">
<status>Entry</status>
<desc>The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2">19971003 Solaris 2.6 and sockets</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/456">456</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1407" seq="1999-1407">
<status>Entry</status>
<desc>ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88950856416985&amp;w=2">19980309 *sigh* another RH5 /tmp problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/368">368</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7294.php">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1409" seq="1999-1409">
<status>Entry</status>
<desc>The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html">19980703 more about 'at'</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90233906612929&amp;w=2">19980805 irix-6.2 &quot;at -f&quot; vulnerability</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc">NetBSD-SA1998-004</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/331">331</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7577.php">at-f-read-files(7577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1411" seq="1999-1411">
<status>Entry</status>
<desc>The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</desc>
<refs>
<ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html">19981126 new version of fsp fixes security flaw</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91228908407679&amp;w=2">19981128 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91244712808780&amp;w=2">19981130 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936850009861&amp;w=2">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/316">316</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7574.php">fsp-anon-ftp-access(7574)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1414" seq="1999-1414">
<status>Entry</status>
<desc>IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92765856706547&amp;w=2">19990525 Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92902484317769&amp;w=2">19990609 IBM's response to &quot;Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/284">284</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1419" seq="1999-1419">
<status>Entry</status>
<desc>Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148">00148</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/219">219</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1423" seq="1999-1423">
<status>Entry</status>
<desc>ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2">19970626 Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2">19971005 Solaris Ping Bug and other [bc] oddities</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146">00146</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/209">209</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1432" seq="1999-1432">
<status>Entry</status>
<desc>Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525997&amp;w=2">19980716 Security risk with powermanagemnet on Solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/160">160</ref>
<ref source="SUNBUG">4024179</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1433" seq="1999-1433">
<status>Entry</status>
<desc>HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525988&amp;w=2">19980715 JetAdmin software</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526067&amp;w=2">19980722 Re: JetAdmin software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/157">157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1437" seq="1999-1437">
<status>Entry</status>
<desc>ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525890&amp;w=2">19980707 ePerl: bad handling of ISINDEX queries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525927&amp;w=2">19980710 ePerl Security Update Available</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/151">151</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1452" seq="1999-1452">
<status>Entry</status>
<desc>GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91764169410814&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91822011021558&amp;w=2">19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91788829326419&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp">Q214802</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/198">198</ref>
<ref source="XF" url="http://xforce.iss.net/static/1975.php">nt-gina-clipboard(1975)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1455" seq="1999-1455">
<status>Entry</status>
<desc>RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp">Q158320</ref>
<ref source="XF" url="http://xforce.iss.net/static/7422.php">nt-rshsvc-ale-bypass(7422)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1456" seq="1999-1456">
<status>Entry</status>
<desc>thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10368">19980819 thttpd 2.04 released (fwd)</ref>
<ref source="CONFIRM" url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref>
<ref source="XF" url="http://xforce.iss.net/static/1809.php">thttpd-file-read(1809)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1468" seq="1999-1468">
<status>Entry</status>
<desc>rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</desc>
<refs>
<ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability">CA-91.20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/31">31</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8106">8106</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1472" seq="1999-1472">
<status>Entry</status>
<desc>Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87710897923098&amp;w=2">19971017 Security Hole in Explorer 4.0</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html">http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/ie/security/freiburg.asp">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp">Q176794</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://xforce.iss.net/static/587.php">http-ie-spy(587)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7819">7819</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1473" seq="1999-1473">
<status>Entry</status>
<desc>When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the &quot;Page Redirect Issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7426.php">ie-page-redirect(7426)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7818">7818</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1476" seq="1999-1476">
<status>Entry</status>
<desc>A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the &quot;Invalid Operand with Locked CMPXCHG8B Instruction&quot; problem.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp ">Q163852</ref>
<ref source="XF" url="http://xforce.iss.net/static/704.php">pentium-crash(704)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1478" seq="1999-1478">
<status>Entry</status>
<desc>The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827429589&amp;w=2">19990706 Bug in SUN's Hotspot VM</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93240220324183&amp;w=2">19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/522">522</ref>
<ref source="XF" url="http://xforce.iss.net/static/2348.php">sun-hotspot-vm(2348)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1481" seq="1999-1481">
<status>Entry</status>
<desc>Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991025 [squid] exploit for external authentication problem</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991103 [squid]exploit for external authentication problem</ref>
<ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.2/bugs/">http://www.squid-cache.org/Versions/v2/2.2/bugs/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/741">741</ref>
<ref source="XF" url="http://xforce.iss.net/static/3433.php">squid-proxy-auth-access(3433)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1486" seq="1999-1486">
<status>Entry</status>
<desc>sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="CONFIRM" url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only">IX75554</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only">IX76853</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only">IX76330</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/408">408</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7675">aix-sadc-timex(7675)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1488" seq="1999-1488">
<status>Entry</status>
<desc>sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml">I-079A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/371">371</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7217.php">ibm-sdr-read-files(7217)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1490" seq="1999-1490">
<status>Entry</status>
<desc>xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926021&amp;w=2">19980528 ALERT: Tiresome security hole in &quot;xosview&quot;, RedHat5.1?</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926034&amp;w=2">19980529 Re: Tiresome security hole in &quot;xosview&quot; (xosexp.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/362">362</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/8787.php">linux-xosview-bo(8787)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1494" seq="1999-1494">
<status>Entry</status>
<desc>colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/675">19940809 Re: IRIX 5.2 Security Advisory</ref>
<ref source="BUGTRAQ" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html">19950307 sigh. another Irix 5.2 hole.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P">19950209-00-P</ref>
<ref source="XF" url="http://xforce.iss.net/static/2112.php">sgi-colorview(2112)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/336">336</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1507" seq="1999-1507">
<status>Entry</status>
<desc>Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-03.html">CA-1993-03</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/59">59</ref>
<ref source="XF" url="http://xforce.iss.net/static/521.php">sun-dir(521)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1512" seq="1999-1512">
<status>Entry</status>
<desc>The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93219846414732&amp;w=2">19990716 AMaViS virus scanner for Linux - root exploit</ref>
<ref source="CONFIRM" url="http://www.amavis.org/ChangeLog.txt">http://www.amavis.org/ChangeLog.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/527">527</ref>
<ref source="XF" url="http://xforce.iss.net/static/2349.php">amavis-command-execute(2349)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1520" seq="1999-1520">
<status>Entry</status>
<desc>A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407227303&amp;w=2">19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/256">256</ref>
<ref source="XF" url="http://xforce.iss.net/static/2270.php">siteserver-site-csc(2270)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1530" seq="1999-1530">
<status>Entry</status>
<desc>cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94209954200450&amp;w=2">19991108 Security flaw in Cobalt RaQ2 cgiwrap</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225629200045&amp;w=2">19991109 [Cobalt] Security Advisory - cgiwrap</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/777">777</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7764.php">cobalt-cgiwrap-incorrect-permissions(7764)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/35">35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1531" seq="1999-1531">
<status>Entry</status>
<desc>Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/763">763</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7767.php">ibm-homepageprint-bo(7767)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1535" seq="1999-1535">
<status>Entry</status>
<desc>Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93256878011447&amp;w=2">19990720 Buffer overflow in AspUpload 1.4</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93501427820328&amp;w=2">19990818 AspUpload Buffer Overflow Fixed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/592">592</ref>
<ref source="XF" url="http://xforce.iss.net/static/3291.php">http-aspupload-bo(3291)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1537" seq="1999-1537">
<status>Entry</status>
<desc>IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827329577&amp;w=2">19990707 SSL and IIS.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/521">521</ref>
<ref source="XF" url="http://xforce.iss.net/static/2352.php">ssl-iis-dos(2352)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1542" seq="1999-1542">
<status>Entry</status>
<desc>RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the &quot;MAIL FROM&quot; command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915641729415&amp;w=2">19991004 RH6.0 local/remote command execution</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923853105687&amp;w=2">19991006 Fwd: [Re: RH6.0 local/remote command execution]</ref>
<ref source="XF" url="http://xforce.iss.net/static/3353.php">linux-rh-rpmmail(3353)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1550" seq="1999-1550">
<status>Entry</status>
<desc>bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the &quot;file&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217006208374&amp;w=2">19991108 BigIP - bigconf.cgi holes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217879020184&amp;w=2">19991109 Re: BigIP - bigconf.cgi holes </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225879703021&amp;w=2">19991109 </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/778">778</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7771.php">bigip-bigconf-view-files(7771)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1556" seq="1999-1556">
<status>Entry</status>
<desc>Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431645&amp;w=2">19980629 MS SQL Server 6.5 stores password in unprotected registry keys</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/109">109</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7354">mssql-sqlexecutivecmdexec-password(7354)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1565" seq="1999-1565">
<status>Entry</status>
<desc>Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/24784">19990820 [SECURITY] New versions of man2html fixes postinst glitch</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6291">6291</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1568" seq="1999-1568">
<status>Entry</status>
<desc>Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91981352617720&amp;w=2">19990223 NcFTPd remote buffer overflow</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12699">19990223 Comments on NcFTPd &quot;theoretical root compromise&quot;</ref>
<ref source="XF" url="http://xforce.iss.net/static/1833.php">ncftpd-port-bo(1833)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0001" seq="2000-0001">
<status>Entry</status>
<desc>RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.</desc>
<refs>
<ref source="BUGTRAQ">19991222 RealMedia Server 5.0 Crasher (rmscrash.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/888">888</ref>
<ref source="XF">realserver-ramgen-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0002" seq="2000-0002">
<status>Entry</status>
<desc>Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94598388530358&amp;w=2">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=36B0596E.8D111D66@teleline.es">20000128 ZBServer 1.50-r1x exploit (WinNT)</ref>
<ref source="VULNWATCH">20020114 ZBServer Pro DoS Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/889">889</ref>
<ref source="XF">zbserver-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0003" seq="2000-0003">
<status>Entry</status>
<desc>Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19991230 UnixWare rtpm exploit + discussion</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0004" seq="2000-0004">
<status>Entry</status>
<desc>ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606572912422&amp;w=2">19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="XF">zbserver-url-dot</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0006" seq="2000-0006">
<status>Entry</status>
<desc>strace allows local users to read arbitrary files via memory mapped file names.</desc>
<refs>
<ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/39831">19991225 strace can lie</ref>
<ref source="XF" url="http://xforce.iss.net/static/4554.php">linux-strace(4554)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0007" seq="2000-0007">
<status>Entry</status>
<desc>Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19991230 PC-Cillin 6.x DoS Attack</ref>
<ref source="XF" url="http://xforce.iss.net/static/4491.php">pccillin-proxy-remote-dos(4491)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1740">1740</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0009" seq="2000-0009">
<status>Entry</status>
<desc>The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the &quot;rm&quot; program, which allows local users to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">19991230 bna,sh</ref>
<ref source="XF">netarchitect-path-vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/907">907</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0010" seq="2000-0010">
<status>Entry</status>
<desc>WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.</desc>
<refs>
<ref source="BUGTRAQ">19991226 WebWho+ ADVISORY</ref>
<ref source="XF">http-cgi-webwhoplus</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0011" seq="2000-0011">
<status>Entry</status>
<desc>Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ">19991231 Local / Remote GET Buffer Overflow Vulnerability in AnalogX SimpleServer:WWW HTTP Server v1.1</ref>
<ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
<ref source="XF">simpleserver-get-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/906">906</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1184">1184</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0012" seq="2000-0012">
<status>Entry</status>
<desc>Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19991227 remote buffer overflow in miniSQL</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/898">898</ref>
<ref source="XF">w3-msql-scanf-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0013" seq="2000-0013">
<status>Entry</status>
<desc>IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.</desc>
<refs>
<ref source="BUGTRAQ">19991231 irix-soundplayer.sh</ref>
<ref source="XF">irix-soundplayer-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/909">909</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0014" seq="2000-0014">
<status>Entry</status>
<desc>Denial of service in Savant web server via a null character in the requested URL.</desc>
<refs>
<ref source="BUGTRAQ">19991228 Local / Remote D.o.S Attack in Savant Web Server V2.0 WIN9X / NT / 2K</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/897">897</ref>
<ref source="XF">savant-server-null-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0015" seq="2000-0015">
<status>Entry</status>
<desc>CascadeView TFTP server allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991231 tftpserv.sh</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/910">910</ref>
<ref source="XF">cascadeview-tftp-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0018" seq="2000-0018">
<status>Entry</status>
<desc>wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19991221 Wmmon under FreeBSD</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/885">885</ref>
<ref source="XF">freebsd-wmmon-root-exploit</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1169">1169</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0020" seq="2000-0020">
<status>Entry</status>
<desc>DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.</desc>
<refs>
<ref source="NTBUGTRAQ">19991221 Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability</ref>
<ref source="BUGTRAQ">19991221 Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability</ref>
<ref source="XF">dnspro-flood-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0022" seq="2000-0022">
<status>Entry</status>
<desc>Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.</desc>
<refs>
<ref source="BUGTRAQ">19991221 serious Lotus Domino HTTP denial of service</ref>
<ref source="BUGTRAQ">19991227 Re: Lotus Domino HTTP denial of service attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0023" seq="2000-0023">
<status>Entry</status>
<desc>Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19991221 serious Lotus Domino HTTP denial of service</ref>
<ref source="BUGTRAQ">19991222 Lotus Notes HTTP cgi-bin vulnerability: possible workaround</ref>
<ref source="BUGTRAQ">19991227 Re: Lotus Domino HTTP denial of service attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
<ref source="OSVDB" url="http://www.osvdb.org/51">51</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0024" seq="2000-0024">
<status>Entry</status>
<desc>IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the &quot;Escape Character Parsing&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-061.asp">MS99-061</ref>
<ref source="BUGTRAQ">19991228 Third Party Software Affected by IIS &quot;Escape Character Parsing&quot; Vulnerability</ref>
<ref source="BUGTRAQ">19991229 More info on MS99-061 (IIS escape character vulnerability)</ref>
<ref source="XF">iis-badescapes</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246401">Q246401</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0025" seq="2000-0025">
<status>Entry</status>
<desc>IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the &quot;Virtual Directory Naming&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-058.mspx">MS99-058</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238606">Q238606</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8098">8098</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0026" seq="2000-0026">
<status>Entry</status>
<desc>Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.</desc>
<refs>
<ref source="BUGTRAQ">19991222 UnixWare i2odialogd remote root exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/876">876</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6310">6310</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0027" seq="2000-0027">
<status>Entry</status>
<desc>IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39962">19991227 IBM NetStation/UnixWare local root exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/900">900</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/5381.php">ibm-netstat-race-condition(5381)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0029" seq="2000-0029">
<status>Entry</status>
<desc>UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991227 UnixWare local pis exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/901">901</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0030" seq="2000-0030">
<status>Entry</status>
<desc>Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.</desc>
<refs>
<ref source="BUGTRAQ">19991222 Solaris 2.7 dmispd local/remote problems</ref>
<ref source="XF">sol-dmispd-fill-disk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0031" seq="2000-0031">
<status>Entry</status>
<desc>The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="L0PHT">19991227 initscripts-4.48-1 RedHat Linux 6.1</ref>
<ref source="REDHAT">RHSA-1999:052-04</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0032" seq="2000-0032">
<status>Entry</status>
<desc>Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.</desc>
<refs>
<ref source="BUGTRAQ">19991222 Solaris 2.7 dmispd local/remote problems</ref>
<ref source="XF">sol-dmispd-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7582">7582</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0033" seq="2000-0033">
<status>Entry</status>
<desc>InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.</desc>
<refs>
<ref source="BUGTRAQ">19991227 Trend Micro InterScan VirusWall SMTP bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/899">899</ref>
<ref source="XF">interscan-viruswall-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0034" seq="2000-0034">
<status>Entry</status>
<desc>Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled &quot;remember passwords.&quot;</desc>
<refs>
<ref source="BUGTRAQ">19991222 More Netscape Passwords Available.</ref>
<ref source="XF">netscape-password-preferences</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0036" seq="2000-0036">
<status>Entry</status>
<desc>Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the &quot;HTML Mail Attachment&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-060.asp">MS99-060</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249082">Q249082</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0037" seq="2000-0037">
<status>Entry</status>
<desc>Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19991228 majordomo local exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
<ref source="BUGTRAQ">20000124 majordomo 1.94.5 does not fix all vulnerabilities</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-005.html">RHSA-2000:005</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/903">903</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0039" seq="2000-0039">
<status>Entry</status>
<desc>AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.</desc>
<refs>
<ref source="BUGTRAQ">19991229 AltaVista</ref>
<ref source="BUGTRAQ">19991230 Follow UP AltaVista</ref>
<ref source="BUGTRAQ">19991229 AltaVista followup and monitor script</ref>
<ref source="BUGTRAQ">20000103 FW: Patch issued for AltaVista Search Engine Directory TraversalVulnerability</ref>
<ref source="BUGTRAQ">20000109 Altavista followup</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/896">896</ref>
<ref source="OSVDB" url="http://www.osvdb.org/15">15</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0040" seq="2000-0040">
<status>Entry</status>
<desc>glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.</desc>
<refs>
<ref source="BUGTRAQ">19991223 Multiple vulnerabilites in glFtpD (current versions)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0041" seq="2000-0041">
<status>Entry</status>
<desc>Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.</desc>
<refs>
<ref source="BUGTRAQ">19991229 The &quot;Mac DoS Attack,&quot; a Scheme for Blocking Internet Connections</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/890">890</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0042" seq="2000-0042">
<status>Entry</status>
<desc>Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.</desc>
<refs>
<ref source="BUGTRAQ">19991229 Local / Remote D.o.S Attack in  CSM Mail Server for Windows 95/NT v.2000.08.A</ref>
<ref source="XF">csm-server-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/895">895</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0043" seq="2000-0043">
<status>Entry</status>
<desc>Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ">19991230 Local / Remote GET Buffer Overflow Vulnerability in CamShot WebCam HTTP Server v2.5 for Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/905">905</ref>
<ref source="XF">camshot-http-get-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0044" seq="2000-0044">
<status>Entry</status>
<desc>Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.</desc>
<refs>
<ref source="BUGTRAQ">20000105 SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/919">919</ref>
<ref source="XF">warftp-macro-access-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0045" seq="2000-0045">
<status>Entry</status>
<desc>MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.</desc>
<refs>
<ref source="BUGTRAQ">20000111 Serious bug in MySQL password handling.</ref>
<ref source="BUGTRAQ">20000113 New MySQL Available</ref>
<ref source="XF">mysql-pwd-grant</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/926">926</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0048" seq="2000-0048">
<status>Entry</status>
<desc>get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.</desc>
<refs>
<ref source="BUGTRAQ">20000112 Serious Bug in Corel Linux.(Local root exploit)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/928">928</ref>
<ref source="CONFIRM" url="http://linux.corel.com/support/clos_patch1.htm">http://linux.corel.com/support/clos_patch1.htm</ref>
<ref source="XF">linux-corel-update</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0050" seq="2000-0050">
<status>Entry</status>
<desc>The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13976&amp;Method=Full">ASB00-01</ref>
<ref source="XF">allaire-webtop-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/915">915</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0051" seq="2000-0051">
<status>Entry</status>
<desc>The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13977&amp;Method=Full">ASB00-02</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/916">916</ref>
<ref source="XF">allaire-spectra-config-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0052" seq="2000-0052">
<status>Entry</status>
<desc>Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.</desc>
<refs>
<ref source="L0PHT" url="http://www.l0pht.com/advisories/pam_advisory">20000104 PamSlam</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-001.html">RHSA-2000:001</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=linux-pam-userhelper">linux-pam-userhelper</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/913">913</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0053" seq="2000-0053">
<status>Entry</status>
<desc>Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-001.asp">MS00-001</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246731">Q246731</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/912">912</ref>
<ref source="XF">mcis-malformed-imap</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0056" seq="2000-0056">
<status>Entry</status>
<desc>IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.</desc>
<refs>
<ref source="BUGTRAQ">20000105 Local / Remote D.o.S Attack in IMail IMONITOR Server for WinNT Version 5.08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/914">914</ref>
<ref source="XF">imail-imonitor-status-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0057" seq="2000-0057">
<status>Entry</status>
<desc>Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13978&amp;Method=Full">ASB00-03</ref>
<ref source="XF">coldfusion-cfcache</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/917">917</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0060" seq="2000-0060">
<status>Entry</status>
<desc>Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94647711311057&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94633851427858&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/894">894</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3765.php">avirt-rover-pop3-dos(3765)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0062" seq="2000-0062">
<status>Entry</status>
<desc>The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000104222219.B41650@schvin.net">20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/922">922</ref>
<ref source="XF">zope-dtml</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0063" seq="2000-0063">
<status>Entry</status>
<desc>cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.</desc>
<refs>
<ref source="BUGTRAQ">20000118 Nortel Contivity Vulnerability</ref>
<ref source="XF">http-cgi-cgiproc-file-read</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0064" seq="2000-0064">
<status>Entry</status>
<desc>cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000118 Nortel Contivity Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
<ref source="XF">http-cgi-cgiproc-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7583">7583</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0065" seq="2000-0065">
<status>Entry</status>
<desc>Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="NTBUGTRAQ">20000117 Remote Buffer Exploit - InetServ 3.0</ref>
<ref source="XF">inetserv-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0070" seq="2000-0070">
<status>Entry</status>
<desc>NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka &quot;Spoofed LPC Port Request.&quot;</desc>
<refs>
<ref source="BINDVIEW" url="http://www.bindview.com/security/advisory/adv_NtImpersonate.html">20000113 Local Promotion Vulnerability in Windows NT 4</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-003.asp">MS00-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247869">Q247869</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=nt-spoofed-lpc-port">nt-spoofed-lpc-port</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/934">934</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0072" seq="2000-0072">
<status>Entry</status>
<desc>Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94823061421676&amp;w=2">20000118 Warning: VCasel security hole.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/937">937</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3867.php">vcasel-filename-trusting(3867)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0073" seq="2000-0073">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-005.asp">MS00-005</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249973">Q249973</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=win-malformed-rtf-control-word">win-malformed-rtf-control-word</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0075" seq="2000-0075">
<status>Entry</status>
<desc>Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.</desc>
<refs>
<ref source="NTBUGTRAQ">20000113 Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x</ref>
<ref source="BUGTRAQ">20000113 Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/930">930</ref>
<ref source="XF">supermail-memleak-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0076" seq="2000-0076">
<status>Entry</status>
<desc>nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94709988232618&amp;w=2">19991230 vibackup.sh</ref>
<ref source="DEBIAN">20000108</ref>
<ref source="XF">nvi-delete-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1439">1439</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0080" seq="2000-0080">
<status>Entry</status>
<desc>AIX techlibss allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94757136413681&amp;w=2">20000110 2nd attempt: AIX techlibss follows links</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/931">931</ref>
<ref source="XF">aix-techlibss-symbolic-link</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0083" seq="2000-0083">
<status>Entry</status>
<desc>HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2031">HPSBUX0001-109</ref>
<ref source="XF">hp-audio-security-perms</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0087" seq="2000-0087">
<status>Entry</status>
<desc>Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94790377622943&amp;w=2">20000113 Misleading sense of security in Netscape</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4385.php">netscape-mail-notify-plaintext(4385)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0088" seq="2000-0088">
<status>Entry</status>
<desc>Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the &quot;Malformed Conversion Data&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-002.mspx">MS00-002</ref>
<ref source="XF">office-malformed-convert</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/946">946</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0089" seq="2000-0089">
<status>Entry</status>
<desc>The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the &quot;RDISK Registry Enumeration File&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000121 RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition</ref>
<ref source="BUGTRAQ">20000122 RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-004.mspx">MS00-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249108">Q249108</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/947">947</ref>
<ref source="XF">nt-rdisk-enum-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0090" seq="2000-0090">
<status>Entry</status>
<desc>VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">20000124 VMware 1.1.2 Symlink Vulnerability</ref>
<ref source="XF">linux-vmware-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/943">943</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1205">1205</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0091" seq="2000-0091">
<status>Entry</status>
<desc>Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.</desc>
<refs>
<ref source="BUGTRAQ">20000122 remote root qmail-pop with vpopmail advisory and exploit with patch</ref>
<ref source="BUGTRAQ">20000123 Re: vpopmail/vchkpw remote root exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/942">942</ref>
<ref source="MISC" url="http://www.inter7.com/vpopmail/ChangeLog">http://www.inter7.com/vpopmail/ChangeLog</ref>
<ref source="MISC" url="http://www.inter7.com/vpopmail/">http://www.inter7.com/vpopmail/</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0092" seq="2000-0092">
<status>Entry</status>
<desc>The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc">FreeBSD-SA-00:01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/939">939</ref>
<ref source="XF">gnu-makefile-tmp-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0094" seq="2000-0094">
<status>Entry</status>
<desc>procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.</desc>
<refs>
<ref source="BUGTRAQ">20000121 *BSD procfs vulnerability</ref>
<ref source="FREEBSD">FreeBSD-SA-00:02</ref>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-001.txt.asc">NetBSD-SA2000-001</ref>
<ref source="OPENBSD">20000120 [2.6] 018: SECURITY FIX: Jan 20, 2000</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/940">940</ref>
<ref source="OSVDB" url="http://www.osvdb.org/20760">20760</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3995">netbsd-procfs(3995)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0095" seq="2000-0095">
<status>Entry</status>
<desc>The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2041">HPSBUX0001-110</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/944">944</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0097" seq="2000-0097">
<status>Entry</status>
<desc>The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the &quot;Malformed Hit-Highlighting Argument&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000127 Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV000126)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/950">950</ref>
<ref source="XF">http-indexserver-dirtrans</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1210">1210</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0098" seq="2000-0098">
<status>Entry</status>
<desc>Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0099" seq="2000-0099">
<status>Entry</status>
<desc>Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94848865112897&amp;w=2">20000119 Unixware ppptalk</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0100" seq="2000-0100">
<status>Entry</status>
<desc>The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0045.html">20000115 Security Vulnerability with SMS 2.0 Remote Control</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-012.asp">MS00-012</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0107" seq="2000-0107">
<status>Entry</status>
<desc>Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000201">20000201</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/958">958</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0111" seq="2000-0111">
<status>Entry</status>
<desc>The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.</desc>
<refs>
<ref source="BUGTRAQ">20000129 [LoWNOISE] Rightfax web client 5.2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/953">953</ref>
<ref source="XF">avt-rightfax-predict-session</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0112" seq="2000-0112">
<status>Entry</status>
<desc>The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973075614088&amp;w=2">20000202 vulnerability in Linux Debian default boot configuration</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/960">960</ref>
<ref source="XF">debian-mbr-bypass-security</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0113" seq="2000-0113">
<status>Entry</status>
<desc>The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94934808714972&amp;w=2">20000128 SyGate 3.11 Port 7323 / Remote Admin hole</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94952641025328&amp;w=2">20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973281714994&amp;w=2">20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole</ref>
<ref source="CONFIRM" url="http://www.sybergen.com/support/fix.htm">http://www.sybergen.com/support/fix.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/952">952</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0116" seq="2000-0116">
<status>Entry</status>
<desc>Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the &quot;Strip Script Tags&quot; restriction by including an extra &lt; in front of the SCRIPT tag.</desc>
<refs>
<ref source="NTBUGTRAQ">20000129 &quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref>
<ref source="BUGTRAQ">20000129 &quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/954">954</ref>
<ref source="XF">http-script-bypass</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1212">1212</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0117" seq="2000-0117">
<status>Entry</status>
<desc>The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).</desc>
<refs>
<ref source="BUGTRAQ">20000127 Cobalt RaQ2 - a user of mine changed my admin password..</ref>
<ref source="BUGTRAQ">20000131 [ Cobalt ] Security Advisory -- 01.31.2000</ref>
<ref source="XF">http-cgi-cobalt-passwords</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/951">951</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0120" seq="2000-0120">
<status>Entry</status>
<desc>The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.</desc>
<refs>
<ref source="ALLAIRE">ASB00-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/955">955</ref>
<ref source="XF" url="http://xforce.iss.net/static/4025.php">allaire-spectra-ras-access(4025)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0121" seq="2000-0121">
<status>Entry</status>
<desc>The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the &quot;Recycle Bin Creation&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000201 &quot;Recycle Bin Creation&quot; Vulnerability in Windows NT / Windows 2000</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-007.mspx">MS00-007</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248399">Q248399</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/963">963</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0127" seq="2000-0127">
<status>Entry</status>
<desc>The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.</desc>
<refs>
<ref source="BUGTRAQ">20000203 Webspeed security issue</ref>
<ref source="CONFIRM" url="http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed">http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/969">969</ref>
<ref source="XF">webspeed-adminutil-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0128" seq="2000-0128">
<status>Entry</status>
<desc>The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000204 &quot;The Finger Server&quot;</ref>
<ref source="CONFIRM" url="http://www.glazed.org/finger/changelog.txt">http://www.glazed.org/finger/changelog.txt</ref>
<ref source="XF">finger-server-input</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7610">7610</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0130" seq="2000-0130">
<status>Entry</status>
<desc>Buffer overflow in SCO scohelp program allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.02a">SB-00.02a</ref>
<ref source="XF">sco-help-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0131" seq="2000-0131">
<status>Entry</status>
<desc>Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94960703721503&amp;w=2">20000201 war-ftpd 1.6x DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/966">966</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4677">4677</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0139" seq="2000-0139">
<status>Entry</status>
<desc>Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/982">982</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0140" seq="2000-0140">
<status>Entry</status>
<desc>Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="NTBUGTRAQ">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/980">980</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0141" seq="2000-0141">
<status>Entry</status>
<desc>Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=20000211224935.A13236@infomag.ape.relarn.ru">20000211 perl-cgi hole in UltimateBB by Infopop Corp.</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/991">991</ref>
<ref source="MISC" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
<ref source="XF">http-cgi-ultimatebb</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0144" seq="2000-0144">
<status>Entry</status>
<desc>Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0034.html">20000207 Infosec.20000207.axis700.a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/971">971</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0145" seq="2000-0145">
<status>Entry</status>
<desc>The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.</desc>
<refs>
<ref source="BUGTRAQ">20000205 Debian (frozen): Perms on /usr/lib/libguile.so.6.0.0</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0146" seq="2000-0146">
<status>Entry</status>
<desc>The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0049.html">20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/972">972</ref>
<ref source="XF">novell-groupwise-url-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0148" seq="2000-0148">
<status>Entry</status>
<desc>MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html">20000208 Remote access vulnerability in all MySQL server versions</ref>
<ref source="BUGTRAQ">20000214 MySQL 3.22.32 released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/975">975</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0149" seq="2000-0149">
<status>Entry</status>
<desc>Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.</desc>
<refs>
<ref source="BUGTRAQ">20000209 [SAFER 000209.EXP.1.2] Zeus Web Server - obtaining source of CGI scripts</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html">20000208 Zeus Web Server: Null Terminated Strings</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/977">977</ref>
<ref source="OSVDB" url="http://www.osvdb.org/254">254</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3982">zeus-server-null-string(3982)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0150" seq="2000-0150">
<status>Entry</status>
<desc>Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.</desc>
<refs>
<ref source="BUGTRAQ">20000209 FireWall-1 FTP Server Vulnerability</ref>
<ref source="BUGTRAQ">20000212 Re: FireWall-1 FTP Server Vulnerability</ref>
<ref source="BUGTRAQ">20000210 Multiple firewalls: FTP Application Level Gateway &quot;PASV&quot; Vulnerability</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/328867">VU#328867</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/979">979</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4417">4417</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0152" seq="2000-0152">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.</desc>
<refs>
<ref source="BUGTRAQ">20000209 Novell BorderManager 3.5 Remote Slow Death</ref>
<ref source="BUGTRAQ">20000211 BorderManager csatpxy.nlm fix avalable.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/976">976</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7468">7468</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0156" seq="2000-0156">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the &quot;Image Source Redirect&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-009.mspx">MS00-009</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7827">7827</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3996">ie-image-source-redirect(3996)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0157" seq="2000-0157">
<status>Entry</status>
<desc>NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-012.txt.asc">1999-012</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/992">992</ref>
<ref source="XF">netbsd-ptrace</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0159" seq="2000-0159">
<status>Entry</status>
<desc>HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000217160216.13708.qmail@underground.org">HPSBUX0002-111</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0161" seq="2000-0161">
<status>Entry</status>
<desc>Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-010.asp">MS00-010</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/994">994</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0162" seq="2000-0162">
<status>Entry</status>
<desc>The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the &quot;VM File Reading&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-011.asp">MS00-011</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0164" seq="2000-0164">
<status>Entry</status>
<desc>The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl">20000220 Sun Internet Mail Server</ref>
<ref source="SUNBUG">4316521</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1004">1004</ref>
<ref source="XF">sims-temp-world-readable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0165" seq="2000-0165">
<status>Entry</status>
<desc>The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">20000210 Re: application proxies?</ref>
<ref source="FREEBSD" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.BSF.4.21.0002192249290.10784-100000@freefall.freebsd.org">FreeBSD-SA-00:04</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-023.shtml">K-023</ref>
<ref source="XF">delegate-proxy-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0166" seq="2000-0166">
<status>Entry</status>
<desc>Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com">20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref>
<ref source="BUGTRAQ">20000223 Pragma Systems response to USSRLabs report</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/995">995</ref>
<ref source="XF">interaccess-telnet-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0168" seq="2000-0168">
<status>Entry</status>
<desc>Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the &quot;DOS Device in Path Name&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCENECCAA.labs@ussrback.com">20000306 con\con is a old thing (anyway is cool)</ref>
<ref source="MS" url="http://www.securityfocus.com/templates/advisory.html?id=2126">MS00-017</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1043">1043</ref>
<ref source="XF">win-dos-devicename-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0169" seq="2000-0169">
<status>Entry</status>
<desc>Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&amp;'.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html">20000314 Oracle Web Listener 4.0.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1053">1053</ref>
<ref source="XF">oracle-weblistener-remote-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0170" seq="2000-0170">
<status>Entry</status>
<desc>Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">20000226 man bugs might lead to root compromise (RH 6.1 and other boxes)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1011">1011</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0171" seq="2000-0171">
<status>Entry</status>
<desc>atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0102.html">20000311 TESO advisory -- atsadc</ref>
<ref source="XF">atsar-root-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1048">1048</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0172" seq="2000-0172">
<status>Entry</status>
<desc>The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">20000303 Potential security problem with mtr</ref>
<ref source="DEBIAN">20000309 mtr</ref>
<ref source="FREEBSD">FreeBSD-SA-00:09</ref>
<ref source="BUGTRAQ">20000308 [TL-Security-Announce] mtr-0.41 and earlier TLSA2000003-1 (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1038">1038</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0174" seq="2000-0174">
<status>Entry</status>
<desc>StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1040">1040</ref>
<ref source="XF">staroffice-scheduler-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0175" seq="2000-0175">
<status>Entry</status>
<desc>Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
<ref source="XF">staroffice-scheduler-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1039">1039</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0178" seq="2000-0178">
<status>Entry</status>
<desc>ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.</desc>
<refs>
<ref source="BUGTRAQ">20000227 Advisory: Foundry Networks ServerIron TCP/IP sequence predictability</ref>
<ref source="MISC" url="http://www.foundrynet.com/bugTraq.html">http://www.foundrynet.com/bugTraq.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1017">1017</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0179" seq="2000-0179">
<status>Entry</status>
<desc>HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0387.html">20000228 HP Omniback remote DoS</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0006-115">HPSBUX0006-115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1015">1015</ref>
<ref source="XF">omniback-connection-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0180" seq="2000-0180">
<status>Entry</status>
<desc>Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0201.html">20000313 SOJOURN Search engine exposes files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1052">1052</ref>
<ref source="XF" url="http://xforce.iss.net/static/4197.php">sojourn-file-read(4197)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0181" seq="2000-0181">
<status>Entry</status>
<desc>Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0119.html">20000311 Our old friend Firewall-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1054">1054</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1256">1256</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0182" seq="2000-0182">
<status>Entry</status>
<desc>iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.</desc>
<refs>
<ref source="BUGTRAQ">20000223 DoS for the iPlanet Web Server, Enterprise Edition 4.1</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0183" seq="2000-0183">
<status>Entry</status>
<desc>Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0093.html">20000310 Fwd: ircii-4.4 buffer overflow</ref>
<ref source="FREEBSD">FreeBSD-SA-00:11</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-008.html">RHSA-2000:008</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1046">1046</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0184" seq="2000-0184">
<status>Entry</status>
<desc>Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0082.html">20000309</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1037">1037</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0185" seq="2000-0185">
<status>Entry</status>
<desc>RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0069.html">20000308 RealServer exposes internal IP addresses</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1049">1049</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0186" seq="2000-0186">
<status>Entry</status>
<desc>Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ">20000228 [ Hackerslab bug_paper ] Linux dump buffer overflow</ref>
<ref source="TURBO">TLSA200007-1</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-100.html">RHSA-2000:100</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1020">1020</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0189" seq="2000-0189">
<status>Entry</status>
<desc>ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.</desc>
<refs>
<ref source="NTBUGTRAQ">20000301 ColdFusions application.cfm shows full path</ref>
<ref source="BUGTRAQ">20000305 ColdFusion Bug: Application.cfm shows full path</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1021">1021</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0191" seq="2000-0191">
<status>Entry</status>
<desc>Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=41256894.00492503.00@mailgw.backupcentralen.se">20000229 Infosec.20000229.axisstorpointcd.a</ref>
<ref source="XF">axis-storpoint-auth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1025">1025</ref>
<ref source="OSVDB" url="http://www.osvdb.org/19">19</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0192" seq="2000-0192">
<status>Entry</status>
<desc>The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0029.html">20000304 OpenLinux 2.3: rpm_query</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1036">1036</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0193" seq="2000-0193">
<status>Entry</status>
<desc>The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003020436.PAA20168@jawa.chilli.net.au">20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1030">1030</ref>
<ref source="XF">linux-dosemu-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0194" seq="2000-0194">
<status>Entry</status>
<desc>buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1007">1007</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0195" seq="2000-0195">
<status>Entry</status>
<desc>setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1008">1008</ref>
<ref source="XF">corel-linux-setxconf-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0196" seq="2000-0196">
<status>Entry</status>
<desc>Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.</desc>
<refs>
<ref source="DEBIAN">20000229</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-006.html">RHSA-2000:006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1018">1018</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0200" seq="2000-0200">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the &quot;Clip Art Buffer Overrun&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-015.mspx">MS00-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1034">1034</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0201" seq="2000-0201">
<status>Entry</status>
<desc>The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.</desc>
<refs>
<ref source="BUGTRAQ">20000301 IE 5.x allows executing arbitrary programs using .chm files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1033">1033</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0202" seq="2000-0202">
<status>Entry</status>
<desc>Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-014.mspx">MS00-014</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1041">1041</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0206" seq="2000-0206">
<status>Entry</status>
<desc>The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html">20000305 Oracle installer problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1035">1035</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0207" seq="2000-0207">
<status>Entry</status>
<desc>SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000301 infosrch.cgi vulnerability (IRIX 6.5)</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000501-01-P">20000501-01-P</ref>
<ref source="XF">irix-infosrch-fname</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1031">1031</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0208" seq="2000-0208">
<status>Entry</status>
<desc>The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.</desc>
<refs>
<ref source="BUGTRAQ">20000228 ht://Dig remote information exposure</ref>
<ref source="FREEBSD">FreeBSD-SA-00:06</ref>
<ref source="DEBIAN">20000227</ref>
<ref source="TURBO">TLSA200005-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1026">1026</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0209" seq="2000-0209">
<status>Entry</status>
<desc>Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.</desc>
<refs>
<ref source="BUGTRAQ">20000227 lynx - someone is deaf and blind ;)</ref>
<ref source="FREEBSD">FreeBSD-SA-00:08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1012">1012</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0210" seq="2000-0210">
<status>Entry</status>
<desc>The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">20000221 flex license manager tempfile predictable name...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/998">998</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0211" seq="2000-0211">
<status>Entry</status>
<desc>The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the &quot;Misordered Windows Media Services Handshake&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-013.mspx">MS00-013</ref>
<ref source="XF">win-media-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1000">1000</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0212" seq="2000-0212">
<status>Entry</status>
<desc>InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.</desc>
<refs>
<ref source="BUGTRAQ">20000224 Local / Remote D.o.S Attack in InterAccess TelnetD Server Release 4.0 *ALL BUILDS* for WinNT Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1001">1001</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4033">interaccess-telnet-dos(4033)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0215" seq="2000-0215">
<status>Entry</status>
<desc>Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.</desc>
<refs>
<ref source="SCO">SB-00.05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1019">1019</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0217" seq="2000-0217">
<status>Entry</status>
<desc>The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.</desc>
<refs>
<ref source="BUGTRAQ">20000224 SSH &amp; xauth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1006">1006</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0218" seq="2000-0218">
<status>Entry</status>
<desc>Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.</desc>
<refs>
<ref source="SUSE">20000210 util &lt; 2.10f</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-002.0.txt">CSSA-2000-002.0</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6980">6980</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7004">7004</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0221" seq="2000-0221">
<status>Entry</status>
<desc>The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.</desc>
<refs>
<ref source="BUGTRAQ">20000225 Scorpion Marlin</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1009">1009</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0222" seq="2000-0222">
<status>Entry</status>
<desc>The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000215155750.M4500@safe.hsc.fr">20000215 Windows 2000 installation process weakness</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/990">990</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0223" seq="2000-0223">
<status>Entry</status>
<desc>Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0107.html">20000311 TESO advisory -- wmcdplay</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1047">1047</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0224" seq="2000-0224">
<status>Entry</status>
<desc>ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.</desc>
<refs>
<ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref>
<ref source="SCO">SSE063</ref>
<ref source="XF">sco-openserver-arc-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0225" seq="2000-0225">
<status>Entry</status>
<desc>The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003601bf854b$6893a090$0100a8c0@FIREWALKER">20000303 Pocsag remote access to client can't be disabled.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1032">1032</ref>
<ref source="XF">telnet-pocsag</ref>
<ref source="OSVDB" url="http://www.osvdb.org/259">259</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0226" seq="2000-0226">
<status>Entry</status>
<desc>IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the &quot;Chunked Transfer Encoding Buffer Overflow Vulnerability.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-018.asp">MS00-018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1066">1066</ref>
<ref source="XF">iis-chunked-encoding-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0228" seq="2000-0228">
<status>Entry</status>
<desc>Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the &quot;Malformed Media License Request&quot; Vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-016.asp">MS00-016</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1058">1058</ref>
<ref source="XF">mwmt-malformed-media-license</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0229" seq="2000-0229">
<status>Entry</status>
<desc>gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0242.html">20000322 gpm-root</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_45.html">20000405 Security hole in gpm &lt; 1.18.1</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-009.html">RHSA-2000:009</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1069">1069</ref>
<ref source="XF">linux-gpm-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0230" seq="2000-0230">
<status>Entry</status>
<desc>Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html">20000316 TESO &amp; C-Skills development advisory -- imwheel</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref>
<ref source="XF">linux-imwheel-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1060">1060</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0231" seq="2000-0231">
<status>Entry</status>
<desc>Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0162.html">20000316 &quot;TESO &amp; C-Skills development advisory -- kreatecd&quot; at:</ref>
<ref source="SUSE">20000405 Security hole in kreatecd &lt; 0.3.8b</ref>
<ref source="XF">linux-kreatecd-path</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1061">1061</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0232" seq="2000-0232">
<status>Entry</status>
<desc>Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-021.asp">MS00-021</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0306.html">20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1082">1082</ref>
<ref source="XF">win-tcpip-printing-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0233" seq="2000-0233">
<status>Entry</status>
<desc>SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.</desc>
<refs>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/vendor/2000-q1/0035.html">20000327 Security hole in SuSE Linux IMAP Server</ref>
<ref source="XF">linux-imap-remote-unauthorized-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0234" seq="2000-0234">
<status>Entry</status>
<desc>The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000330220757.28456.qmail@securityfocus.com">20000330 Cobalt apache configuration exposes .htaccess</ref>
<ref source="CONFIRM" url="http://www.securityfocus.com/templates/advisory.html?id=2150">http://www.securityfocus.com/templates/advisory.html?id=2150</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1083">1083</ref>
<ref source="XF">cobalt-raq-remote-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0235" seq="2000-0235">
<status>Entry</status>
<desc>Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:10-orville-write.asc">FreeBSD-SA-00:10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1070">1070</ref>
<ref source="XF">freebsd-orvillewrite-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1263">1263</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0236" seq="2000-0236">
<status>Entry</status>
<desc>Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38D2173D.24E39DD0@relaygroup.com">20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1063">1063</ref>
<ref source="XF">netscape-server-directory-indexing</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0237" seq="2000-0237">
<status>Entry</status>
<desc>Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.</desc>
<refs>
<ref source="MISC" url="http://zsh.stupidphat.com/advisory.cgi?000311-1">http://zsh.stupidphat.com/advisory.cgi?000311-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1075">1075</ref>
<ref source="XF">netscape-webpublisher-invalid-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0238" seq="2000-0238">
<status>Entry</status>
<desc>Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=s8d1f3e3.036@kib.co.kodiak.ak.us">20000317 DoS with NAVIEG</ref>
<ref source="XF">nav-email-gateway-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1064">1064</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0240" seq="2000-0240">
<status>Entry</status>
<desc>vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net">20000321 vqserver /........../</ref>
<ref source="CONFIRM" url="http://www.vqsoft.com/vq/server/faqs/dotdotbug.html">http://www.vqsoft.com/vq/server/faqs/dotdotbug.html</ref>
<ref source="XF">vqserver-dir-traverse</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1067">1067</ref>
<ref source="OSVDB" url="http://www.osvdb.org/270">270</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0243" seq="2000-0243">
<status>Entry</status>
<desc>AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=web-5645555@post2.rnci.com">20000324 AnalogX SimpleServer 1.03 Remote Crash&quot; at: </ref>
<ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
<ref source="XF" url="http://xforce.iss.net/static/4189.php">simpleserver-exception-dos(4189)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1076">1076</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1265">1265</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0245" seq="2000-0245">
<status>Entry</status>
<desc>Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003290852.aa27218@blaze.arl.mil">20000328 Objectserver vulnerability</ref>
<ref source="SGI" url="ftp://sgigate.sgi.com/security/20000303-01-PX">20000303-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-030.shtml">K-030</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1079">1079</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1267">1267</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4206">irix-objectserver-create-accounts(4206)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0246" seq="2000-0246">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the &quot;Virtualized UNC Share&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-019.asp">MS00-019</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=249599">Q249599</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1081">1081</ref>
<ref source="XF">iis-virtual-unc-share</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0247" seq="2000-0247">
<status>Entry</status>
<desc>Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html">20000322 Local root compromise in GNQS 3.50.6 and 3.50.7</ref>
<ref source="MISC" url="http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt">http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:13.generic-nqs.asc">FreeBSD-SA-00:13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1842">1842</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4306">generic-nqs-local-root(4306)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0249" seq="2000-0249">
<status>Entry</status>
<desc>The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise47.php3">20000426 Insecure file handling in IBM AIX frcactrl program</ref>
<ref source="IBM">ERS-OAR-E01-2000:075.1</ref>
<ref source="XF">aix-frcactrl</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1152">1152</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0251" seq="2000-0251">
<status>Entry</status>
<desc>HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0021.html">HPSBUX0004-112</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1090">1090</ref>
<ref source="XF">hp-virtual-vault</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0252" seq="2000-0252">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html">20000411 Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4975.php">dansie-shell-metacharacters</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0253" seq="2000-0253">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.</desc>
<refs>
<ref source="BUGTRAQ">20000411 Re: Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0254" seq="2000-0254">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.</desc>
<refs>
<ref source="BUGTRAQ">20000411 Re: Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4954.php">dansie-form-variables</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0255" seq="2000-0255">
<status>Entry</status>
<desc>The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0022.html">20000405 SilverBack Security Advisory: Nbase-Xyplex DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1091">1091</ref>
<ref source="XF">nbase-xyplex-router</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0257" seq="2000-0257">
<status>Entry</status>
<desc>Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0004171825340.10088-100000@nimue.tpi.pl">20000418 Novell Netware 5.1 (server 5.00h, Dec 11, 1999)...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1118">1118</ref>
<ref source="XF">netware-remote-admin-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0258" seq="2000-0258">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the &quot;Myriad Escaped Characters&quot; Vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-023.asp">MS00-023</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1101">1101</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0260" seq="2000-0260">
<status>Entry</status>
<desc>Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the &quot;Link View Server-Side Component&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-025.asp">MS00-025</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1109">1109</ref>
<ref source="OSVDB" url="http://www.osvdb.org/282">282</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0261" seq="2000-0261">
<status>Entry</status>
<desc>The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
<ref source="XF">ken-download-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1282">1282</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0262" seq="2000-0262">
<status>Entry</status>
<desc>The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
<ref source="XF">ken-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0263" seq="2000-0263">
<status>Entry</status>
<desc>The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html">20000416 xfs</ref>
<ref source="XF">redhat-fontserver-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1111">1111</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0264" seq="2000-0264">
<status>Entry</status>
<desc>Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref>
<ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
<ref source="XF">panda-admin-privileges</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0265" seq="2000-0265">
<status>Entry</status>
<desc>Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref>
<ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref>
<ref source="XF">panda-uninstall-program</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0267" seq="2000-0267">
<status>Entry</status>
<desc>Cisco Catalyst 5.4.x allows a user to gain access to the &quot;enable&quot; mode without a password.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml">20000419 Cisco Catalyst Enable Password Bypass Vulnerability</ref>
<ref source="XF">cisco-catalyst-password-bypass</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1122">1122</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1288">1288</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0268" seq="2000-0268">
<status>Entry</status>
<desc>Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml">20000420 Cisco IOS Software TELNET Option Handling Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1123">1123</ref>
<ref source="XF">cisco-ios-option-handling</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1289">1289</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0272" seq="2000-0272">
<status>Entry</status>
<desc>RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95625288231045&amp;w=2">20000420 Remote DoS attack in Real Networks Real Server Vulnerability</ref>
<ref source="CONFIRM" url="http://service.real.com/help/faq/servg270.html">http://service.real.com/help/faq/servg270.html</ref>
<ref source="XF">realserver-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1128">1128</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0273" seq="2000-0273">
<status>Entry</status>
<desc>PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0031.html">20000409 A funny way to DOS pcANYWHERE8.0 and 9.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1095">1095</ref>
<ref source="XF">pcanywhere-login-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0274" seq="2000-0274">
<status>Entry</status>
<desc>The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0035.html">20000410 linux trustees 1.5 long path name vulnerability</ref>
<ref source="CONFIRM" url="http://www.braysystems.com/linux/trustees.html">http://www.braysystems.com/linux/trustees.html</ref>
<ref source="XF">linux-trustees-patch-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1096">1096</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0276" seq="2000-0276">
<status>Entry</status>
<desc>BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000410131628.659.qmail@securityfocus.com">20000410 BeOS syscall bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1098">1098</ref>
<ref source="XF">beos-syscall-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0277" seq="2000-0277">
<status>Entry</status>
<desc>Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the &quot;XLM Text Macro&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-022.asp">MS00-022</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1087">1087</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1272">1272</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0278" seq="2000-0278">
<status>Entry</status>
<desc>The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0006.html">20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1089">1089</ref>
<ref source="XF">eviewer-admin-request-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0279" seq="2000-0279">
<status>Entry</status>
<desc>BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0029.html">20000407 BeOS Networking DOS</ref>
<ref source="MISC" url="http://bebugs.be.com/devbugs/detail.php3?oid=2505312">http://bebugs.be.com/devbugs/detail.php3?oid=2505312</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1100">1100</ref>
<ref source="XF">beos-networking-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0282" seq="2000-0282">
<status>Entry</status>
<desc>TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html">20000412 TalentSoft Web+ Input Validation Bug Vulnerability</ref>
<ref source="CONFIRM" url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html">ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1102">1102</ref>
<ref source="XF">talentsoft-web-input</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0283" seq="2000-0283">
<status>Entry</status>
<desc>The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html">20000412 Performance Copilot for IRIX 6.5</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1106">1106</ref>
<ref source="XF">irix-pmcd-info</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0285" seq="2000-0285">
<status>Entry</status>
<desc>Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html">20000416 XFree86 server overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1306">1306</ref>
<ref source="XF">xfree86-xkbmap-parameter-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0287" seq="2000-0287">
<status>Entry</status>
<desc>The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.html">20000412 BizDB Search Script Enables Shell Command Execution at the Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1104">1104</ref>
<ref source="XF">http-cgi-bizdb</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0289" seq="2000-0289">
<status>Entry</status>
<desc>IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0284.html">20000327 Security Problems with Linux 2.2.x IP Masquerading</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_48.html">20000520 Security hole in kernel &lt; 2.2.15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1078">1078</ref>
<ref source="XF">linux-masquerading-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0290" seq="2000-0290">
<status>Entry</status>
<desc>Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0005.html">20000331 Webstar 4.0 Buffer overflow vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/4792.php">macos-webstar-get-bo(4792)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1822">1822</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0292" seq="2000-0292">
<status>Entry</status>
<desc>The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004190908140.32750-100000@localhost.localdomain">20000418 Adtran DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1129">1129</ref>
<ref source="XF">adtran-ping-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0294" seq="2000-0294">
<status>Entry</status>
<desc>Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2162">FreeBSD-SA-00:12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1107">1107</ref>
<ref source="XF">freebsd-healthd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/606">606</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0296" seq="2000-0296">
<status>Entry</status>
<desc>fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0011.html">20000331 fcheck v.2.7.45 and insecure use of Perl's system()</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1086">1086</ref>
<ref source="XF">fcheck-shell</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0297" seq="2000-0297">
<status>Entry</status>
<desc>Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.</desc>
<refs>
<ref source="ALLAIRE" url="http://www2.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">ASB00-06</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1085">1085</ref>
<ref source="XF">allaire-forums-allaccess</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1270">1270</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0298" seq="2000-0298">
<status>Entry</status>
<desc>The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0027.html">20000407 All Users startup folder left open if unattended install and OEMP reinstall=1</ref>
<ref source="XF" url="http://xforce.iss.net/static/4278.php">win2k-unattended-install(4278)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1758">1758</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0301" seq="2000-0301">
<status>Entry</status>
<desc>Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95505800117143&amp;w=2">20000405 Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm)</ref>
<ref source="CONFIRM" url="http://support.ipswitch.com/kb/IM-20000208-DM02.htm">http://support.ipswitch.com/kb/IM-20000208-DM02.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1094">1094</ref>
<ref source="XF">ipswitch-imail-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0302" seq="2000-0302">
<status>Entry</status>
<desc>Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95453598317340&amp;w=2">20000331 Alert: MS Index Server (CISADV000330)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1084">1084</ref>
<ref source="XF">http-indexserver-asp-source</ref>
<ref source="OSVDB" url="http://www.osvdb.org/271">271</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0303" seq="2000-0303">
<status>Entry</status>
<desc>Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise50.php3">20000503 Vulnerability in Quake3Arena Auto-Download Feature</ref>
<ref source="CONFIRM" url="http://www.quake3arena.com/news/index.html">http://www.quake3arena.com/news/index.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1169">1169</ref>
<ref source="XF">quake3-auto-download</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7531">7531</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0304" seq="2000-0304">
<status>Entry</status>
<desc>Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the &quot;Undelimited .HTR Request&quot; vulnerability.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise52.php3">20000511 Microsoft IIS Remote Denial of Service Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx">MS00-031</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1191">1191</ref>
<ref source="XF">iis-authchangeurl-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0305" seq="2000-0305">
<status>Entry</status>
<desc>Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the &quot;IP Fragment Reassembly&quot; vulnerability.</desc>
<refs>
<ref source="BINDVIEW" url="http://www.securityfocus.com/templates/advisory.html?id=2240">20000519 jolt2 - Remote DoS against NT, W2K, 9x</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-029.asp">MS00-029</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1236">1236</ref>
<ref source="XF">ip-fragment-reassembly-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0306" seq="2000-0306">
<status>Entry</status>
<desc>Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.02a">SB-99.02</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=AAh6GYsGU1@leshka.chuvashia.su">19981229 Local/remote exploit for SCO UNIX.</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0307" seq="2000-0307">
<status>Entry</status>
<desc>Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.07b">SB-99.07</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0308" seq="2000-0308">
<status>Entry</status>
<desc>Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.08a">SB-99.08</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0309" seq="2000-0309">
<status>Entry</status>
<desc>The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#trctrap">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6126">6126</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0310" seq="2000-0310">
<status>Entry</status>
<desc>IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#maxqueue">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7539">7539</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0311" seq="2000-0311">
<status>Entry</status>
<desc>The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the &quot;Mixed Object Access&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-026.asp">MS00-026</ref>
<ref source="XF">ms-mixed-object</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1145">1145</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0313" seq="2000-0313">
<status>Entry</status>
<desc>Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ifmedia">19991109 Any user can change interface media configurations.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7540">7540</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0314" seq="2000-0314">
<status>Entry</status>
<desc>traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7574">7574</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0315" seq="2000-0315">
<status>Entry</status>
<desc>traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7575">7575</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0316" seq="2000-0316">
<status>Entry</status>
<desc>Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0191.html">20000424 Solaris 7 x86 lp exploit</ref>
<ref source="SUNBUG">4314312</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1143">1143</ref>
<ref source="XF">solaris-lp-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0318" seq="2000-0318">
<status>Entry</status>
<desc>Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0057.html">20000413 Security problems with Atrium Mercur Mailserver 3.20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1144">1144</ref>
<ref source="XF">mercur-remote-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0319" seq="2000-0319">
<status>Entry</status>
<desc>mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=2694.000424@SECURITY.NNOV.RU">20000424 unsafe fgets() in sendmail's mail.local</ref>
<ref source="XF">sendmail-maillocal-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1146">1146</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0320" seq="2000-0320">
<status>Entry</status>
<desc>Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=9763.000421@SECURITY.NNOV.RU">20000421 unsafe fgets() in qpopper</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1133">1133</ref>
<ref source="XF">qpopper-fgets-spoofing</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0322" seq="2000-0322">
<status>Entry</status>
<desc>The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execure arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Enip.BSO.23.0004241601140.28851-100000@www.whitehats.com">20000424 piranha default password/exploit</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-014.html">RHSA-2000:014</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1149">1149</ref>
<ref source="XF">piranha-passwd-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0323" seq="2000-0323">
<status>Entry</status>
<desc>The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the &quot;Text I-ISAM&quot; vulnerability. </desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-22&amp;msg=19990729195531.25108.qmail@underground.org">19990728 Alert : MS Office 97 Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp">MS99-030</ref>
<ref source="XF">jet-text-isam</ref>
<ref source="BID" url="http://www.securityfocus.com/level2/?go=vulnerabilities&amp;id=595">595</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0324" seq="2000-0324">
<status>Entry</status>
<desc>pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000425150157.13567A-100000@sword.damocles.com">20000425 Denial of Service Against pcAnywhere.</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0201.html">20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0258.html">20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1150">1150</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4347.php">pcanywhere-tcpsyn-dos(4347)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1301">1301</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0327" seq="2000-0327">
<status>Entry</status>
<desc>Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the &quot;Virtual Machine Verifier&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93993545118416&amp;w=2">19991014 Another Microsoft Java Flaw Disovered</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-045.asp">MS99-045</ref>
<ref source="XF">msvm-verifier-java</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0328" seq="2000-0328">
<status>Entry</status>
<desc>Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.19990824165629.00abcb40@192.168.124.1">19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-046.asp">MS99-046</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/604">604</ref>
<ref source="XF">nt-sequence-prediction-sp4</ref>
<ref source="XF">tcp-seq-predict</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0329" seq="2000-0329">
<status>Entry</status>
<desc>A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the &quot;Active Setup Control&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-048.asp">MS99-048</ref>
<ref source="XF">ie-active-setup-control</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0330" seq="2000-0330">
<status>Entry</status>
<desc>The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the &quot;File Access URL&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-049.asp">MS99-049</ref>
<ref source="XF">win-fileurl-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0331" seq="2000-0331">
<status>Entry</status>
<desc>Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the &quot;Malformed Environment Variable&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0147.html">20000421 CMD.EXE overflow (CISADV000420)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-027.asp">MS00-027</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1135">1135</ref>
<ref source="XF">nt-cmd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0332" seq="2000-0332">
<status>Entry</status>
<desc>UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000503091316.99073.qmail@hotmail.com">20000502 Fun with UltraBoard V1.6X</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1164">1164</ref>
<ref source="XF">ultraboard-printabletopic-fileread</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1309">1309</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4065">4065</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0334" seq="2000-0334">
<status>Entry</status>
<desc>The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=15411&amp;Method=Full">ASB00-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1181">1181</ref>
<ref source="XF">allaire-spectra-container-editor-preview</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0335" seq="2000-0335">
<status>Entry</status>
<desc>The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.</desc>
<refs>
<ref source="BUGTRAQ">20000502 glibc resolver weakness</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1166">1166</ref>
<ref source="XF">glibc-resolver-id-predictable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0336" seq="2000-0336">
<status>Entry</status>
<desc>Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-012.html">RHSA-2000:012</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-009.0.txt">CSSA-2000-009.0</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000009.html">TLSA2000010-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1232">1232</ref>
<ref source="XF">openldap-symlink-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0337" seq="2000-0337">
<status>Entry</status>
<desc>Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0188.html">20000424 Solaris x86 Xsun overflow.</ref>
<ref source="SUNBUG">4335411</ref>
<ref source="XF">solaris-xsun-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1140">1140</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0338" seq="2000-0338">
<status>Entry</status>
<desc>Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520%40clico.pl">20000423 CVS DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1136">1136</ref>
<ref source="XF">cvs-tempfile-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0339" seq="2000-0339">
<status>Entry</status>
<desc>ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000421044123.2353.qmail@securityfocus.com">20000420 ZoneAlarm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1137">1137</ref>
<ref source="XF">zonealarm-portscan</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1294">1294</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0340" seq="2000-0340">
<status>Entry</status>
<desc>Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00042902575201.09597@wintermute-pub">20000428 SuSE 6.3 Gnomelib buffer overflow</ref>
<ref source="CONFIRM" url="http://www.suse.com/us/support/download/updates/axp_63.html">http://www.suse.com/us/support/download/updates/axp_63.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1155">1155</ref>
<ref source="XF">linux-gnomelib-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0341" seq="2000-0341">
<status>Entry</status>
<desc>ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95736106504870&amp;w=2">20000501 Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1156">1156</ref>
<ref source="XF">nntpserver-cassandra-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0342" seq="2000-0342">
<status>Entry</status>
<desc>Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka &quot;Stealth Attachment.&quot;</desc>
<refs>
<ref source="MISC" url="http://www.peacefire.org/security/stealthattach/explanation.html">http://www.peacefire.org/security/stealthattach/explanation.html</ref>
<ref source="CONFIRM" url="http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077">http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1157">1157</ref>
<ref source="XF">eudora-warning-message</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0344" seq="2000-0344">
<status>Entry</status>
<desc>The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0005012042550.6419-100000@ferret.lmh.ox.ac.uk">20000501 Linux knfsd DoS issue</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1160">1160</ref>
<ref source="XF">linux-knfsd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0346" seq="2000-0346">
<status>Entry</status>
<desc>AppleShare IP 6.1 and later allows a remote at